What antivirus does, and what it misses
Traditional antivirus works like a bouncer with a photo book. It scans files against a list of known bad software and blocks matches. Modern versions add some behavior checks, and the free protection built into Windows and macOS is genuinely decent at this job.
What it misses is everything that does not look like a known virus. Most real intrusions today do not drop an obvious malware file — the attacker signs in with a stolen password, uses the legitimate tools already on the machine, and moves quietly. To a photo-book bouncer, that is just an ordinary customer. Antivirus also tells you almost nothing afterward: it blocked something or it did not, with no story of what happened before or since.
What EDR adds, in plain English
EDR — endpoint detection and response — is less a bouncer and more a security camera with a guard who can act. It records what happens on the machine continuously: which programs started, what they touched, what network connections opened. When a pattern looks like an attack in progress — even one using legitimate tools — it raises an alert, and a responder can isolate the machine from the network with one click before the problem spreads.
The honest translation: antivirus tries to stop known bad files at the door; EDR watches behavior so someone can catch and cut off an intrusion that got past the door. The response part is the point, which leads to a question most vendors skip past: responded to by whom?
What insurers now expect
If you carry cyber insurance or plan to, this decision may not be entirely yours anymore. Insurance applications now routinely ask whether you run EDR across your computers, alongside MFA and backups, and your answers become part of the policy. Answer yes carelessly and a later claim can be contested; answer no and you may see higher premiums or thinner coverage.
Requirements vary by insurer and by your industry — a firm handling government or health-related data will face sharper questions than a retail shop. The practical takeaway is to read your own application before buying anything, because it is effectively a checklist of what your insurer considers baseline, and it may already require EDR whether or not anyone told you plainly.
What it costs per seat
Realistic numbers, hedged as ranges because vendors negotiate.
- Built-in antivirus: free, already on your machines, worth configuring properly.
- Business antivirus suites: roughly 2 to 5 dollars per computer per month.
- EDR software on its own: roughly 4 to 15 dollars per computer per month depending on tier.
- Managed detection and response, meaning EDR plus a 24-7 human team watching it: roughly 10 to 30 dollars per computer per month.
For a 10-person business, the difference between decent antivirus and fully managed EDR is therefore about 100 to 250 dollars a month. Compare that to the going cost of a single email-compromise incident, which routinely runs into five figures once you count the fraud loss, the cleanup, and the week of lost work.
The alerts problem: who is watching?
Here is the part that decides whether EDR is worth anything: the alerts have to be seen. EDR without a person watching is a security camera recording an empty guard room. Alerts arrive at 2am, weekends included, and they need judgment — is this the bookkeeper running a new report tool, or an intruder?
A small business has three honest options. Ignore alerts, which makes the spend mostly theater. Assign an employee, which fails the first time an alert fires during their vacation. Or pay for the managed tier, where a security operations team triages around the clock and calls you for the ones that matter. For nearly every business under 50 people, the managed tier is the only one of the three that works as advertised, and it is why I quote managed prices rather than raw EDR prices to clients.
How to decide, step by step
- Check what you have now: open the security settings on three machines and note whether built-in protection is on and updating.
- Pull your cyber insurance application or renewal questionnaire and highlight every security control it asks about. That is your minimum list.
- If you handle sensitive client data, take payments, or have anything a regulator cares about, get quotes for managed detection and response, not bare EDR.
- Ask any provider two questions: who watches alerts overnight, and what exactly happens in the first 30 minutes after a serious one?
- Whatever you buy, deploy it to every machine, including the old laptop in the back office. Attackers look for the one you skipped.
If you want help reading the insurance questionnaire against what you actually run, that gap review is quick work for anyone Security+ certified — it is a service we offer at HashWhales, and a fair thing to ask of whoever handles your IT.
