IT glossary
EDR (Endpoint Detection and Response)
EDR, or endpoint detection and response, is security software on laptops and servers that watches for suspicious behaviour and can isolate the machine.
An endpoint is simply any device a person uses. The name is unhelpful; it means “a computer”.
How it differs from antivirus
Traditional antivirus compares files against a list of known bad ones. That works until an attacker uses something not on the list, which is most of the time now.
EDR watches behaviour instead: a document that starts encrypting files, a process reaching out to an unfamiliar address, an account doing something at 4am it has never done before. It records what happened so it can be investigated afterwards, and it can cut the machine off the network automatically.
Why it matters to you
Two reasons. First, it is the control that most reliably limits the damage of a ransomware incident, because it can stop the spread before a person is involved. Second, it is now on almost every cyber-insurance questionnaire, and answering “no” to it affects your premium and sometimes your eligibility.
The thing to check
EDR is only as useful as the person reading its output. Software that flags a problem into an inbox nobody watches is a licence, not a defence. Ask who monitors it, and what happens overnight.