Service · Cybersecurity

Antivirus and EDR

In a lot of companies endpoint protection exists on paper but nowhere in one place: three different products depending on how old the machine is, expired subscriptions on the oldest laptops, and two servers where the agent was never installed because they were busy on roll-out day. The result is that nobody can say how many machines are genuinely protected this morning. We bring it all into one console and then take care of the alerts it produces.

One console
workstations, servers and mobiles
Isolation
a machine cut off within minutes
Exclusions
justified, dated and reviewed
Report
what was stopped this month

Where this service reaches

Classic antivirus recognises what it already knows; EDR watches behaviour and keeps a record of what happened before the alert. That record is what answers the only question that matters afterwards: how did this get in?

Put your scope to an engineer

Coverage inventory

We compare the machine list in your directory with the list in the console. The gap between the two is almost always the first unpleasant surprise, and it closes within days.

Agent deployment

Remote installation on workstations, servers and, if you want it, mobiles, through Intune or the vendor console, with the remaining machines tracked down to zero.

Policy tuning

Real-time protection, mail scanning, macro blocking, protection against mass file encryption. Default settings rarely suit a shop till and a database server equally well.

Clearing out exclusions

Every exclusion is justified, dated and narrowed to a precise path. Whole folders excluded five years ago to make some line-of-business tool work are the single most common weakness we meet.

Alert handling

We sort what arrives, drop the noise and act on the rest: isolating the machine, killing the process, tracing the origin and returning it to service.

Periodic report

Coverage, alerts handled, trends and machines that have drifted out of management. A short document, sent at the agreed rhythm.

The way an engagement runs

Moving from one product to another happens department by department, never overnight across the whole estate: two security agents on one machine get in each other's way.

01

Selection

We look at what your subscriptions already cover before proposing another product, because endpoint protection is bundled into several Microsoft 365 plans.

02

Trial

Installation on a representative sample including a production machine and a server, to measure the effect on performance and flush out conflicts.

03

Full roll-out

Deployment in waves, a clean removal of the previous product and coverage verified machine by machine.

04

Running it

Alert monitoring according to the plan you choose, continuous policy tuning and a regular look at the exclusions still in force.

An EDR with nobody reading its alerts protects about as much as an alarm whose sound the neighbour has muted. Detections often land on a Sunday morning, and the value of the tool lies entirely in the gap between the alert and the first action. When choosing, the real question is not the brand on the console: it is who is watching it, and how quickly.

Questions and answers

For many Windows estates, yes, provided it is driven from a central console, tuned well beyond the defaults and watched by somebody. It is often already inside your subscriptions. A third-party product earns its place mainly where you run a lot of non-Windows machines or have unusual requirements.

The effect is generally imperceptible on a modern machine. It shows on older hardware or during a full scan, which we then schedule outside working hours. The machine driving a production tool, or a shop till, gets precise exclusions worked out with the vendor of the software involved.

The machine is isolated from the network while remaining reachable by us, which halts the spread without destroying evidence. We then trace the origin, check whether other machines show the same signs, and tell you what has to be rebuilt rather than cleaned. You receive a written account.

That follows the plan you subscribe to: response times differ between Start, Business and Premium, and the arrangements for out-of-hours cover are set out in the contract. Outside those windows the console keeps blocking and recording, and alerts are picked up when the day starts.

One console for the whole estate

Tell us how many workstations and servers you have, what is already installed and what constraints you live with. We will propose a target and a migration plan.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.