Antivirus, EDR, and XDR – what sets them apart
Antivirus recognizes what is already known. It works against mass-distributed malware but misses everything that is new or custom-made.
EDR monitors behavior on the endpoint and can roll back what has already occurred. It covers computers and servers.
XDR takes the same logic and adds more data sources: cloud accounts, email, and identities. Attacks that look innocent in each individual system become visible when the signals are combined.
This development reflects how attacks have changed. Fewer and fewer start with a downloaded file, and more and more start with a login that appears legitimate.
The response component is half the product
The name includes the word response, and that is not just for show.
Isolation. A compromised machine is automatically disconnected from the network while still being remotely manageable. This is the difference between one affected computer and an entire affected environment.
Rollback. Files that have been encrypted or altered can be rolled back to their state before the attack.
The chain of events. Afterwards, you should be able to see how the attacker got in, what was executed, and what was accessed. Without that chain of events, you won't know if you're finished.
The latter is why EDR is often a requirement for cyber insurance. Without event data, an incident cannot be investigated.
An alert that no one reads provides no protection.
This is the most common shortcoming we see, and it has nothing to do with the choice of product.
EDR generates alerts around the clock. An organization without staff to respond when an alert comes in has bought a tool, not protection. For most Nordic businesses, the window of time between automatic isolation and a human beginning to investigate is critical.
This is why EDR is almost always combined in practice with a staffed SOC – either your own or a managed service.
What determines the choice
How much does it require from you? Some platforms assume you have an analyst to fine-tune rules. Others are built to work without one.
What happens when something is detected? Ask specifically what happens automatically and what requires a human decision.
How long is event data stored? Short retention makes investigation impossible. Intrusions are rarely discovered on the same day they occur.
Does it handle your legacy systems? Older Windows versions, Linux, and virtual environments have varying levels of support – and that is often where your most sensitive assets are running.
For MSPs
Multi-tenancy is non-negotiable. You need customer separation, a unified overview, and policies that can be reused instead of rebuilt for every customer.
Deployment is handled via your RMM, and alerts should land in your ticketing system with the correct customer and contract from the start. A security alert monitored in a separate console alongside the ticket queue is an alert that will sooner or later be missed.
EDR is one layer among many. We go through how they connect under IT security.

.png)
.png)
