Every computer in your business almost certainly has antivirus on it right now. So did almost every business that got ransomed last year. The uncomfortable fact of modern security is that antivirus software, installed and forgotten, protects you against the attacks of ten years ago, while today’s attackers design their work specifically to walk past it: stolen passwords, legitimate tools used maliciously, staff persuaded to click things, malware built fresh for each campaign.
The fix is not better software alone; it is software plus watching. Managed antivirus and EDR means your endpoint protection is chosen, configured, monitored and responded to by people whose job it is: alerts investigated the day they fire, machines isolated the moment something real appears, and the whole estate covered rather than most of it. This page explains the layers and what buying them as a service looks like.
AV, EDR, MDR: the jargon sorted
Three acronyms cover the whole conversation:
Antivirus (AV)
The classic layer: software that recognises and blocks known malicious files. Still necessary; nowhere near sufficient. Its blind spot is anything that does not look like known malware, which is precisely where serious attacks now live.
EDR (Endpoint Detection and Response)
The modern layer: instead of only matching known-bad files, EDR watches behaviour on each machine. A user account suddenly encrypting hundreds of files, a Word document spawning system commands, a login at 3am from an odd location: EDR flags and can automatically contain the pattern (isolating the machine from the network) even when no known malware is involved. This behavioural approach is why EDR catches the ransomware run and the stolen-credential intrusion that AV waves through.
MDR (Managed Detection and Response)
Not another tool, but the human layer: EDR generates detections, and someone qualified has to triage them, dismiss the false alarms, and act on the real ones fast. MDR is that someone, around the clock. Without it, EDR is a smoke alarm in an empty building.
Our managed service delivers the stack: business-grade AV and EDR deployed on every machine, with the monitoring and response layer handled as part of your support.
Why “managed” is most of the value
Four failure modes account for nearly every endpoint-security disaster we audit, and none of them are software problems:
Coverage gaps. Protection on most machines: not the warehouse PC, not the director’s home laptop, not the server everyone forgot is a computer. Attackers need one gap; managed deployment means the coverage list is maintained, not remembered.
Nobody reads the alerts. Unmanaged consoles accumulate warnings like an unwatched inbox. The breach post-mortems are brutal on this point: the alert usually fired, days before the damage, into a void. Managed means every detection is triaged by an engineer, and the real ones become immediate action.
Silent decay. Agents stop updating, licences lapse, a machine rebuild skips reinstallation, exclusions added “temporarily” in 2023 remain. Managed protection is health-checked continuously, so decay becomes a ticket instead of a discovery.
No response plan. Detection without response is spectating. Our arrangement pairs containment (automatic isolation of suspect machines) with the escalation path: what happens next, who is told, and how the incident response plan engages if it is real.
Where this sits in your defences
Endpoint protection is one layer of several, and honesty requires saying so: it pairs with enforced MFA (the control that blocks stolen-password logins), prompt patching, staff phishing training, and tested, immutable backups as the layer of last resort. The full stack is our cyber security service; EDR is also increasingly assumed by cyber insurers, whose questionnaires now ask for it by name, and it satisfies the malware-protection control in Cyber Essentials with room to spare.
For ransomware specifically (the scenario this layer most visibly earns its keep against), our ransomware protection guide shows how the layers interlock.
What it costs
Managed endpoint protection prices per device per month: UK market rates for the AV+EDR layer typically run £3 to £8 per device, with the monitored response component either bundled into managed support (as it is in our plans) or priced on top by standalone providers. For a 20-machine business, call it under £150 a month for the complete layer: set against the going rate for a single ransomware recovery, the arithmetic does not require a spreadsheet.
If you already pay for Microsoft 365 Business Premium, note that Defender for Business is included in the licence: one of the reasons the Premium tier comparison matters. Managed properly, it is a genuinely capable EDR; unconfigured, it is a checkbox. Either way the managing is the part that was missing.
Frequently asked questions
What is managed antivirus?
Endpoint protection delivered as a service: software selected and deployed across every device, kept healthy, with alerts monitored and acted on by engineers rather than accumulating unseen. The management is the difference between owning a control and having one.
What’s the difference between antivirus and EDR?
Antivirus blocks known malicious files. EDR watches machine behaviour and catches attacks that use no known malware at all: stolen credentials, abused legitimate tools, fresh ransomware. Modern protection needs both, plus someone watching.
Is Windows Defender enough for a business?
The consumer Defender built into Windows is respectable AV and better than its reputation, but it is unmanaged and un-monitored by default. The business-grade Defender in M365 Business Premium, properly configured and watched, is a different proposition, and a competitive one.
Do insurers require EDR?
Increasingly, yes: cyber insurance questionnaires now commonly ask about EDR or “endpoint detection and response” by name, alongside MFA and tested backups. Gaps show up as premium loading, conditions, or declined claims.
What happens when something is detected?
Triage first (a meaningful share of detections are false alarms; dismissing them well is a skill), then for real threats: automatic isolation of the machine, investigation of scope, removal, and restoration, with you informed in plain English throughout rather than left to decode a console.
How disruptive is rollout?
Not very: agents deploy remotely to all machines, typically inside a day, with no user action needed. The visible change is the occasional blocked file and the absence of drama thereafter.
Find out what your current AV is missing
The audit takes minutes per machine and regularly embarrasses green ticks: coverage gaps, dead agents, alert backlogs nobody has opened. It is part of our free IT health check, with plain findings and a per-device price to fix the layer properly. Get in touch before someone else tests your endpoints first.