Choosing and Deploying an EDR

What separates EDR from classic antivirus, what to look for when selecting, and why most deployments fail on operations rather than technology.

Endpoint protection is the area where most organisations believe they are fine because something is installed. Yet the gap between classic signature-based antivirus and EDR is an order of magnitude in what it sees and what it can do.

The difference

Antivirus EDR
What it looks for Known malware signatures Suspicious behaviour
Against zero-days No protection Partial protection
What it can do Quarantine Kill processes, isolate hosts
Investigation None Retrospective search
Fileless attacks Invisible Visible from the process chain

A significant share of modern attacks brings no file: they use legitimate system tooling (shells, scripting engines, administrative utilities). Signature-based protection cannot see these, because there is nothing to recognise.

What to look for when selecting

Whether it covers the whole estate. Windows, macOS, Linux servers, and legacy systems where present. A product covering only workstations is half a solution.

Whether retrospective search exists. If a new indicator of compromise emerges in three weeks, can it tell you whether it occurred in your environment? That requires retaining telemetry, not just alerts.

How many false positives. Only a pilot reveals this. Ask for a 30-day trial in your own environment, not a demo.

Whether it integrates with your SIEM. EDR is one of the densest signal sources. If it cannot export, it remains an isolated island. We covered this in our SIEM deployment article.

Who responds to alerts. The most important question, and not a technical one. If nobody is available to watch, you need a managed service (MDR) rather than a standalone product.

The common trap: an organisation buys the best EDR, deploys it, and leaves it in monitoring mode for fear of false blocks. Two years later it emerges nobody ever reviewed an alert. An unmonitored EDR is worth exactly nothing.

Deployment steps

1. Inventory. How many endpoints, running which operating systems? Deployment coverage is the key metric: 85 percent coverage means the attacker works on the remaining 15.

2. Monitoring mode. The first 2-4 weeks: the EDR logs and alerts without blocking. This reveals which legitimate tools trigger alerts.

3. Tuning. Every false positive requires a decision: exception, rule refinement or acceptance. Exceptions should be narrow, documented and periodically reviewed.

4. Gradual blocking. Starting with high-confidence detections, then widening.

5. Response process. Who receives the alert, what they do with it, when they escalate, and what happens at night and at weekends.

What gets forgotten

Post-deployment verification. Coverage must be reviewed regularly in the console. A new machine, a restored system, a forgotten server: something always slips through.

Tamper protection. An attacker's first act is disabling the EDR. Enabling tamper protection and alerting on disable attempts is a baseline requirement.

Servers. Many deployments stop at workstations, yet the attack continues on servers. EDR on the domain controller and file server is disproportionately valuable.

Legacy systems. Where no agent can be installed, compensating controls are needed: strict segmentation, enhanced network monitoring. In industrial environments this is the rule rather than the exception.

What to measure

  • Coverage: what percentage of the inventory runs and reports
  • Mean response time from alert to action
  • False positive rate after tuning
  • Tamper protection active on every machine

If coverage is below 98 percent, every other metric is theoretical. Our IT security services include designing and deploying endpoint protection architecture.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.