Endpoint detection and response (EDR) is security software on every laptop, desktop and server that records what the machine is doing, spots attack behavior that signature-based antivirus misses, and lets someone isolate or roll back the machine remotely. A small business needs it for two practical reasons: the attacks that hurt small businesses now arrive as legitimate-looking activity rather than as a known virus file, and cyber insurance underwriters increasingly ask whether you have EDR before they will quote you.
Los Angeles based since 2007 · Channel Futures MSP 501 ranked · CA License #1140088
What is endpoint detection and response?
EDR does three things antivirus does not. It records endpoint activity continuously, so there is a history to investigate after an alert. It judges behavior rather than files, so an attack made entirely of built-in Windows tools still gets flagged. And it can act: isolate the machine from the network, kill a process, or roll back changes, without anyone driving to the office.
The short version of how the category got here: signature-based antivirus arrived in the late 1980s and worked as long as malware was a file with a known fingerprint. Next-generation antivirus added machine learning and behavioral analysis to catch what had no signature yet. EDR, from the mid 2010s, added the recording, the investigation, and the response. Each layer exists because the previous one stopped being sufficient, not because the previous one stopped working. If you want the longer comparison, we wrote up the difference between antivirus and antimalware.
How is EDR different from the antivirus we already have?
| Question | Traditional antivirus | EDR |
| What it looks for | Known bad files | Suspicious behavior, including activity made of legitimate tools |
| What happens after an alert | The file is quarantined | You can see what ran before and after, and act on the machine remotely |
| History for investigation | Little to none | Continuous recording of process, file and network activity |
| Ransomware | Catches known families | Flags the encryption behavior itself, and can roll changes back |
| Who reads it | Nobody, usually | A monitored deployment routes alerts to an analyst |
That last row is the one businesses get wrong. EDR that nobody watches is a very good recording of an incident you found out about late.
Who needs EDR, and who can wait?
Buy it now if you hold regulated or confidential client data, if you are renewing cyber insurance, if you have staff working on laptops outside the office, or if a client has sent you a security questionnaire. Insurance is the forcing function for a lot of Los Angeles businesses: underwriters increasingly treat EDR as a prerequisite for coverage rather than a discount item, which reflects how much of the loss they are trying to avoid.
Wait if you have no multi-factor authentication yet. MFA on email and remote access is cheaper, faster, and closes a more common path in. Do that first, then EDR.
Do not buy EDR as a standalone if nobody is going to monitor it. Either take a monitored deployment or accept that you have bought a forensic tool rather than a defense.
What does EDR cost?
At Be Structured, EDR is part of the managed security stack rather than a line item you buy alone. That stack is priced per device, commonly $50 per device per month, and includes EDR with 24/7 SOC monitoring, multi-factor authentication, Windows Defender hardening and LAPS, spam and outbound email filtering, SPF, DKIM and DMARC management, dark web monitoring, quarterly internal and external vulnerability scanning, and Microsoft 365 backup with disaster recovery. Managed IT sits underneath it at $125 to $300 per user per month depending on headcount and coverage depth. The full picture, including what is billed separately, is on our managed IT services cost page.
Per device rather than per user matters here. A firm with 20 people and 45 devices pays for the 45 things an attacker can land on, not the 20 chairs.
What changes on day one?
Agents deploy quietly, usually inside one business day, and users notice nothing. What changes is on the other side: within the first week you get a picture of what is running on machines nobody had looked at in years, and that first report is routinely the most useful artifact of the engagement.
The second change is what happens during an incident. Instead of asking a user to unplug the network cable and hoping, an engineer isolates the machine from a console in seconds while the rest of the office keeps working. We wrote about how managed EDR services change business cybersecurity in more detail.
Monitored EDR or unmonitored?
We offer both, and the choice is about who reads the alerts.
Monitored EDR routes detections into our 24/7 Security Operations Center as a Service. After-hours issues are triaged in about 10 minutes, and containment steps we are pre-authorized to take are agreed in writing before anything happens. This is the right choice for almost everyone without a security team.
Unmonitored EDR gives your own staff the tooling and the console. It makes sense when you have people who will actually watch it, which in practice means an internal team with a security remit and a rotation.
Either way, EDR is standard in our managed service provider and managed security service provider engagements. We do not sell environments without it.
How to evaluate an EDR provider
- Ask who watches it and when. Get the after-hours answer specifically, and get a target time to first human touch.
- Ask what they can do without calling you. Isolating a host, killing a process and disabling an account should be pre-authorized in writing, by severity.
- Ask how long the telemetry is retained. Investigation needs history. Thirty days is thin if an intrusion sat quiet for two months.
- Ask about servers, not just laptops. Coverage that stops at workstations leaves the machine holding your data uncovered.
- Ask what your insurer needs to see. A provider that has filled in a cyber insurance application before will know which questions the deployment has to answer.
- Ask what happens to the data if you leave. Your incident history should not be hostage to a renewal.
EDR from Be Structured, in Los Angeles
Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA. Our team deploys, tunes and monitors EDR as part of a scoped security stack, and our local presence means that when an incident needs hands on a device rather than a console, we reach most of the LA area in roughly 30 minutes.
If you are comparing us against the rest of the market, our page on how to evaluate outsourced IT support is written to be used against us as well as everyone else.
➤ Get Your Free IT Assessment: contact Be Structured to scope EDR for your environment, or call (323) 331-9452.
