IT & Cloud
Endpoint Security
Also called: EDR, Endpoint Detection and Response
Protection on the device itself that detects malicious behaviour, contains it, and preserves the forensic trail — going beyond signature-based antivirus.
Signature antivirus recognises known bad files. EDR watches behaviour — a document spawning a script, mass file encryption, credential dumping — so it catches novel and living-off-the-land attacks that carry no known signature. It can also isolate a machine from the network automatically the moment it looks compromised.
Tooling without response is shelfware. EDR only pays off if alerts reach someone who investigates them, which is why most organisations without a security team buy it as a managed service rather than a licence.
Related terms
- Patch Management
- The controlled process of testing and deploying operating system, firmware, and application updates across a fleet on a defined schedule.
- Zero Trust
- A security model that treats no network as inherently safe, verifying identity, device health, and authorisation for every request rather than trusting anything inside a perimeter.
- MFA
- Authentication requiring two or more independent factors — something you know, have, or are — so a stolen password alone does not grant access.
- RMM
- The agent-based platform an IT provider uses to monitor device health, deploy patches, run scripts, and support endpoints remotely at scale.
More IT & Cloud terms
Support305 in the press
All press coverageNeed this specified correctly?
Our engineers will review your drawings or quote and tell you exactly where Endpoint Security belongs in the design.
Talk to an engineer