What is EDR? A plain guide for Perth business owners

What is EDR? A plain guide for Perth business owners

Antivirus alone is not enough. Here is what Endpoint Detection and Response means for Perth SMEs, how it differs from “Defender is on”, and where to read our required-stack page.

Back to Blog

The Monday morning story we see too often

A Perth professional services firm opens for the week. Someone cannot open a shared folder. Then another. By 9:30 the office knows something is wrong. By 10:00 the ransom note is on the screen. The “antivirus” was installed. Nobody was watching behaviour. Nobody isolated a laptop on Saturday night when the encryption stage started.

That story is not rare. It is also not inevitable. Endpoint Detection and Response (EDR) exists to catch odd process behaviour early and put a human response around it. If you want the short product-style overview we use with clients, start at /security-standard/security-stack/edr/. This article is the longer owner’s guide: what to expect, what to demand, and how it fits a serious uplift program.

We will also point you to the Continual Security Uplift Program (see /one-plan/), because buying a tool without an operating rhythm is how Perth businesses end up with shelfware.

Owners often tell us they thought they were covered because a green icon sat in the system tray. Icons are not response. Response is someone who can act when the icon would have been useless anyway.

EDR in one kitchen-table explanation

Your staff work on endpoints: laptops, desktops, sometimes a server under the desk that should have been retired. Malware and ransomware still love those machines. They arrive through email, USB, cracked software, and drive-by downloads.

Traditional antivirus checks files against known bad signatures and basic heuristics. Useful. Incomplete. Attackers use living-off-the-land tricks: PowerShell, legitimate remote tools, scripts that look almost normal until they are not.

EDR records what processes do. It looks for chains of behaviour that match attack patterns. When confidence is high, it alerts. Managed EDR means someone investigates and can contain the device, not that you get a colourful email at 2am and a request to “please advise”.

You still need backups, patching, and least privilege. EDR is the smoke alarm and the night watch, not the building code. Skip the building code and the alarm just tells you the house is already on fire.

A simple test: if a laptop starts encrypting files at midnight, does anyone notice before staff arrive? If the honest answer is no, you do not have managed EDR yet. You have hope with a licence key.

Why Perth SMEs are not “too small”

Attackers automate. They do not sit in a room picking famous brands only. Credential lists, phishing kits, and ransomware affiliates scale down happily to a twelve-person firm in Belmont or a clinic in Joondalup.

Hybrid work expands the blast radius. Home Wi-Fi, shared family PCs, and travel laptops all hold work data. Without endpoint visibility, your provider only learns what users report. Users report late.

Insurers and larger customers ask sharper questions each year. They want to know whether devices are monitored and who responds. “We think it is fine” ages badly in a claim file.

The cost of a week offline usually dwarfs the cost of watched endpoints. Owners know this after an incident. The hard part is acting before the story becomes personal.

Why “we have Microsoft Defender” is only half an answer

Microsoft 365 Business Premium includes Defender for Business. Used well, with Intune enrolment and finished policies, it is strong. Many SMEs never finish the setup. Devices stay unmanaged. Exceptions pile up. Secure Score freezes.

Even with Defender healthy, ask who responds when a high-severity alert fires on a Sunday. Microsoft provides protection technology. Your operating model provides the humans and the playbooks. Managed EDR is how Stride IT closes that gap while still favouring Business Premium as the licence floor.

Layers beat slogans. Native Microsoft controls plus managed detection beats either alone. Common sense still wins: do not run daily work as admin, do not ignore patching, do not skip MFA.

Think of Business Premium as the floor of the house. EDR is the monitored alarm circuit. You still lock the doors. You still teach staff not to open every attachment. None of those jobs cancel the others.

A week in the life when EDR is working

Tuesday: a new laptop is enrolled before the user gets mailbox access. The agent shows healthy. No drama.

Thursday: a low-level alert for a suspicious script is investigated and closed as a legit admin task. The note is kept. Noise gets tuned.

Saturday night: ransomware-like behaviour starts on a sales device. The host is isolated. The payload is stopped. The user is contacted. Monday is annoying, not existential.

Quarterly review: directors see a short list of real investigations, coverage percentages, and uplift actions (for example, retiring a machine that cannot take modern controls). That is what good looks like. Boring on purpose.

Contrast that with a week where agents are missing on three machines, alerts sit unread, and the only “report” is a renewal invoice. Same spend category on a budget line. Completely different outcomes.

What bad endpoint “security” looks like in the wild

Two endpoint products fighting on one laptop. Neither configured. Both vendors blamed when something lands.

A shared inbox full of alerts that everyone assumes someone else reads. A policy that excludes the finance PC “because it is old and slow”. A server that never got an agent because it was “temporary” three years ago.

After-hours cover that is really “email us and we will look Monday”. Containment that requires a director’s signature while files are encrypting. Dashboards shown once in a sales meeting and never again.

If any of that sounds familiar, fix the operating model first. Buying another logo will not help.

Questions worth asking before you renew “security”

Who watches alerts after hours? What can they isolate without waiting for you? Which devices are out of scope? How do findings change your patching and hardening plan? Can they show last quarter’s endpoint incidents in plain English?

If the answer leans on you logging into yet another portal every morning, you are the analyst. Most owners did not sign up for that job.

Compare answers against our required-stack write-up at /security-standard/security-stack/edr/. Use it as a checklist in provider conversations, even if you are not our client yet.

Ask how new starters get coverage and how leavers lose it. Ask what happens when a staff member refuses enrolment on a personal device that still holds mail. Vague answers mean vague protection.

Where Continual Security Uplift comes in

Tools rot without a program. Continual Security Uplift is how we baseline, stabilise, and keep reviewing controls so Secure Score moves and gaps do not quietly reopen (see /one-plan/). EDR is required in that program, alongside ITDR, SIEM, and posture work.

We decline clients who want ticket-only MSP service with security left alone. That filter protects the clients who stay. If you want endpoints watched as part of a named Standard, not a one-off install, start with a Baseline application and read the EDR stack page again at /security-standard/security-stack/edr/.

Perth businesses do not need more fear. They need finished controls, measured detection, and providers who will say no when the floor is refused. EDR is part of that floor. Treat it that way and Monday mornings get quieter.

If you only remember one line from this guide, make it this: antivirus without watched response is a sticker. Managed EDR is a practice. Put the practice inside Continual Security Uplift and you can show directors what improved, not just what was installed.

Want the required-stack definition we run with clients? Read /security-standard/security-stack/edr/ and the Our One Plan.