Cyber Explained

What is EDR — and how is it different from antivirus?

You may have been told antivirus isn’t enough any more, and that you need “EDR.” Here’s what that means, in plain English.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Supporting 130+ organisations since 2006
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

EDR (Endpoint Detection and Response) is next-generation security for your computers and laptops. Traditional antivirus looks for known viruses; EDR watches the behaviour of your devices in real time, spots suspicious activity (even brand-new threats), and can automatically isolate a device and roll back an attack. For today’s threats — ransomware, fileless attacks, stolen credentials — EDR is far more effective than antivirus alone, which is why it’s now expected for Cyber Essentials and cyber insurance.

The difference

EDR vs antivirus

Traditional antivirusEDR
Looks forKnown viruses (a “wanted list”)Suspicious behaviour, even brand-new threats
ReactsAfter infectionIn real time, as it happens
Can it isolate a device?NoYes — automatically, to stop spread
Can it roll back an attack?NoOften, yes
Good against ransomware?LimitedStrong

Why it matters

The threats have changed

Modern attacks often don’t use a “virus” at all — they abuse legitimate tools, stolen passwords and brand-new malware that antivirus has never seen. EDR catches the behaviour, not just the signature, which is why it stops things traditional antivirus misses. It’s now effectively expected to pass Cyber Essentials and to satisfy cyber-insurance questionnaires.

Managed EDR

EDR plus a team watching it

EDR is most powerful when it’s managed — monitored by a team (or SOC) who respond when it flags something, day or night. That’s part of our 24/7 monitoring and wider cyber security services. Want to see where you stand today? Try our free risk scan.

FAQs

Common questions

What is EDR?
EDR (Endpoint Detection and Response) is advanced security for computers and laptops that monitors device behaviour in real time, detects suspicious or brand-new threats, and can automatically isolate a device and roll back an attack.
What’s the difference between EDR and antivirus?
Antivirus looks for known viruses from a list; EDR watches behaviour and catches new and fileless threats, reacts in real time, and can isolate devices and reverse damage — far more effective against modern attacks like ransomware.
Do I still need antivirus if I have EDR?
EDR typically includes and replaces traditional antivirus — it does everything antivirus does and much more. You don’t run both separately.
Is EDR required for Cyber Essentials?
Cyber Essentials requires effective malware protection, and modern EDR is the standard way to meet that bar. Insurers increasingly expect it too.
What is managed EDR or MDR?
Managed EDR (sometimes called MDR) is EDR monitored and responded to by a security team or SOC around the clock, so threats are actioned immediately rather than just logged.

Is your endpoint protection up to the job?

Get a free risk scan, or talk to us about managed EDR and 24/7 monitoring.