Skip to main content
Dig IT Solutions logo

Cyber Security

EDR vs antivirus: what is the difference and which does your business need?

Endpoint detection and response compared with traditional antivirus for UK small businesses: how each works, what it catches, what it costs and who needs it.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Antivirus checks files against a list of known malware and blocks matches. Endpoint detection and response (EDR) watches how every device behaves, detects attacks that use new malware or legitimate tools, isolates the device automatically and records what happened so it can be investigated. For a business facing ransomware and phishing, EDR is the baseline. Antivirus alone no longer is.

For twenty years the answer to "are our computers protected?" was "yes, we have antivirus". Attacks have moved on and, for a business that would be seriously harmed by ransomware or a stolen mailbox, antivirus on its own is no longer a defensible position. This article explains what endpoint detection and response (EDR) does that antivirus cannot, gives a side-by-side comparison, and helps you decide what your business needs.

What antivirus does

Traditional antivirus scans files and compares them against a database of known malware signatures, plus some heuristics for suspicious-looking code. If a file matches, it is quarantined. It is good at stopping the malware that has already been seen and catalogued, which is a great deal of malware, and it is cheap and unobtrusive.

Its weakness is that it is looking for known things. New variants are produced faster than signatures can be written. More importantly, modern attacks often involve no malicious file at all: an attacker with a stolen password logs in with a legitimate remote access tool, uses PowerShell and Windows' own administrative utilities to move around, and only introduces the ransomware executable at the very end, by which point antivirus on one machine is irrelevant.

What EDR does

EDR takes a different approach. Instead of asking "is this file bad?", it asks "is this behaviour bad?". An agent on each device records what is happening: which processes start, what they touch, what network connections they make, whether credentials are being read from memory, whether files are being renamed and encrypted at speed, whether shadow copies are being deleted. That telemetry is analysed continuously against known attack techniques.

When something matches, EDR responds: it can kill the process, roll back changes, and isolate the device from the network so that the attack cannot spread while a human investigates. It also keeps the record, so afterwards you can answer the questions that matter: how did they get in, what did they touch, did they take data, which other machines are affected. Those are precisely the questions the ICO and your insurer will ask.

Modern EDR products include antivirus as one of their layers, so adopting EDR replaces the standalone antivirus rather than adding to it.

EDR vs antivirus: side by side

Traditional antivirusEndpoint detection and response (EDR)
Detection methodSignatures and simple heuristics: known bad filesBehavioural analysis of processes, memory, network and file activity
Catches new or modified malwarePoorly, until a signature existsYes, by behaviour rather than identity
Catches attacks using legitimate tools (stolen logins, PowerShell, remote tools)NoYes
ResponseQuarantine the fileKill process, roll back, isolate the device from the network automatically
Visibility after an incidentMinimal: a log that a file was blockedFull timeline of what happened, on which devices, and what was accessed
Ransomware in progressUsually too late once encryption startsDetects and isolates on encryption behaviour, often within seconds
Needs someone watchingNot reallyYes: alerts need triage, which is why managed EDR or MDR exists
Cyber Essentials malware controlSatisfies it if maintainedSatisfies it
Cyber insurance questionnairesIncreasingly not accepted on its ownCommonly required by name
CostLow per deviceA few pounds per device per month, often within a managed IT fee
Included with Microsoft 365 Business PremiumDefender Antivirus is in WindowsDefender for Business is included

Why the difference matters in practice

Consider the way ransomware actually reaches a small business, described in our ransomware guide. An attacker phishes a password, logs in through the VPN, spends a week exploring the network with legitimate administrative tools, deletes the backups, and then encrypts everything on a Saturday night.

Antivirus sees nothing until the encryption executable lands, and by then the attacker is domain administrator and may have disabled it. EDR sees the unusual sign-in followed by credential dumping on day one, the reconnaissance tools on day two, and if anything gets as far as encryption it isolates that machine within seconds of the first files changing. The practical difference is one device reimaged versus an entire business rebuilt.

The same applies to the quieter incidents. A user opens a malicious document that launches a script to steal browser-saved passwords. No file on disk is "known bad". EDR flags the script behaviour, kills it and tells you which credentials to reset.

The catch: alerts need a human

EDR produces alerts, and alerts need someone to read them, decide whether they matter and act. A platform that emails an unread mailbox is not protection. This is why EDR for small businesses is nearly always delivered as a managed service, with a response team watching the console day and night, investigating and taking action, and escalating to you when it matters. The industry term is managed detection and response (MDR). When you are offered "EDR", ask who watches it, within what hours, and what they are authorised to do without calling you first. Our endpoint security service is built around that answer, and it is what we deploy for clients such as Mr Plant Hire across their depots.

What about Microsoft Defender?

There are several products with "Defender" in the name, which causes confusion.

  • Microsoft Defender Antivirus is the free antivirus built into Windows. It is competent, and it is what most home users rely on. It is not EDR.
  • Microsoft Defender for Business is Microsoft's EDR for small and medium businesses, included in Microsoft 365 Business Premium and available standalone. It provides behavioural detection, automated investigation and device isolation.
  • Microsoft Defender for Endpoint is the enterprise version with more advanced features.

Many businesses already hold Business Premium licences and have Defender for Business sitting unused. Turning it on properly, with policies, onboarding of every device and someone watching the alerts, is often the cheapest security improvement available. Alternatively, third-party EDR platforms are widely used by managed providers and are equally acceptable to assessors and insurers.

Which does your business need?

If your business would be seriously disrupted by losing access to its files for a week, handles client data or money, is asked for Cyber Essentials, or holds cyber insurance, you need EDR with someone watching it. That describes almost every business of up to 250 people. It should be on every device: laptops, desktops, servers, Macs, and any personal computer that accesses company data.

Antivirus alone is now suitable for very small setups with nothing much to lose and no compliance demands, and even then the price difference is small.

EDR is one layer, not a complete strategy. It sits alongside MFA, patching, email filtering, backups the attacker cannot reach and staff awareness. The NCSC's ransomware guidance sets out that layered approach, and our article on continuous monitoring explains where EDR fits within it.

What to do next

If you are not sure whether every device in your business runs EDR, or whether anyone is watching the alerts, an IT health check will confirm what is installed, what is licensed but unused, and what it would take to close the gap.

Frequently asked questions

What does EDR stand for and what does it do?
Endpoint detection and response. It is software on each laptop, desktop and server that continuously records activity (processes, network connections, file changes, credential use), analyses it for attack behaviour, and can respond automatically by killing processes and isolating the device from the network. It also keeps a record so that an incident can be investigated and its scope understood.
Is Windows Defender antivirus enough for a business?
The free Microsoft Defender Antivirus built into Windows is a competent antivirus, and it is far better than nothing. It is not EDR. Microsoft's EDR product is Defender for Business or Defender for Endpoint, included in Microsoft 365 Business Premium, which adds behavioural detection, automated isolation and investigation. Many businesses already pay for it and have not switched it on.
Does EDR replace antivirus?
Modern EDR platforms include antivirus as one of their layers, so you do not run both separately. What you replace is the standalone antivirus product and its console. Cyber Essentials' malware protection control is satisfied by EDR, and insurers increasingly require it rather than merely accepting it.
What is managed EDR or MDR?
EDR generates alerts that need a person to interpret and act on. Managed detection and response (MDR) adds that person: a security team watching the alerts around the clock, investigating and responding. For a small business without its own security staff, EDR without someone watching it is only half the value. Most managed IT providers now bundle the two.
How much does EDR cost for a small business?
It is priced per device per month, typically a few pounds, and is usually included in a managed IT agreement rather than bought separately. If you have Microsoft 365 Business Premium you may already be licensed for Defender for Business. The cost of one ransomware incident that EDR would have isolated exceeds many years of the subscription.
Do servers and Macs need EDR too?
Yes. Servers hold the data and are where ransomware does the most damage, and they are frequently the machines running an old antivirus or none. Macs are targeted less often but are not immune, and if they access company data they are in scope for Cyber Essentials. Every device that touches business data should run the same managed EDR.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us