EDR: Endpoint Detection and Response

Managed endpoint detection with 24/7 human response, not antivirus left on its own.

Required for all clients

Endpoint Detection and Response (EDR) watches what actually runs on your laptops, desktops, and servers. It is not a green tick that antivirus is “on”. It is continuous behaviour monitoring with people ready to act when something looks wrong.

For Perth SMEs, that difference matters. Most ransomware still starts on a device someone uses every day. A finance laptop. A warehouse PC. A director’s notebook left open after a late email. Without EDR that someone is watching, you learn about trouble when files are encrypted or customers ring asking why invoices look odd.

At Stride IT we treat EDR as required stack under the Continual Security Uplift Program (see /one-plan/). It sits with ITDR and SIEM as part of the floor, not a nice-to-have you add after a scare. You can read the EDR page in context of the full stack at /security-standard/security-stack/edr/.

What EDR is, in plain terms

Think of antivirus as a bouncer with a guest list. It blocks known bad files. That helps. It is not enough. Attackers change names, pack malware in new ways, and abuse tools that already live on Windows. A guest list alone will miss that.

EDR is more like cameras plus a night desk. It records process activity, odd script use, and signs that something is trying to spread. When a pattern looks like ransomware prep or remote takeover, an alert fires. A human (or a managed security team you pay to stay awake) investigates. They isolate the machine if needed. They tell you what happened in English, not jargon dumps.

Good EDR does three jobs. Detect. Contain. Explain. Detection without response is just noisy logging. Response without detection is guessing. Explanation without either is a PDF nobody can use next quarter.

You still need patching, sensible admin rights, and backups you have tested. EDR does not replace those. It covers the gap between “the file looked fine” and “the file is encrypting shared drives”.

Why Perth SMEs get hit without it

Perth businesses are not too small to target. Attackers run automated scans and buy credential lists. They do not care that you are a ten-person accounting firm in Osborne Park or a trade business in Mandurah. If your Microsoft 365 tenant holds invoices, client data, or payroll, you are worth the effort.

Many local firms still run “antivirus that came with the PC” or a licence that expired two renewals ago. Nobody checks alerts because alerts go to a shared inbox nobody owns. A staff member opens a fake delivery notice. The payload runs. By Monday morning the shared drive is locked and the backup copy was never tested offline.

Hybrid work makes it worse. Laptops leave the office Wi-Fi. Someone works from a cafe. Someone’s kid installs a game on the home PC that also holds work files. Without endpoint visibility, your IT provider is flying blind until the help desk ticket says “nothing opens”.

Insurance questions are getting sharper too. Brokers ask whether endpoints are monitored and who responds after hours. “We think Defender is on” is a weak answer. Managed EDR gives you a clearer story: devices are enrolled, alerts are triaged, and containment is practised, not theorised.

Skip EDR and you favour hope over evidence. Hope is cheap until it is not.

What good looks like day to day

On a quiet day, good EDR is almost boring. Agents stay healthy. Patch status is visible. Low-noise alerts get closed with a short note. Your quarterly review shows a few investigated events and zero unresolved criticals.

When something real happens, the pace changes. An analyst sees a suspicious process chain on a sales laptop at 11pm. They isolate the host. They kill the bad process. They check whether the same hash or behaviour showed up elsewhere. You get a call or ticket with a plain summary: what ran, what was stopped, what you should reset (passwords, tokens, shared folders), and what to watch for tomorrow.

Staff feel almost nothing except, sometimes, a brief lockout while a machine is contained. That inconvenience beats rebuilding from backups. Directors see a short incident note in the next uplift review, not a surprise invoice and a shrug.

Good also means coverage. New laptops get the agent before they hit email. Offboarded devices get retired properly. Servers that still matter are enrolled, not “we will do those later”. Later is how gaps stay open.

What bad looks like

Bad looks like a dashboard nobody opens. Licences bought once, then forgotten. Alerts emailed to a generic address that filters to junk. An MSP who says “Defender is included” and never shows you response times or containment drills.

Bad also looks like tools fighting each other. Two endpoint products installed, both half configured, both blaming the other when something slips through. Or agents missing on the one device that holds the finance share.

The worst version is theatre. A colourful report once a year. No after-hours coverage. No isolation playbook. When ransomware hits on a Saturday, everyone discovers the “24/7” claim meant “someone might read email on Monday”.

If your provider cannot explain last month’s endpoint investigations in a few sentences, you do not have managed EDR. You have software sitting on a hard drive.

How it fits with Microsoft 365 Business Premium and Defender

Microsoft 365 Business Premium is our licence floor. It brings Defender for Business and a stack of identity and device controls you should finish, not leave half-set. That is real value. It is not a full managed detection service on its own.

Defender for Business gives strong native endpoint protection when policies are applied and devices are enrolled in Intune. Many Perth SMEs never finish that work. Policies sit in draft. Devices stay personal. Secure Score stalls. The product capability is there; the operating model is missing.

Managed EDR sits alongside that Microsoft layer. You keep Business Premium controls. You add always-on detection and human response for behaviours that need eyes after hours. You do not throw away common sense: MFA still matters, admin accounts stay separate, and backups stay tested.

Think layers, not silver bullets. Business Premium hardens the estate. EDR watches runtime behaviour. ITDR watches identity abuse (see /security-standard/security-stack/itdr/). SIEM correlates signals so one weird login plus one weird process becomes one investigation (see /security-standard/security-stack/siem/). None of that replaces staff who know not to approve a fake MFA prompt.

What directors should ask their IT provider

Ask who sees endpoint alerts at 2am on a Sunday, and what they are authorised to do without waiting for your approval. Ask how fast a compromised laptop can be isolated. Ask for last quarter’s real incidents, not a marketing slide.

Ask which devices are covered and which are not. Ask how new starters get the agent and how leavers lose access. Ask whether servers and shared workstations are included or “out of scope” for budget reasons.

Ask how EDR findings feed back into patching and hardening. A contained ransomware attempt that never leads to a fix is a warning you ignored. Ask for the link to your Continual Security Uplift roadmap so detections become permanent control changes.

If answers are vague, priced as endless extras, or depend on you reading dashboards yourself, keep shopping. Directors should buy outcomes: watched endpoints and measured response, not another portal password.

How EDR ties to Continual Security Uplift

The Continual Security Uplift Program is how Stride IT keeps controls finished and Secure Score moving. EDR is not a one-off install at onboarding. It is baseline, then stabilise, then quarterly review (see /one-plan/).

In Baseline we check coverage and response readiness. In Stabilise and Uplift we enrol devices, tune noise, and prove containment works. In Continual reviews we show what was investigated, what was fixed, and what still needs hardware or policy work.

EDR also supports the Stride IT Security Standard story you can show clients and insurers: endpoints are not hope-based. They are monitored under a named program with a mark process that is honest about what it is and is not.

If you will not run EDR, we decline. Loudly and early. That is how we keep the Standard real for the clients who stay. More on the required stack sits at /security-standard/security-stack/, with this capability detailed at /security-standard/security-stack/edr/.

EDR will not make you unhackable. Nothing will. It will make “something weird on a laptop” into a handled event instead of a quiet disaster. For Perth businesses serious about uplift, that is the floor, not the ceiling. Talk to us about Baseline if you want that floor under written outcomes, not ticket theatre.

Further reading

What is EDR? A plain guide for Perth business owners

A longer owner’s guide on the same topic, written for Perth businesses comparing providers.

Read the blog

WHAT YOU GET

Faster containment when something nasty runs on a device.

Evidence you can show insurers and boards: endpoints are watched, not just scanned.

Fewer “we found it on Monday” surprises after a weekend breach.

FREQUENTLY ASKED QUESTIONS

Is EDR required for Stride IT clients?

Yes. Endpoint Detection and Response (EDR) is required for every client under the Stride IT Security Standard. It is not an optional add-on. If you will not run it, we decline.

How does EDR fit Our One Plan?

EDR is part of the required detection and posture stack inside Our One Plan. It sits on top of Microsoft 365 Business Premium. We baseline it in the Baseline Review, implement it during Stabilise and Uplift, and review it in quarterly Continual reviews.

Do you sell this as a standalone product?

No. This stack runs as part of Our One Plan with Continual Security Uplift. We do not cherry-pick detection controls while leaving the rest of the Standard unfinished.

THE REST OF THE STACK

APPLY FOR BASELINE

We confirm Business Premium readiness and the full required stack, including EDR, before we start.

Apply for Our One Plan

Still here? Apply for Our One Plan.

Baseline is an application, not a shopping cart. We confirm Business Premium readiness, the required stack (EDR, ITDR, SIEM, SAT, ESPM, ISPM), map Secure Score to the Stride IT Security Standard, and show a tailored uplift plan and schedule. If you will not support the minimum, we decline. Early, clearly, and without drama.