Last year, my team watched a ransomware attack unfold in real time. The attacker didn't drop a single malicious file. They used a stolen password, then PowerShell, then a legitimate admin tool. Our antivirus sat there, perfectly content, because nothing it recognized was happening. That's when I stopped thinking of AV as the answer to everything. The numbers back this up: 79% of detections in 2024 were malware-free (CrowdStrike 2025 Global Threat Report). If your whole detection strategy is signature-based, you're not doing threat detection. You're doing archaeology on yesterday's attacks.
Is antivirus worth keeping?
Sure, but not as your main line of defense. Think of AV as the bouncer at a club—it checks IDs and turns away the obvious troublemakers. It's great for stopping known commodity malware. But it's blind to anything new. By 2025, that malware-free detection number had climbed to 82% (CrowdStrike 2026 Global Threat Report). Relying on signatures means missing the majority of what's actually happening. Keep AV for baseline hygiene, but don't expect it to catch someone who knows what they're doing.
What EDR gives you that AV can't
EDR is like having a security camera on every endpoint, but smarter. It watches behavior, not just files. It notices when a process suddenly starts talking to an unknown IP, or when PowerShell runs a script that wasn't scheduled. When something looks off, it can isolate the machine, kill the process, grab forensic data, and even roll back changes. AV quarantines a file; EDR contains an incident. That's a fundamentally different capability.
Here's a real example: A few months ago, a client's server started making outbound connections at 3 AM. No one was logged in. The EDR flagged it, isolated the server, and we found a crypto miner that had been planted weeks earlier. AV had scanned that server every day and found nothing, because the miner was using a legitimate system tool to hide. That's the difference.
EDR vs. zero trust: you need both
Let's be clear: EDR doesn't replace zero trust, and zero trust doesn't replace EDR. EDR is reactive—it helps you see when something's wrong. Zero trust is proactive—it assumes the network is already compromised and limits what an attacker can do even if they get in. They're complementary. You need the visibility from EDR and the restrictions from zero trust. It's not either/or.
Do you really need both AV and EDR?
Most orgs run both, but it's not about stacking tools. It's about reducing noise. AV catches the junk—the script kiddies and commodity malware—so your EDR isn't drowning in alerts. But if you're on a tight budget, EDR is the one you can't skip. AV alone gives you a false sense of security.
How fast are attackers moving?
In 2024, the average breakout time—from initial compromise to lateral movement—was 48 minutes (CrowdStrike 2025 Global Threat Report). By 2025, it was down to 29 minutes (CrowdStrike 2026 Global Threat Report). That's less than the time it takes to grab lunch. If you're not monitoring alerts 24/7, you're already behind. Automation helps: IBM found that organizations using AI and automation extensively saved an average of $1.93 million in breach costs compared to those that didn't (IBM Cost of a Data Breach Report 2026).
Patching: still the most important thing?
Yes, and it's getting worse. The Verizon 2026 DBIR found that more breaches now start with exploitation of software vulnerabilities than with stolen passwords (Verizon 2026 Data Breach Investigations Report). And zero-day exploits before public disclosure jumped 42% (CrowdStrike 2026 Global Threat Report). Patch fast. Use CISA's Known Exploited Vulnerabilities (KEV) catalog to prioritize—it lists vulnerabilities that are actually being exploited in the wild. As of August 2026, that's about 1,670 vulnerabilities (CISA Known Exploited Vulnerabilities Catalog). If one of those is on your network, you're in the crosshairs.
What about mobile endpoints?
Phones and tablets are a growing target. The Verizon 2026 DBIR highlights that higher click rates on mobile make people more likely to fall for fake texts and scam calls (Verizon 2026 Data Breach Investigations Report). And OWASP Mobile Top 10 2024 lists risks like insecure data storage and insufficient cryptography (OWASP Mobile Top 10 2024). So yes, you need EDR on mobile too. Microsoft Defender for Endpoint supports Windows, macOS, Linux, Android, and iOS (Microsoft). But also think about app-side controls—mobile security isn't just about the OS.
Can EDR stop ransomware?
EDR can detect and contain ransomware behavior, but ransomware is evolving. The FBI IC3 2024 report says ransomware complaints rose 9% from 2023 (FBI IC3 2024 Internet Crime Report). The real defense is offline, encrypted backups that you test regularly (CISA StopRansomware). If you get hit, you restore. Don't pay—ransom payouts are shrinking, and businesses are frequently choosing not to pay (Verizon 2026 DBIR). Report incidents to the FBI's IC3 (CISA).
What I'd actually do
If you're starting from scratch, here's a concrete plan:
- Deploy EDR on every internet-connected endpoint—workstations, laptops, servers, even mobile devices (CIS/MS-ISAC). Use a platform like Microsoft Defender for Endpoint or CrowdStrike Falcon.
- Keep AV on for baseline hygiene, but don't expect it to save you.
- Patch aggressively, using the KEV catalog to prioritize.
- Turn on MFA everywhere—use at least AAL2, which requires two different factors (NIST SP 800-63B).
- Don't just install EDR and walk away. Build a 24/7 monitoring process, even if it's a small team. The breakout time is 29 minutes—your detection needs to be faster than that.
One more thing: test your incident response plan. Run a tabletop exercise where someone simulates a breach. You'll be surprised what you miss. Last time we did one, we discovered our backup restoration process took 14 hours—way too slow. We fixed it. You don't want to learn that during a real incident.
Sources
- CISA - https://www.cisa.gov/stopransomware
- CrowdStrike 2026 Global Threat Report - https://www.crowdstrike.com/en-us/global-threat-report/
- IBM Cost of a Data Breach Report 2026 - https://www.ibm.com/reports/data-breach
- Verizon 2026 Data Breach Investigations Report - https://www.verizon.com/business/resources/reports/dbir/
- CISA Known Exploited Vulnerabilities Catalog - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!