Endpoint detection and response (EDR) is security software on every laptop, desktop and server that records what the machine is doing, spots attack behavior that signature-based antivirus misses, and lets someone isolate or roll back the machine remotely. A small business needs it for two practical reasons: the attacks that hurt small businesses now arrive as legitimate-looking activity rather than as a known virus file, and cyber insurance underwriters increasingly ask whether you have EDR before they will quote you.

Los Angeles based since 2007 · Channel Futures MSP 501 ranked · CA License #1140088

What is endpoint detection and response?

EDR does three things antivirus does not. It records endpoint activity continuously, so there is a history to investigate after an alert. It judges behavior rather than files, so an attack made entirely of built-in Windows tools still gets flagged. And it can act: isolate the machine from the network, kill a process, or roll back changes, without anyone driving to the office.

The short version of how the category got here: signature-based antivirus arrived in the late 1980s and worked as long as malware was a file with a known fingerprint. Next-generation antivirus added machine learning and behavioral analysis to catch what had no signature yet. EDR, from the mid 2010s, added the recording, the investigation, and the response. Each layer exists because the previous one stopped being sufficient, not because the previous one stopped working. If you want the longer comparison, we wrote up the difference between antivirus and antimalware.

How is EDR different from the antivirus we already have?

Question Traditional antivirus EDR
What it looks for Known bad files Suspicious behavior, including activity made of legitimate tools
What happens after an alert The file is quarantined You can see what ran before and after, and act on the machine remotely
History for investigation Little to none Continuous recording of process, file and network activity
Ransomware Catches known families Flags the encryption behavior itself, and can roll changes back
Who reads it Nobody, usually A monitored deployment routes alerts to an analyst

That last row is the one businesses get wrong. EDR that nobody watches is a very good recording of an incident you found out about late.

Who needs EDR, and who can wait?

Buy it now if you hold regulated or confidential client data, if you are renewing cyber insurance, if you have staff working on laptops outside the office, or if a client has sent you a security questionnaire. Insurance is the forcing function for a lot of Los Angeles businesses: underwriters increasingly treat EDR as a prerequisite for coverage rather than a discount item, which reflects how much of the loss they are trying to avoid.

Wait if you have no multi-factor authentication yet. MFA on email and remote access is cheaper, faster, and closes a more common path in. Do that first, then EDR.

Do not buy EDR as a standalone if nobody is going to monitor it. Either take a monitored deployment or accept that you have bought a forensic tool rather than a defense.

What does EDR cost?

At Be Structured, EDR is part of the managed security stack rather than a line item you buy alone. That stack is priced per device, commonly $50 per device per month, and includes EDR with 24/7 SOC monitoring, multi-factor authentication, Windows Defender hardening and LAPS, spam and outbound email filtering, SPF, DKIM and DMARC management, dark web monitoring, quarterly internal and external vulnerability scanning, and Microsoft 365 backup with disaster recovery. Managed IT sits underneath it at $125 to $300 per user per month depending on headcount and coverage depth. The full picture, including what is billed separately, is on our managed IT services cost page.

Per device rather than per user matters here. A firm with 20 people and 45 devices pays for the 45 things an attacker can land on, not the 20 chairs.

What changes on day one?

Agents deploy quietly, usually inside one business day, and users notice nothing. What changes is on the other side: within the first week you get a picture of what is running on machines nobody had looked at in years, and that first report is routinely the most useful artifact of the engagement.

The second change is what happens during an incident. Instead of asking a user to unplug the network cable and hoping, an engineer isolates the machine from a console in seconds while the rest of the office keeps working. We wrote about how managed EDR services change business cybersecurity in more detail.

Monitored EDR or unmonitored?

We offer both, and the choice is about who reads the alerts.

Monitored EDR routes detections into our 24/7 Security Operations Center as a Service. After-hours issues are triaged in about 10 minutes, and containment steps we are pre-authorized to take are agreed in writing before anything happens. This is the right choice for almost everyone without a security team.

Unmonitored EDR gives your own staff the tooling and the console. It makes sense when you have people who will actually watch it, which in practice means an internal team with a security remit and a rotation.

Either way, EDR is standard in our managed service provider and managed security service provider engagements. We do not sell environments without it.

How to evaluate an EDR provider

  1. Ask who watches it and when. Get the after-hours answer specifically, and get a target time to first human touch.
  2. Ask what they can do without calling you. Isolating a host, killing a process and disabling an account should be pre-authorized in writing, by severity.
  3. Ask how long the telemetry is retained. Investigation needs history. Thirty days is thin if an intrusion sat quiet for two months.
  4. Ask about servers, not just laptops. Coverage that stops at workstations leaves the machine holding your data uncovered.
  5. Ask what your insurer needs to see. A provider that has filled in a cyber insurance application before will know which questions the deployment has to answer.
  6. Ask what happens to the data if you leave. Your incident history should not be hostage to a renewal.

EDR from Be Structured, in Los Angeles

Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA. Our team deploys, tunes and monitors EDR as part of a scoped security stack, and our local presence means that when an incident needs hands on a device rather than a console, we reach most of the LA area in roughly 30 minutes.

If you are comparing us against the rest of the market, our page on how to evaluate outsourced IT support is written to be used against us as well as everyone else.

➤ Get Your Free IT Assessment: contact Be Structured to scope EDR for your environment, or call (323) 331-9452.

Frequently Asked Questions About EDR

What is endpoint detection and response (EDR)?

EDR is security software on every laptop, desktop and server that records what the machine is doing, detects attack behavior rather than only known bad files, and lets an engineer isolate the device, kill a process or roll back changes remotely. The recording is what makes an alert investigable, and the remote action is what makes containment fast.

How is EDR different from antivirus?

Antivirus looks for known bad files and quarantines them. EDR judges behavior, so an attack built entirely from legitimate Windows tools still gets flagged, keeps a continuous history of process, file and network activity so you can see what happened before and after an alert, and can act on the machine remotely. Antivirus answers what was that file. EDR answers what happened on this computer.

Does a small business really need EDR?

If you hold regulated or confidential client data, have staff on laptops outside the office, or are renewing cyber insurance, yes. Underwriters increasingly treat EDR as a prerequisite for coverage rather than a discount item. If you do not yet have multi-factor authentication on email and remote access, do that first: it is cheaper, faster, and closes a more common way in.

How much does EDR cost?

At Be Structured, EDR is part of a managed security stack priced per device, commonly $50 per device per month, which also includes 24/7 SOC monitoring, multi-factor authentication, Windows Defender hardening and LAPS, email filtering, SPF, DKIM and DMARC management, dark web monitoring, quarterly vulnerability scanning, and Microsoft 365 backup with disaster recovery. Managed IT sits underneath at $125 to $300 per user per month.

Why is EDR priced per device instead of per user?

Because an attacker lands on a device, not on a chair. A 20-person firm often runs 45 endpoints once you count servers, laptops, a workstation for a shared function, and the machine in the back that runs one piece of software. Per-device pricing counts the things that need an agent.

Do we need someone monitoring EDR, or can we run it ourselves?

Both are possible, and the difference is who reads the alerts. Monitored EDR routes detections to our 24/7 Security Operations Center, where after-hours issues are triaged in about 10 minutes and pre-authorized containment steps are agreed in writing in advance. Unmonitored EDR gives your own staff the console, which only works if you have people with a security remit and a rotation. Unmonitored EDR that nobody watches is a very good recording of an incident you found out about late.

Does EDR stop ransomware?

It changes the outcome more often than not, because it flags the encryption behavior itself rather than waiting to recognize a specific ransomware family, and because isolation from a console stops the spread in seconds. It is not a guarantee, and it is not a substitute for immutable, offsite and tested backups. The pairing is what gets a business back to work.

Will EDR slow down our computers?

Modern agents are light and users typically notice nothing after deployment. Deployment itself usually completes inside one business day. What people do notice is the first report, which routinely shows software running on machines nobody had audited in years.

What should we ask an EDR provider before signing?

Who watches it after hours, and what is the target time to first human touch. What the provider is pre-authorized to do without calling you. How long telemetry is retained, since an intrusion that sat quiet for two months needs more than thirty days of history. Whether servers are covered, not just laptops. What your cyber insurer needs to see. And what happens to your incident history if you leave.