Blog / Practical controls
Practical controls
EDR vs Antivirus for a Small Business, and the Question That Matters More: Who Is Watching It at 2 a.m.?
EDR vs antivirus explained for a business owner: what each one catches, why insurers ask for EDR, and why a red alert nobody reads is the same as no alert.
The red alert that waited 31 hours
The owner of a 45-person building-products distributor bought endpoint detection and response last year for one reason: the cyber insurance renewal form had a checkbox for it, and the premium was lower with the box ticked. His IT provider installed the agent on 52 computers and three servers, showed him a dashboard full of green dots, and the two of them never spoke of it again.
On a Friday at 6:12 p.m. one dot turns red. The EDR has seen a program on the warehouse manager's PC try to disable Windows backups and reach out to a server in another country. It isolates nothing, because nobody set it to. It sends an email to a shared mailbox called it-alerts, which forwards to the IT provider's ticket system, which has a rule that routes weekend tickets to Monday.
The alert sits there through Friday night and all of Saturday. Around 1 a.m. Sunday the same program, now on the file server, begins encrypting. By the time a technician opens the ticket at 9:40 Monday morning, the dashboard shows 31 hours of red and the sales team cannot open a single quote.
The EDR did its job. It saw the attack in the first minute. What the distributor never bought was a person to look.
What the heck does this mean
Antivirus is a list. It compares files on a computer against known bad ones and blocks the matches. Good against yesterday's malware, blind to anything new, and mostly blind to attacks that use no malware at all, just built-in Windows tools driven by hand.
Endpoint detection and response, EDR, watches behavior instead of matching files. A program that disables backups, then pulls passwords out of memory, then talks to a foreign server is doing something no accounting app does. EDR notices the pattern, records it, and can cut the computer off the network. It is the difference between a lock that knows a thousand burglars by face and a guard who notices someone climbing through a window.
Here is the part vendors skip. EDR produces alerts. Alerts need a human, at the hour they arrive, with the authority to act. Managed detection and response, MDR, is the name for buying that human along with the tool. Without one, EDR is an expensive security camera whose tape nobody reviews.
The numbers that matter
Only 34% of organizations with 100 to 250 employees stopped a ransomware attack before encryption, in the Sophos State of Ransomware 2026 survey. Two in three had tools on the computers and still watched the files lock.
Pre-ransomware detection made up 5% of the cases in the Arctic Wolf 2026 Threat Report, and those detections frequently stopped the attack before anything was encrypted. Small share, enormous difference. The 5% went home at the usual time.
The mean time to identify a breach was 183 days, according to the IBM 2026 Cost of a Data Breach Report. Six months. The distributor's 31 hours was fast by comparison, which tells you how low the bar sits.
What to do this week
- Ask your IT provider two questions in writing: "Is EDR installed on every computer and server, including the owner's laptop and the warehouse PC?" and "Who reads the alerts between 6 p.m. Friday and 9 a.m. Monday?" The answer to the second one is your actual security posture. (CIS 10 Malware Defenses)
- Turn on automatic isolation for high-severity detections. Most EDR products can cut a computer off the network on their own when they see ransomware behavior. A false alarm costs one person an hour. A real one contained at 6:12 p.m. costs nothing further. (CIS 10 Malware Defenses)
- Make the alert path human: alerts go to a phone that rings, not a shared mailbox that feeds a ticket queue. Decide who carries the phone this month and write the name down where the owner can see it. (CIS 13 Network Monitoring and Defense)
- Check the dashboard for machines that have not reported in for seven days. An agent that stopped checking in is a computer with no protection, and attackers uninstall agents first when they can. (CIS 10 Malware Defenses)
- Run one tabletop drill. Read the alert from the story aloud on a Friday afternoon and have the team say what happens next: who isolates, who calls the insurer, who tells sales. Fix whatever the drill exposes. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment checks whether EDR is on every machine, whether isolation is switched on, and where the alert goes at 6:12 on a Friday. The answers are often not what the owner was told at renewal. The Cyber Hygiene Test takes three minutes and asks the who-is-watching question directly. A 15-minute call with an engineer turns a green dashboard into a plan with a name on it.
Our assessment is mapped to your regulators, and the read-only compliance agent shows whether EDR is deployed on every machine, which agents have stopped reporting, and whether alerts are being reviewed. We have no access and do not remediate; response stays with you or your IT partner, and we show you where the gap is.
Questions people ask
Is Windows Defender enough for a business? Defender is a competent antivirus and a reasonable floor for a five-person office with little to lose. It is not EDR unless you pay for the business tier that adds detection and response, and even then someone has to read what it finds. If you hold client data, patient data or money, plan on EDR plus a person, and treat Defender as the layer underneath.
What is the difference between EDR and MDR? EDR is the software on the computer that watches behavior and raises alerts. MDR, managed detection and response, is a service where trained people watch those alerts around the clock and act on them. EDR alone is a smoke detector. MDR is the fire department. The distributor in the story had the first and was insured as if it had the second.
Does EDR slow down computers? Modern EDR agents use a small slice of processor time and are rarely noticed on a machine under five or six years old. Where staff complain, it is usually an old PC that was already slow, or an agent set to scan everything at 9 a.m. on Monday. Tune the schedule, replace the antique, keep the agent on. The alternative is a computer that runs at full speed for the attacker.
The dashboard was honest for 31 hours. Honesty without a listener is just a color.
Questions people ask
Is Windows Defender enough for a business?
Defender is a competent antivirus and a reasonable floor for a five-person office with little to lose. It is not EDR unless you pay for the business tier that adds detection and response, and even then someone has to read what it finds. If you hold client data, patient data or money, plan on EDR plus a person, and treat Defender as the layer underneath.
What is the difference between EDR and MDR?
EDR is the software on the computer that watches behavior and raises alerts. MDR, managed detection and response, is a service where trained people watch those alerts around the clock and act on them. EDR alone is a smoke detector. MDR is the fire department. The distributor in the story had the first and was insured as if it had the second.
Does EDR slow down computers?
Modern EDR agents use a small slice of processor time and are rarely noticed on a machine under five or six years old. Where staff complain, it is usually an old PC that was already slow, or an agent set to scan everything at 9 a.m. on Monday. Tune the schedule, replace the antique, keep the agent on. The alternative is a computer that runs at full speed for the attacker.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
A Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs
A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.
Practical controlsSecurity Awareness Training for a Small Business: Why the Report Button Beats the Delete Key
Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.
Practical controlsHow to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It
Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.
