{"id":3367,"date":"2026-09-09T15:08:00","date_gmt":"2026-09-09T20:08:00","guid":{"rendered":"https:\/\/minnovatenetworks.com\/blog\/antivirus-is-not-edr\/"},"modified":"2026-09-09T15:43:28","modified_gmt":"2026-09-09T20:43:28","slug":"antivirus-is-not-edr","status":"publish","type":"post","link":"https:\/\/minnovatenetworks.com\/blog\/antivirus-is-not-edr\/","title":{"rendered":"Antivirus is not EDR, and the difference is the whole ballgame"},"content":{"rendered":"<p>Almost every practice we assess has antivirus. Almost none of them have detection. Those sound like the same thing and they are not, and the gap between them is where ransomware lives.<\/p>\n<h2>What antivirus actually does<\/h2>\n<p>Traditional antivirus works from a list. Security vendors collect malicious files, compute a fingerprint for each one, and push that list down to your machines. When a file appears, the software checks the fingerprint against the list. Match, block. No match, allow.<\/p>\n<p>That model works beautifully against a threat that has already been catalogued. It has one structural weakness, and the weakness is not a bug: <strong>a file that nobody has catalogued yet has no fingerprint on the list.<\/strong> The check comes back clean because the check can only ever come back clean.<\/p>\n<p>Attackers understand this better than anyone. Recompiling a payload so it produces a different fingerprint is trivial and largely automated. The version that lands in your practice may well be the only copy of that exact file in existence.<\/p>\n<h2>What EDR does instead<\/h2>\n<p>Endpoint detection and response stops asking what a file <em>is<\/em> and starts watching what it <em>does<\/em>. It runs continuously on every machine, recording process activity, file operations, network connections and credential access, and it looks for behaviour that no legitimate program has any reason to exhibit.<\/p>\n<p>Consider what ransomware has to do to work. It has to enumerate files across drives and shares. It has to open them, encrypt the contents, and write them back at speed. Usually it deletes shadow copies first, so you cannot roll back. Often it stops backup and database services so the files it wants are not locked.<\/p>\n<p>Every one of those steps is legitimate in isolation. Backup software enumerates files. Installers stop services. The combination, in that order, at that rate, is not something any normal application does. That pattern is visible regardless of what the file is called, whether anyone has seen it before, or how recently it was compiled.<\/p>\n<h2>The &#8220;response&#8221; half is the half people forget<\/h2>\n<p>Detection alone is a smoke alarm. It tells you the building is on fire and then keeps telling you.<\/p>\n<p>The response capability is what makes EDR worth paying for. When the platform sees an attack in progress it can cut the machine off from the network immediately, while leaving our remote access intact so we can work on it. That single action is the difference between one ruined workstation and an encrypted server that every operatory depends on.<\/p>\n<p>Several platforms can also roll back the changes an attack made, restoring files it encrypted before it was stopped. This is not a substitute for backup and we would never present it as one, but it turns a very bad afternoon into an inconvenient one.<\/p>\n<h2>Why this matters more in a practice than in an office<\/h2>\n<p>In a normal office, an encrypted file server is expensive. In a dental practice it stops production. The schedule lives in practice management software. The images live on a server. If neither opens at eight in the morning, you are not running a slower day, you are cancelling patients and calling them one by one.<\/p>\n<p>The recovery clock also runs differently. A business that loses a day of email absorbs it. A practice that loses two days of appointments has lost that revenue permanently, because those chairs cannot be run twice next week.<\/p>\n<h2>The part your insurer already knows<\/h2>\n<p>Cyber insurance applications have quietly become security audits. Modern questionnaires ask specifically whether you run endpoint detection and response, not merely antivirus, and they ask it as a yes or no question with your signature underneath.<\/p>\n<p>Answering that question loosely is a genuinely bad idea. If a claim is investigated and the control you attested to was not actually in place, you are in a dispute about coverage at the exact moment you need the coverage. It is worth knowing precisely what is running on your machines before you sign anything that says you know.<\/p>\n<h2>What we would look for in your environment<\/h2>\n<p>If you want to check this yourself before speaking to anybody, three questions get you most of the way:<\/p>\n<ul>\n<li><strong>What is actually installed?<\/strong> Not what you bought, what is running right now on every machine, including the one in the back office nobody uses and the laptop that goes home.<\/li>\n<li><strong>Who looks at the alerts?<\/strong> A detection nobody reads is not a control. If alerts go to an inbox that is checked on Mondays, the answer is nobody.<\/li>\n<li><strong>Can anything isolate a machine automatically?<\/strong> If the answer depends on a human noticing first, assume an attack that starts at 2am runs until morning.<\/li>\n<\/ul>\n<p>The honest summary is that antivirus was designed for a threat model that stopped being the main one a long time ago. It is still worth having. It is just not the thing standing between your practice and a bad week.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Antivirus asks &#8220;have I seen this file before?&#8221; That question has a wrong answer every time an attack is new. Here is what endpoint detection and response does instead, and why it matters to a practice.<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[52],"tags":[60,57,58,59],"class_list":["post-3367","post","type-post","status-publish","format-standard","hentry","category-endpoint-security","tag-antivirus","tag-edr","tag-endpoint-security","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=3367"}],"version-history":[{"count":1,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3367\/revisions"}],"predecessor-version":[{"id":3372,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3367\/revisions\/3372"}],"wp:attachment":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=3367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=3367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=3367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}