Cybersecurity Glossary
Endpoint Detection and Response
Security software that watches behaviour on each device, and lets you investigate and contain remotely.
What Endpoint Detection and Response means
Traditional antivirus compares files against a list of known bad ones. Endpoint detection and response watches what programs do: which processes start which, what touches many files quickly, what connects where. It also records that activity so an investigation is possible afterwards, and lets an administrator isolate a machine from the network remotely.
Why Endpoint Detection and Response matters for small businesses and nonprofits
Most current attacks use legitimate tools rather than recognisable malware files, so signature matching alone misses them. The remote isolation capability alone often justifies the cost during an incident.
What to do about Endpoint Detection and Response
- Replace basic antivirus with a behaviour based product on every device
- Make sure someone is responsible for reading and acting on alerts
- Verify that isolation works before you need it, by testing on one machine
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.