Service · Cybersecurity

Antivirus and EDR

Business antivirus is not better than the home kind because it catches more. It is better because somebody manages it. Twenty licences bought off the shelf and installed by hand mean twenty different configurations and at least one laptop whose protection quietly switched off back in March. EDR goes a step further: it keeps a record of activity on each machine, which means an intrusion can be interrupted mid-way and replayed step by step later.

One dashboard
every endpoint
EDR
behaviour, not only signatures
Quarantine
remote, in one click
Report
periodic

Included in this service

Installation is the smallest part of the job. What matters more is that somebody can see protection is running everywhere and knows what to do with an alert. We work with Microsoft Defender for Business and Defender for Endpoint, as well as ESET PROTECT, SentinelOne and comparable platforms.

Talk the scope through with an engineer

Central dashboard

A single view of every computer, server and phone: engine version, last check-in and most recent detection.

Workstations

Scanning of files, email and browsing, analysis of how processes behave, and tamper protection that stops anyone switching the agent off.

Servers

Dedicated policies and exclusions for the domain controller, the file server and the server hosting your Optima or Symfonia database. Each one needs different exclusions.

ASR rules

Attack surface reduction settings that stop Office macros arriving from the web, misuse of PowerShell and attempts to dump credentials from LSASS.

Endpoints gone quiet

Any machine that has not checked in for a longer period is flagged, and we track down what became of it.

Alert handling

Analysis of the detection, remote isolation of the computer, removal of the threat and a short report on what occurred.

How we work together

Pushing out agents is quick. The bulk of the effort is policy and exclusion work, not pushing agents out.

01

Selection

We choose a product that fits your needs and existing subscriptions. Quite often protection is already paid for within a Microsoft 365 plan and sits unused.

02

Deployment

Pushed out centrally via Intune or GPO, so nobody has to visit each PC. The old antivirus is removed with the same tooling.

03

Policies

Rules and exclusions. Poorly chosen exclusions on a database server are the usual reason for complaints that “everything has crawled since the new antivirus”.

04

Operations

We monitor endpoint health, deal with alerts Mon-Fri 8:00-18:00 CET or around the clock on the Premium plan, and send out reports.

Antivirus on its own will not save you from ransomware. It catches what is already known, while an attack aimed at a specific company is tested against the popular products in advance. Protection comes only from layering: EDR, minimal privileges, approved software only, and backups out of the intruder's reach.

Questions and answers

Go for whatever covers your needs and will actually be looked after day to day. Between established vendors, dashboards, reporting and support often differ more than detection does. Already on Business Premium? Then Defender for Business is the obvious place to begin.

Disconnect the computer from the network but leave it switched on, because powering down wipes traces from memory. From the dashboard, EDR cuts the machine off so it talks to nothing but the management service. Then the written procedure takes over, and it is far better drafted before anything goes wrong.

A five-person accounting office with a good, centrally managed antivirus can manage without it. Once you process customer data at scale, run production or fall under the KSC act, EDR is worth treating as standard, because it shows how an attack unfolded and lets you cut it short.

The EDR agent reports to the cloud, so a laptop at home or in a hotel shows up exactly as it would on the office LAN. We can trigger isolation and scans remotely wherever the device happens to be.

Take control of device protection

Tell us how many devices you have and which antivirus you use now. We will bring everything under one dashboard and shape the policies around your servers.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.