Cybersecurity · Endpoints
Endpoint Detection and Response (EDR)
Traditional antivirus asks whether a file is known to be bad. Endpoint detection and response asks a more useful question: is this behaviour normal? Legitimate tools misused by an attacker — PowerShell, remote management utilities, credential access — never appear on a list of known-bad files.
We deploy, tune and operate EDR across every device we manage, and treat the detections as work to be investigated rather than notifications to be dismissed.
The problem
Why signature scanning is no longer sufficient
Modern intrusions are largely built from tools already present on the machine. An attacker who has stolen a password does not need malware to read files, create accounts or disable protection — they need permission, and they already have it.
The second problem is coverage. Antivirus is often installed everywhere except the places that matter most: the old application server, the machine in the workshop, the virtual host, the director's personal laptop that reads company mail.
The third is silence. Many organizations have a product that generates detections nobody reads. A tool that flags credential theft on a Sunday evening only has value if something happens next.
What we do
How we operate EDR
- 01
Complete, verified coverage
Deployment to every workstation, laptop and server, with weekly reporting on devices that are unprotected, unhealthy or have not reported in — coverage gaps are treated as incidents in their own right.
- 02
Behavioural detection with teeth
Detection of credential access, suspicious script execution, shadow-copy deletion, persistence attempts and lateral movement, with policies enforced rather than left in audit mode.
- 03
Automatic containment
A device showing high-confidence malicious activity is isolated from the network automatically while retaining our management connection, so investigation continues without letting the activity spread.
- 04
Tuning that reduces noise honestly
Exclusions are documented, narrow and reviewed. Broad exclusions added to silence a line-of-business application are a common way environments quietly lose protection.
- 05
Investigation and response
Each meaningful detection is investigated to a conclusion: what ran, what account was involved, whether anything persisted, and what needs to change afterwards.
- 06
Protection of the tool itself
Tamper protection enabled and alerting on any attempt to disable protection or uninstall the agent, since that is usually an attacker's first move.
Security considerations
EDR is a detection layer, not a strategy
EDR sees the endpoint. It does not see a mailbox rule created in the cloud, a firewall left unpatched, or an account added to an administrative group in the directory. Used alone it produces a false sense of completeness.
We pair it with identity controls, email security, centralized logging and tested backups, and connect its telemetry to the same place as the other signals so an investigation has one timeline rather than four.
- Identity and Conditional Access
- Email and phishing defence
- Central log retention
- Immutable backup
- Patch and vulnerability cycle
- Written response runbook
Where this fits
This service is one layer of the broader programme set out on cybersecurity services in St. Catharines.
Questions
Frequently asked questions
- Is Microsoft Defender good enough?
- Defender for Endpoint is a capable EDR platform and is included in several Microsoft 365 plans, which often makes it the sensible choice. The differentiator is configuration and whether anyone is reading and acting on the detections.
- Will EDR slow older machines down?
- Modern agents are light, but genuinely old hardware and specialised applications need testing. Where a workshop or line-of-business machine is sensitive, we validate performance first rather than deploying blind.
- What happens when a device is isolated at 2am?
- The device is cut off from the network but stays reachable by us. Investigation begins immediately, and the user is contacted with an explanation and a working alternative when the business day starts.
Keep reading
Related cybersecurity services
- Identity & Access ManagementMFA, Conditional Access, privileged accounts and joiner-mover-leaver control.
- Email SecurityStopping invoice fraud, impersonation and credential-harvesting mail.
- Ransomware ProtectionBlocking the intrusion path and keeping a recovery option that survives it.
- Managed Detection & ResponseAnalysts watching the alerts overnight so a detection becomes an action.
- Vulnerability ManagementContinuous discovery, risk ranking and verified remediation.
- Security AssessmentsA measured picture of current controls, gaps and priorities.
Next step
Talk to Griffin IT Group about your St. Catharines IT environment
Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.
