Here's a number that should keep you up at night: 82 percent. That's the share of detections that were malware-free in 2025, according to the CrowdStrike 2026 Global Threat Report. No malicious file. No signature to match. Just an attacker using legitimate tools and stolen credentials to move through your network in an average of 29 minutes—down from 48 minutes the year before. If your incident response plan still treats antivirus as your first line of defense, you're not responding to incidents; you're watching them happen.
I'm not here to bury antivirus—it still has a job. But the threat landscape has shifted, and too many teams are stuck in a mindset that predates the shift. They ask the wrong questions, chase the wrong metrics, and react instead of prepare. So let me answer the questions I actually hear from security teams, and bust some myths along the way.
1. Is antivirus still worth keeping if I have EDR?
Yes, but not for the reason you think. Antivirus (AV) is a prevention tool that catches known malware by matching signatures. EDR (Endpoint Detection and Response) watches behavior in real time and can catch things AV can't—fileless attacks, zero-days, the stuff that doesn't have a signature yet (CISA). Most organizations should run both, letting EDR focus on sophisticated threats while AV handles the commodity noise (CISA). Think of AV as the bouncer checking IDs; EDR is the security camera that notices someone climbing in a window. You want both.
2. Isn't EDR just a fancy antivirus? What's the real difference?
No. Antivirus quarantines or deletes files that match a known bad signature. EDR can isolate an endpoint, terminate a process, capture forensic data, and even roll back changes (CISA). That's the difference between a fire extinguisher and a fire department. AV might put out a small trash fire, but EDR can contain a blaze before it spreads to the whole building. And in a world where attackers are inside for an average of 29 minutes before they act (CrowdStrike 2026), you need that containment capability.
3. But my EDR alerts are noisy. Can't I just tune them out?
That's a dangerous myth—that alerts are noise to be silenced. The reality is that the noise is the signal. If you're drowning in alerts, you haven't tuned your EDR properly. The CIS/MS-ISAC Essential Guide recommends deploying EDR on internet-connected and critical endpoints, including workstations and web servers, and using the telemetry to understand what normal looks like (CIS/MS-ISAC). A well-configured EDR should give you a handful of high-fidelity alerts, not a firehose. If it's noisy, your detection rules are too broad, or you're not using the behavioral analytics properly.
4. What's the deal with zero trust? Do I need it for incident response?
Zero trust and EDR are complementary, not competing. Zero trust is a proactive framework—never trust, always verify (NIST SP 800-207). EDR is reactive—it detects and responds after something happens. You need both. Zero trust limits the blast radius by granting least-privilege access per session (NIST SP 800-207). EDR catches what slips through and helps you clean up. Think of zero trust as the building's security doors and EDR as the alarm system inside. If an attacker does get in, you want to know fast—and you want them contained to a small area.
5. Ransomware is still the big fear. How does EDR help me respond?
Ransomware is a form of malware that encrypts your files and demands payment (CISA). The FBI's IC3 report saw complaints rise 9% from 2023 (FBI IC3 2024). EDR can detect the behavior—mass file encryption, unusual process activity—and isolate the endpoint before it spreads. But don't rely on EDR alone. CISA's StopRansomware guidance is clear: the best bet for recovery is offline, encrypted backups that you test regularly (CISA). And if you do get hit, report it to the FBI via IC3 or a Secret Service field office (CISA). Don't pay—the Verizon 2026 DBIR notes that ransom payouts are shrinking because businesses are choosing not to pay (Verizon).
6. What about mobile devices? Are they endpoints too?
Absolutely. The Verizon 2026 DBIR highlights mobile as a growing target because people click more on mobile (Verizon). And the OWASP Mobile Top 10 2024 lists risks like insecure data storage and insufficient cryptography (OWASP). Your EDR should cover mobile—Microsoft Defender for Endpoint supports Android and iOS, for example (Microsoft). But mobile security also depends on the apps themselves. You can't just slap EDR on a phone and call it done; you need to enforce app security policies too.
7. How fast do I need to patch vulnerabilities?
Faster than you think. The Verizon 2026 DBIR found that exploiting software vulnerabilities is now the top way attackers get in—more than stolen passwords (Verizon). CISA's Known Exploited Vulnerabilities catalog lists about 1,670 vulnerabilities that are known to be exploited in the wild (CISA KEV). That's your priority list. NIST SP 800-40r4 frames patching as preventive maintenance (NIST). Don't try to patch everything; prioritize the KEV list and anything internet-facing. And don't forget that some vulnerabilities have no patch—vendors may take months or stop supporting end-of-life software, so you need non-patch mitigations (NIST).
8. What's the first thing I should do when an incident happens?
Don't panic, and don't start clicking around. Follow your incident response plan. NIST SP 800-61 Rev. 2 outlines four phases: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity (NIST). If you don't have a plan, that's your problem. The best move is to have EDR that can isolate the endpoint remotely (CIS/MS-ISAC) and a tested backup. Then, after the incident, do a post-mortem and feed lessons back into your preparation—that's how you improve.
Quick tip: If you don't have a dedicated incident response team, at least designate a few people who know what to do when the EDR alert fires. Practice with tabletop exercises. The average breakout time is 29 minutes—you don't have time to figure it out on the fly.
Bottom line
The single best move you can make for incident response is to deploy a modern EDR on every internet-connected endpoint, configure it properly, and pair it with offline, tested backups. Antivirus alone is not enough. The data is clear: 82% of attacks are malware-free, and attackers are in and out in under half an hour (CrowdStrike 2026). If you're still relying on signatures to catch them, you're already too late.
Sources
- CISA (endpoint detection and response) - https://www.cisa.gov/stopransomware
- CrowdStrike 2026 Global Threat Report - https://www.crowdstrike.com/en-us/global-threat-report/
- NIST SP 800-207 (Zero Trust Architecture) - https://doi.org/10.6028/NIST.SP.800-207
- NIST SP 800-61 Rev. 2 (Incident Handling Guide) - https://csrc.nist.gov/pubs/sp/800/61/r2/final
- Verizon 2026 Data Breach Investigations Report - https://www.verizon.com/business/resources/reports/dbir/
- CISA Known Exploited Vulnerabilities Catalog - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!