Protection inventory
What is installed on each device, which version and licence, and which machines have nothing at all. Forgotten servers and laptops that have not connected for months usually turn up.
Traditional antivirus compares files against a list of known threats. EDR watches behaviour: a Word document launching PowerShell, a process encrypting hundreds of files a minute, an account suddenly connecting to every server. The difference matters because modern ransomware rarely arrives as a file any list would recognise. But an EDR with nobody watching its alerts is little more than expensive antivirus. In many SMEs we find three different brands spread across the machines, expired licences on the sales team's laptops and a console full of alerts nobody has opened in months. We bring it all under one console, configure blocking and automated response, and make it clear who handles each alert and how quickly.
We work with Microsoft Defender for Business or for Endpoint, SentinelOne, CrowdStrike, ESET, Sophos or Bitdefender, depending on what you already have or what fits best. We do not sell a brand.
What is installed on each device, which version and licence, and which machines have nothing at all. Forgotten servers and laptops that have not connected for months usually turn up.
The old antivirus comes off and the new one goes on without leaving any machine unprotected in between, distributed through Intune or the vendor console.
Blocking, attack surface reduction and folder protection configured properly. Exclusions for business software are justified and documented rather than excluding the entire C drive.
Network isolation of a suspicious device, process termination and, with some products, rollback of encrypted files.
A procedure for each severity level: what is checked, how quickly and who is told. In business hours on any plan, or around the clock with 24/7 IT support or SOC monitoring.
A monthly status: protected devices, out-of-date devices, threats blocked and alerts resolved.
Migration happens in batches of devices, with the new product in passive mode at first to avoid two engines fighting each other.
Protection status across all devices and choice of product, starting with what your licences already include.
Installation on a varied group of machines to tune exclusions and check business software.
Migration in batches, removal of the previous product and blocking switched on.
Alert review under the agreed procedure, a monthly report and policy adjustments.
Ransomware no longer just walks in: it tries to switch the antivirus off first. The groups targeting SMEs use tools built to disable protection before encrypting. The EDR's tamper protection, which stops it being turned off without authorisation from the console, is one of those small settings that make a real difference, and it is often left disabled.
The antivirus built into Windows is decent basic protection. What it lacks is central management, advanced behavioural detection and response from a console; that is Defender for Business, included in Microsoft 365 Business Premium. For an SME holding that licence, setting it up properly is often all that is needed.
Automated responses, such as isolating the device or stopping the process, work at any hour. Human review depends on your plan: in business hours the alert is checked first thing the next morning; with 24/7 IT support or SOC monitoring, a technician picks it up straight away.
Yes, with server-specific licences. Servers need more careful exclusions, especially database and backup servers, and deployment takes place in a maintenance window.
The main products include protection for Android and iOS: detection of malicious links, dangerous apps and fake Wi-Fi networks. On personal phones it is installed only with the employee's consent and without access to their personal content.
Tell us which antivirus you run today, how many devices and servers you have and which Microsoft 365 licences you pay for. We will reply with a migration proposal.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.