Service · IT security

Antivirus and EDR

In many SMEs antivirus is a patchwork. The older PCs still run whatever the previous IT provider installed, the new laptops use built-in Defender, the server has something with an expired licence, and the Macs in marketing have nothing at all. Warnings end up in a mailbox nobody reads, or pop up on the user’s screen and get clicked away. Traditional antivirus recognises known malware by its signature. Modern attacks, however, often manage without classic malware: they use PowerShell, remote support tools or stolen credentials. Endpoint detection and response, or EDR, therefore watches behaviour on the device and raises the alarm when, say, Word suddenly launches a script that starts encrypting files in bulk. The real value only appears once somebody responds to that alarm. We bring every device under one consistent solution, configure it properly and establish who reviews alerts and what happens next.

One console
for Windows, macOS, servers and mobiles
EDR
with behavioural detection, not signatures alone
Isolation
of an infected device at the push of a button
Clear playbook
for who reacts to which alert

Everything this covers

The right product is often licensed already, for example Defender for Business in Microsoft 365 Business Premium. We also work with other established vendors.

Settle the details with an engineer

Inventory

Which products run on which devices, which devices have no protection, which licences exist and when they expire.

Standardisation

Old products removed and a single solution deployed on all workstations and servers, remotely and without reboots during working hours.

Policies

Tamper protection, attack surface reduction rules such as blocking macros from the internet, controlled folder access against ransomware, and exclusions only with a documented reason.

Servers and business software

Carefully chosen exclusions for databases and line-of-business software such as BMD, RZL or practice management systems, so protection neither slows them down nor breaks features.

Alerting and response

Alerts go to a monitored mailbox or directly into our ticket system. Automatic responses cover clear-cut cases, for instance isolating a device from the network.

Reporting

A monthly overview of protection status, devices with outdated definitions, detected threats and open alerts.

Our working method

Switching to a new solution is quick. What matters more is that someone keeps watching afterwards.

01

Inventory and licences

We record every device and product and check whether your existing licences are sufficient.

02

Pilot

Deployment on a few devices per department, checks for clashes with business applications, fine-tuning of exclusions.

03

Deployment

Removing legacy products and rolling out to all devices in waves, then confirming every device shows up in the console.

04

Response playbook

Deciding who reviews alerts and how they escalate, in line with your service plan. Handover with short documentation.

Most ransomware attacks are spotted by the security software; the trouble is nobody reads the warning. Attackers often spend hours trying to disable protection, and that very effort triggers alerts. Whoever handles those alerts promptly stops the attack before any data is encrypted. That is why every EDR deployment needs a clear response playbook.

Frequently asked questions

Built-in Microsoft Defender Antivirus is decent baseline protection. What it lacks is central management, EDR with behavioural analysis, remote isolation and a view across every device. Those come with Defender for Business, which is part of Business Premium or can be licensed on its own.

Under our service plans we handle alerts Monday to Friday, 8:00-17:00 Austrian time. Premium clients have round-the-clock standby, with the contact route set out in the contract. For clear-cut cases we configure automatic isolation that also works at night.

Yes, if it offers EDR, is centrally managed and covers all your platforms. In that case we tidy it up rather than replace it. We do not run two products side by side, because they interfere with each other.

The device loses all network connectivity except to the management console. The user cannot work, but the attack cannot spread either. We investigate the device remotely and then release it or rebuild it.

One protection for every device, and someone watching it

Let us know your current antivirus and device count. We will check whether your licences already cover what you need and what can be consolidated.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.