Cybersecurity
Endpoint Protection (EDR)
Someone reads the alerts.
Endpoint protection is the security software on your laptops, desktops and servers. Modern endpoint detection and response (EDR) watches how a machine behaves rather than only matching files it has seen before, and can isolate a device from the network on its own. happier IT deploys it, tunes it, and, the part that usually gets skipped, employs the people who read what it says.
Who it's for
The software is rarely the problem.
Four situations account for nearly every endpoint conversation we have, and only one of them is about the product.
The agent is installed and the console is unopened. The licence renews, the software reports in, and the last person to sign in to the dashboard did so during the rollout. This is the normal state of things in an organization without a security team, not a scandal.
Coverage has quietly drifted. Eighty devices in the asset list, sixty-one reporting an agent. The missing ones are usually a server nobody wants to reboot and the laptops of people who have left.
You are running the antivirus that came with the machine. It is better than nothing, and it works by recognising what it has already seen. A real limit rather than a criticism.
Someone used the letters EDR at you. An insurer or a client asked whether you have endpoint detection and response, and "we have antivirus" is no longer an answer that counts on the form.
Coverage beats configuration
An endpoint tool on 90% of devices is not 90% as useful. The uncovered 10% is where anything unwelcome settles in quietly.
The first number to ask any provider for is agents reporting versus devices owned, this week, not the number at rollout.
What's included
What we deploy, and what we do with it.
The licence is the easy half. Six of the eight items below are about coverage, tuning and who is looking.
-
Behaviour-based detection
Rather than asking "have I seen this file before", EDR asks whether what is happening is normal: a process rewriting thousands of files, a script launched from a document, a tool asking for credentials it has no reason to want.
-
Isolation, automatic or one-click
A machine can be cut off from the network while staying reachable by us. The problem stops moving, the evidence stays intact, and the person using it gets a phone call rather than a mystery.
-
Servers and cloud workloads, not just laptops
The same agent on file servers, application servers and cloud virtual machines. Servers hold more and get excluded more often, usually because somebody once worried about performance and the exclusion was never revisited.
-
Rollout to verified full coverage
Deployment, then reconciliation against your asset list and your user directory, so what you get is a number for how many devices are covered rather than a general impression.
-
Tuning to your environment
Every organization runs something unusual: an old line-of-business application, a bespoke script, a design plugin. Untuned tools bury one real detection under a hundred false ones, so the first few weeks are spent making it quiet enough to be believed.
-
Human triage in our own SOC
A security operations centre, the team that watches alerts and decides which matter, staffed by happier IT employees in Canada. <a href="/managed-security-services/">How that works</a>.
-
Disk encryption and device control
BitLocker and FileVault, the whole-disk encryption already built into Windows and macOS, switched on, with recovery keys stored somewhere you can actually find them. A lost laptop should be an inconvenience, not a privacy notification.
-
A monthly report in plain English
What was detected, what we did, coverage as a number, and anything you need to decide. Written so it can go to a director or an insurer without being translated first.
How it works
Deployment without a bad week.
The failure mode is a fleet-wide rollout that collides with one line-of-business application on a Monday. A pilot avoids it.
-
Pilot on a mixed dozen
A fortnight on a deliberately awkward sample: someone in accounts, someone in the field, a designer, one server. It surfaces the application conflicts while they are two tickets rather than sixty.
-
Roll out, then reconcile
Deployment across the fleet, then the unglamorous part that decides whether any of it worked: comparing what reports in against what you own, and chasing the difference until it is zero or written down with a reason.
-
Watch, tune, report
Detections route to our security operations centre under the containment authority you agreed. Rules are tuned monthly, coverage is rechecked, and you get a report you will actually read.
What it costs
Inside managed IT, or priced per device with monitoring.
The licence is the small number. The cost that matters is the human attention attached to it, which is the line most quotes leave out.
Endpoint protection is inside happier IT’s managed IT It is not a security tier you upgrade into, because a device without it is not a device we can look after honestly.
Bought as part of managed security
Where you already own a suitable licence inside a Microsoft plan, we will say so and manage what you have rather than selling you a second product to sit beside the first.
Two questions for any EDR quote
One: who looks at the detections, and during which hours? Two: are they permitted to isolate a machine without phoning first, and at what severity?
If the answers are "you do" and "not applicable", you are buying software rather than protection. That can be the right decision, just price it as software.
Why us for this
The detection is not the product. What happens next is.
Every provider in Canada can resell broadly the same handful of endpoint platforms, so the vendor badge on a proposal tells you very little. What differs is the twenty minutes after something fires at 2am.
happier IT’s analysts are our own employees, working from our security operations centre in Canada with your environment and your ticket history in front of them. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific. Time from detection to a person looking at it: minutes, not hours.
We will also tell you what this does not do. EDR will not stop someone typing a password into a convincing page, and it protects nothing on a device where it was never installed, jobs for phishing prevention and for the coverage number above.
Go deeper
- What is EDR? Endpoint detection and response, explained.
- Managed security services (MSSP) The people who read the detections.
- Intrusion detection and response What happens after an alert.
Questions
What people ask before they sign anything.
What is EDR?
EDR stands for endpoint detection and response: security software on each computer and server that watches behaviour, records what happened, and can act on its own. The recording matters as much as the detection, it is what lets someone answer "what did this actually touch" afterwards, which a traditional antivirus product cannot. There is a longer plain-English definition in our glossary entry on EDR.
What is the difference between EDR and antivirus?
Antivirus asks whether a file matches something known to be bad. EDR asks whether the behaviour on the machine makes sense, keeps a timeline of what happened, and can isolate the device from the network without waiting for a person. In practice the second one is what an insurance form is asking about. Modern EDR products include the antivirus function, so this is a replacement rather than an addition.
Does Microsoft Defender count as EDR?
The paid Defender for Endpoint tiers do; the free Defender Antivirus built into Windows does not, it is good signature-based antivirus, which is a different product with the same family name. The distinction is licensing, and it catches people out. Plenty of organizations already own the EDR tier inside a Microsoft 365 plan and have never switched it on. We check that before quoting anything else.
Will it slow our computers down?
On current hardware, not noticeably. The honest exception is machines already short of memory or running an old disk, where any additional agent is felt, and those machines were already frustrating your staff before we arrived. We measure boot and application-launch times on the pilot group before and after, and share the numbers rather than reassurance.
Who actually reads the alerts?
In most organizations under 200 people, nobody, and that is a staffing reality rather than a failing. Reading a detection console properly means someone available on a rota who knows what normal looks like in your environment. For happier IT clients that is our security operations centre in Canada, staffed by our employees. If you keep it in-house, decide who owns the console and what hours they cover, and write it down.
What does endpoint protection cost?
When comparing quotes, check whether the number includes servers, which are usually the more expensive agent and the more important one.
Related
Where to go next.
Related services
Worth reading
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.