Cyber Security
EDR vs antivirus: what is the difference and which does your business need?
Endpoint detection and response compared with traditional antivirus for UK small businesses: how each works, what it catches, what it costs and who needs it.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Antivirus checks files against a list of known malware and blocks matches. Endpoint detection and response (EDR) watches how every device behaves, detects attacks that use new malware or legitimate tools, isolates the device automatically and records what happened so it can be investigated. For a business facing ransomware and phishing, EDR is the baseline. Antivirus alone no longer is.
For twenty years the answer to "are our computers protected?" was "yes, we have antivirus". Attacks have moved on and, for a business that would be seriously harmed by ransomware or a stolen mailbox, antivirus on its own is no longer a defensible position. This article explains what endpoint detection and response (EDR) does that antivirus cannot, gives a side-by-side comparison, and helps you decide what your business needs.
What antivirus does
Traditional antivirus scans files and compares them against a database of known malware signatures, plus some heuristics for suspicious-looking code. If a file matches, it is quarantined. It is good at stopping the malware that has already been seen and catalogued, which is a great deal of malware, and it is cheap and unobtrusive.
Its weakness is that it is looking for known things. New variants are produced faster than signatures can be written. More importantly, modern attacks often involve no malicious file at all: an attacker with a stolen password logs in with a legitimate remote access tool, uses PowerShell and Windows' own administrative utilities to move around, and only introduces the ransomware executable at the very end, by which point antivirus on one machine is irrelevant.
What EDR does
EDR takes a different approach. Instead of asking "is this file bad?", it asks "is this behaviour bad?". An agent on each device records what is happening: which processes start, what they touch, what network connections they make, whether credentials are being read from memory, whether files are being renamed and encrypted at speed, whether shadow copies are being deleted. That telemetry is analysed continuously against known attack techniques.
When something matches, EDR responds: it can kill the process, roll back changes, and isolate the device from the network so that the attack cannot spread while a human investigates. It also keeps the record, so afterwards you can answer the questions that matter: how did they get in, what did they touch, did they take data, which other machines are affected. Those are precisely the questions the ICO and your insurer will ask.
Modern EDR products include antivirus as one of their layers, so adopting EDR replaces the standalone antivirus rather than adding to it.
EDR vs antivirus: side by side
| Traditional antivirus | Endpoint detection and response (EDR) | |
|---|---|---|
| Detection method | Signatures and simple heuristics: known bad files | Behavioural analysis of processes, memory, network and file activity |
| Catches new or modified malware | Poorly, until a signature exists | Yes, by behaviour rather than identity |
| Catches attacks using legitimate tools (stolen logins, PowerShell, remote tools) | No | Yes |
| Response | Quarantine the file | Kill process, roll back, isolate the device from the network automatically |
| Visibility after an incident | Minimal: a log that a file was blocked | Full timeline of what happened, on which devices, and what was accessed |
| Ransomware in progress | Usually too late once encryption starts | Detects and isolates on encryption behaviour, often within seconds |
| Needs someone watching | Not really | Yes: alerts need triage, which is why managed EDR or MDR exists |
| Cyber Essentials malware control | Satisfies it if maintained | Satisfies it |
| Cyber insurance questionnaires | Increasingly not accepted on its own | Commonly required by name |
| Cost | Low per device | A few pounds per device per month, often within a managed IT fee |
| Included with Microsoft 365 Business Premium | Defender Antivirus is in Windows | Defender for Business is included |
Why the difference matters in practice
Consider the way ransomware actually reaches a small business, described in our ransomware guide. An attacker phishes a password, logs in through the VPN, spends a week exploring the network with legitimate administrative tools, deletes the backups, and then encrypts everything on a Saturday night.
Antivirus sees nothing until the encryption executable lands, and by then the attacker is domain administrator and may have disabled it. EDR sees the unusual sign-in followed by credential dumping on day one, the reconnaissance tools on day two, and if anything gets as far as encryption it isolates that machine within seconds of the first files changing. The practical difference is one device reimaged versus an entire business rebuilt.
The same applies to the quieter incidents. A user opens a malicious document that launches a script to steal browser-saved passwords. No file on disk is "known bad". EDR flags the script behaviour, kills it and tells you which credentials to reset.
The catch: alerts need a human
EDR produces alerts, and alerts need someone to read them, decide whether they matter and act. A platform that emails an unread mailbox is not protection. This is why EDR for small businesses is nearly always delivered as a managed service, with a response team watching the console day and night, investigating and taking action, and escalating to you when it matters. The industry term is managed detection and response (MDR). When you are offered "EDR", ask who watches it, within what hours, and what they are authorised to do without calling you first. Our endpoint security service is built around that answer, and it is what we deploy for clients such as Mr Plant Hire across their depots.
What about Microsoft Defender?
There are several products with "Defender" in the name, which causes confusion.
- Microsoft Defender Antivirus is the free antivirus built into Windows. It is competent, and it is what most home users rely on. It is not EDR.
- Microsoft Defender for Business is Microsoft's EDR for small and medium businesses, included in Microsoft 365 Business Premium and available standalone. It provides behavioural detection, automated investigation and device isolation.
- Microsoft Defender for Endpoint is the enterprise version with more advanced features.
Many businesses already hold Business Premium licences and have Defender for Business sitting unused. Turning it on properly, with policies, onboarding of every device and someone watching the alerts, is often the cheapest security improvement available. Alternatively, third-party EDR platforms are widely used by managed providers and are equally acceptable to assessors and insurers.
Which does your business need?
If your business would be seriously disrupted by losing access to its files for a week, handles client data or money, is asked for Cyber Essentials, or holds cyber insurance, you need EDR with someone watching it. That describes almost every business of up to 250 people. It should be on every device: laptops, desktops, servers, Macs, and any personal computer that accesses company data.
Antivirus alone is now suitable for very small setups with nothing much to lose and no compliance demands, and even then the price difference is small.
EDR is one layer, not a complete strategy. It sits alongside MFA, patching, email filtering, backups the attacker cannot reach and staff awareness. The NCSC's ransomware guidance sets out that layered approach, and our article on continuous monitoring explains where EDR fits within it.
What to do next
If you are not sure whether every device in your business runs EDR, or whether anyone is watching the alerts, an IT health check will confirm what is installed, what is licensed but unused, and what it would take to close the gap.

