Cybersecurity Glossary

Endpoint Detection and Response

Security software that watches behaviour on each device, and lets you investigate and contain remotely.

What Endpoint Detection and Response means

Traditional antivirus compares files against a list of known bad ones. Endpoint detection and response watches what programs do: which processes start which, what touches many files quickly, what connects where. It also records that activity so an investigation is possible afterwards, and lets an administrator isolate a machine from the network remotely.

Why Endpoint Detection and Response matters for small businesses and nonprofits

Most current attacks use legitimate tools rather than recognisable malware files, so signature matching alone misses them. The remote isolation capability alone often justifies the cost during an incident.

What to do about Endpoint Detection and Response

Three steps to deal with Endpoint Detection and Response

  • Replace basic antivirus with a behaviour based product on every device
  • Make sure someone is responsible for reading and acting on alerts
  • Verify that isolation works before you need it, by testing on one machine

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.