IT glossary

EDR (Endpoint Detection and Response)

EDR, or endpoint detection and response, is security software on laptops and servers that watches for suspicious behaviour and can isolate the machine.

An endpoint is simply any device a person uses. The name is unhelpful; it means “a computer”.

How it differs from antivirus

Traditional antivirus compares files against a list of known bad ones. That works until an attacker uses something not on the list, which is most of the time now.

EDR watches behaviour instead: a document that starts encrypting files, a process reaching out to an unfamiliar address, an account doing something at 4am it has never done before. It records what happened so it can be investigated afterwards, and it can cut the machine off the network automatically.

Why it matters to you

Two reasons. First, it is the control that most reliably limits the damage of a ransomware incident, because it can stop the spread before a person is involved. Second, it is now on almost every cyber-insurance questionnaire, and answering “no” to it affects your premium and sometimes your eligibility.

The thing to check

EDR is only as useful as the person reading its output. Software that flags a problem into an inbox nobody watches is a licence, not a defence. Ask who monitors it, and what happens overnight.

The service this relates to

See also

All terms

Still not sure what you actually need?

That is a normal place to start, and a 30-minute call usually settles it faster than more reading.