Skip to content

Cybersecurity

Endpoint Protection & EDR

We deploy and manage endpoint protection and EDR from a central console, giving visibility across every workstation and server. The difference from plain antivirus is not detection: it is that someone actually sees the alerts and responds to them within an agreed time, and reports on what happened.

Who it is for

  • Companies running different antivirus on every machine
  • Businesses where nobody looks at the security alerts
  • Organisations with laptops operating outside the office network
  • Sites with servers and NAS that must be covered together

When we are NOT the right choice

  • If only licence supply is wanted, with no management
  • If agents cannot be installed on the devices
  • If the requirement is compliance certification, which we do not undertake

PROCESS

The process

Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.

  1. 01Device and protection inventory

    We record what runs on each device today, which licences have expired, and which machines are not protected at all.Time: 2-5 working daysDeliverable: Device register with protection status

  2. 02Policy design

    We define separate policies for office workstations, servers and production machines, because they do not tolerate the same controls.Time: Alongside the studyDeliverable: Policies per device group

  3. 03Deployment and central console

    We deploy the agent everywhere and remove remnants of previous products, which frequently conflict with each other.Time: 1-3 days depending on device countDeliverable: Unified visibility across all devices

  4. 04Alerting and response

    We define who is alerted, for what, and what happens next. An alert with no recipient is not protection.Time: During implementationDeliverable: Alerts with a recipient and a procedure

  5. 05Monitoring and reporting

    We watch the alerts, respond within SLA, and report periodically on what occurred and what needs fixing.Time: Ongoing, under agreementDeliverable: Periodic incident report

What is includedWhat is not included
Device and current protection inventoryPenetration testing and offensive assessments
Agent deployment across workstations and serversSecurity awareness training for staff
Central console with unified visibilityCertification and legal compliance services
Policies per device groupData recovery after an incident where no backup exists
Alerts with a named recipient and procedure
Periodic incident reporting to management

Technology and equipment

  • Bitdefender
  • Microsoft 365
  • Windows / Windows Server
  • Synology
  • MikroTik RouterOS

From practice

In most businesses protection exists, but it differs on every machine: an expired subscription here, a free edition there, two products installed together blocking each other somewhere else.

The real gap is not detection though. It is that alerts land in a console nobody opens. The value of the service sits exactly there: who sees the alert, how quickly, and what they do next.

Prerequisites

  • Ability to install an agent on the devices
  • A device register, or access to build one
  • A nominated alert recipient on your side
  • A decision on production machines with special requirements

Cost

Charged monthly per protected device, with management and response included. The charge is not primarily for the licence: the cost covers someone watching the alerts and responding to them.

We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.

What moves the cost

  • Number of workstations and servers
  • Whether laptops outside the network are included
  • SLA level for incident response
  • Whether special policies are needed for production machines

Frequently asked questions

What is the difference between antivirus and EDR for a 30 person company?

Antivirus blocks known threats on the device. EDR records what happened, so you can see how an incident started and where it spread. At 30 people, the practical difference is being able to answer what actually occurred.

Is built-in Windows antivirus enough?

As detection it covers a lot. What is missing in a business context is central visibility: which devices are up to date, where a threat is active, and who gets alerted when something happens.

What happens when ransomware hits?

The endpoint contains and isolates, but recovery depends on the backup. That is why backup verification and restore testing are part of the same plan, not a separate conversation.

Do you do penetration testing?

No, we do not undertake offensive assessments or compliance certification projects. We work on the technical measures and their day to day operation.

NEXT STEP

See what is actually protected today

We inventory every device and its protection status, and show you where the gaps and expired licences are.

GET IN TOUCH

Tell us what you need

Four fields. An engineer replies, not a sales desk.

Fields marked * are required.

By sending this form you accept the processing of your details under our Privacy Policy.