Service · Cybersecurity

Antivirus and EDR

Traditional antivirus compares files against a list of known threats. EDR watches behaviour: a Word document launching PowerShell, a process encrypting hundreds of files a minute, an account suddenly connecting to every server. The difference matters because modern ransomware rarely arrives as a file any list would recognise. But an EDR with nobody watching its alerts is little more than expensive antivirus. In many SMEs we find three different brands spread across the machines, expired licences on the sales team's laptops and a console full of alerts nobody has opened in months. We bring it all under one console, configure blocking and automated response, and make it clear who handles each alert and how quickly.

1 console
for workstations, servers and phones
Isolation
of an infected device in one click
Anti-ransomware
with rollback where supported
Alerts
reviewed in business hours or 24/7

What falls within the scope of this service

We work with Microsoft Defender for Business or for Endpoint, SentinelOne, CrowdStrike, ESET, Sophos or Bitdefender, depending on what you already have or what fits best. We do not sell a brand.

Pin down the details with one of our engineers

Protection inventory

What is installed on each device, which version and licence, and which machines have nothing at all. Forgotten servers and laptops that have not connected for months usually turn up.

Orderly migration

The old antivirus comes off and the new one goes on without leaving any machine unprotected in between, distributed through Intune or the vendor console.

Policies and exclusions

Blocking, attack surface reduction and folder protection configured properly. Exclusions for business software are justified and documented rather than excluding the entire C drive.

Automated response

Network isolation of a suspicious device, process termination and, with some products, rollback of encrypted files.

Alert handling

A procedure for each severity level: what is checked, how quickly and who is told. In business hours on any plan, or around the clock with 24/7 IT support or SOC monitoring.

Reporting

A monthly status: protected devices, out-of-date devices, threats blocked and alerts resolved.

How the engagement unfolds, one stage at a time

Migration happens in batches of devices, with the new product in passive mode at first to avoid two engines fighting each other.

01

Inventory

Protection status across all devices and choice of product, starting with what your licences already include.

02

Pilot

Installation on a varied group of machines to tune exclusions and check business software.

03

Rollout

Migration in batches, removal of the previous product and blocking switched on.

04

Operation

Alert review under the agreed procedure, a monthly report and policy adjustments.

Ransomware no longer just walks in: it tries to switch the antivirus off first. The groups targeting SMEs use tools built to disable protection before encrypting. The EDR's tamper protection, which stops it being turned off without authorisation from the console, is one of those small settings that make a real difference, and it is often left disabled.

Common questions

The antivirus built into Windows is decent basic protection. What it lacks is central management, advanced behavioural detection and response from a console; that is Defender for Business, included in Microsoft 365 Business Premium. For an SME holding that licence, setting it up properly is often all that is needed.

Automated responses, such as isolating the device or stopping the process, work at any hour. Human review depends on your plan: in business hours the alert is checked first thing the next morning; with 24/7 IT support or SOC monitoring, a technician picks it up straight away.

Yes, with server-specific licences. Servers need more careful exclusions, especially database and backup servers, and deployment takes place in a maintenance window.

The main products include protection for Android and iOS: detection of malicious links, dangerous apps and fake Wi-Fi networks. On personal phones it is installed only with the employee's consent and without access to their personal content.

One console, and alerts someone deals with

Tell us which antivirus you run today, how many devices and servers you have and which Microsoft 365 licences you pay for. We will reply with a migration proposal.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.