Skip to main content

What Is EDR? Endpoint Detection and Response vs Antivirus, Explained.

6 min read
By Houston IT Developers
Laptop screen and keyboard on a tidy office desk lit by soft daylight from a window

EDR appears on every security quote and in every insurance questionnaire, usually with no explanation. Here is what it is, why antivirus stopped being enough, and how to tell whether you are getting the managed version or just the software.

What EDR stands for

Endpoint Detection and Response.

An endpoint is any device somebody works on — laptop, desktop, server. EDR software sits on that device and does three things: continuously records what is happening, flags behaviour that looks like an attack, and gives someone the ability to act on it.

That third word is the one people skip. Detection without response is a smoke alarm in an empty house.

Why antivirus stopped being enough

Traditional antivirus works by comparison. It holds a list of known-bad files and checks what lands on your machine against that list. When malware meant a file somebody downloaded, this worked reasonably well.

Two things broke it.

Attacks stopped using files. The common pattern now is "living off the land" — an intruder uses the legitimate tools already on your computer. PowerShell, Windows Management Instrumentation, the built-in administrative utilities your IT team relies on. There is no malicious file to match against, because every program involved is one Microsoft shipped.

Malware became disposable. Generating a unique variant per target is trivial now. A signature list is always describing attacks that already happened to somebody else.

EDR asks a different question. Not is this file on the bad list, but is this behaviour normal. A document opening a command shell which then reaches out to an unfamiliar server and starts touching files across a network share is suspicious regardless of whether any single component is known malware. That chain is what EDR catches.

It also records. After an incident, the difference between "we think nothing was taken" and "we can demonstrate what was and was not accessed" is whether anything was logging. That distinction has real legal and disclosure consequences.

EDR vs the other acronyms

TermWhat it means
AV / NGAVBlocks known-bad files. Next-gen AV adds some behavioural analysis
EDRBehavioural detection + recording + response tools, on endpoints
XDRThe same idea extended across identity, email, cloud and network
MDREDR (or XDR) plus a 24/7 team who investigate and respond for you

Nearly every EDR product includes antivirus, so this is not an either/or purchase — EDR supersedes AV rather than sitting beside it. MDR is the service wrapper, and for a small business it is usually the one that matters.

Unmanaged vs managed EDR

This is where money gets wasted, so it is worth being blunt.

Unmanaged EDR gives you a console and an alert feed. Someone at your company must watch it, understand which of the day's detections are real, and act within minutes when one is. Continuously. Including at 2am, on holidays, and while that person is on leave.

That is a genuine job. It is not a thing your office manager does between other duties, and it is not a thing a one-person IT department does overnight. Businesses buy excellent EDR, nobody reads the console, and eighteen months later an incident is discovered by a customer. The software worked exactly as designed and detected the intrusion on day one.

Managed EDR attaches a security operations centre to the same software. Analysts triage every detection and contain the real ones, with the authority to isolate a machine without waiting for you.

Test for it with one question: will you isolate a compromised machine without calling me first? If the answer is no, you are buying software and a dashboard.

What it costs

Published vendor list prices:

ProductPublished price
Huntress Managed EDR$7.99 / endpoint / mo (100-endpoint tier, 50 minimum direct)
CrowdStrike Falcon Go$7.99 / device / mo (max 100 devices)
CrowdStrike Falcon Pro$14.99 / device / mo
CrowdStrike Falcon Enterprise$19.99 / device / mo
CrowdStrike Falcon Complete (managed)Quote only
SophosNo published per-endpoint price

Delivered by a provider who also monitors it, expect roughly $10–$30 per endpoint per month, or $25–$55 per user per month bundled with email security, identity protection and awareness training. For a fuller breakdown see how much CrowdStrike costs and our vendor comparison.

Note the difference between per endpoint and per user. A person with a laptop, a desktop and a tablet is one user and three endpoints. Below about 100 staff, per-user bundles are usually cheaper.

What EDR does not do

  • It does not back anything up. No major EDR vendor sells backup — not Huntress, not CrowdStrike, not Sophos. If ransomware encrypts a file server, EDR stops the spread; restoring data is a backup problem.
  • It does not filter email. Neither Huntress nor CrowdStrike ships an email gateway. That is a separate product.
  • It does not replace a firewall. CrowdStrike's "firewall management" centrally manages the firewall already built into Windows and macOS. It is not a perimeter appliance.
  • It does not stop invoice fraud. If a member of staff is talked into wiring money to a fake supplier, no detection fires anywhere. That is a training and process problem.
  • It cannot protect a device it is not installed on. Personal laptops and unmanaged servers are invisible.

Does a small business need it?

Two separate answers, both usually yes.

Commercially, it is becoming mandatory whether or not you agree with the reasoning. Cyber-insurance applications ask whether you run EDR, and the answer affects your premium or your eligibility. Enterprise client security questionnaires ask the same. At that point EDR is a cost of doing business.

Practically, EDR catches the category of attack antivirus structurally cannot see. Small businesses are not targeted less than large ones — they are targeted more, because the tooling is automated and they are known to be softer. What differs is that they find out later.

The realistic question is not whether to run EDR but whether anyone is watching it.


We deploy and monitor managed EDR on every endpoint for Houston businesses and remotely nationwide, with a 24/7 SOC behind it and the authority to contain a threat at 3am without waiting for you. It is part of our managed cybersecurity plan and bundles with managed IT. A free security assessment will tell you what is protecting your machines right now — including which agents have quietly stopped reporting.

Houston IT Developers

Houston IT Developers

Houston IT Developers is a leading software development and digital marketing agency based in Houston, Texas. We specialize in web development, mobile apps, and digital solutions.

View all posts →

Need Help With Your Project?

Our team of experts is ready to help you build your next web or mobile application. Get a free consultation today.

Get in Touch

Related Posts