This week a researcher published a working exploit that slips past Microsoft Defender on a fully patched Windows PC and hands an attacker complete control — we broke it down in our piece on the Defender “ShieldBreak” flaw. It’s a blunt reminder that “we run antivirus” and “we’d catch an intruder” are very different statements. The gap between them has a name: EDR.
So what is EDR?
EDR stands for Endpoint Detection and Response. Traditional antivirus is a bouncer with mugshots of known troublemakers — it stops the files it recognises. EDR is more like CCTV on every laptop and server: it records what’s actually happening — which programs run, what talks to the internet, what quietly changes — and flags odd behaviour even when no known virus is involved. When something’s wrong, you can respond: isolate the machine, kill the process, roll back the damage.
Why antivirus alone falls short
That behaviour-first approach matters because modern attackers are built to dodge the old one. Australia’s ASD has warned that criminals increasingly “live off the land,” using legitimate built-in Windows tools so there’s no malware file to spot. And it’s common: one in three Australian organisations were hit by ransomware or extortion last year — while 97% stayed confident they could protect their data.
What to do about it
The setup we still walk into most often across the Northern Beaches and Central West is simple: the built-in antivirus is on, and that’s the whole plan — nobody’s watching the alerts. That’s a smoke alarm in an empty house. Real protection is EDR with a human actually watching it — often sold as MDR (Managed Detection and Response). If you can’t name who reads your security alerts, that’s this week’s question. Our cybersecurity team can sort it out in a quick chat.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
