Brilliance in the Basics #4: Endpoint Protection

Endpoint protection takes more than antivirus. Learn how device inventories, security updates, and clear response ownership help individuals and small businesses reduce risk.

Imagine an employee’s laptop blocks a suspicious download. That is a useful security win—but it leaves important questions unanswered. Is the operating system current? Did the same file reach another device? Who reviews the alert? Could the business recover if the next attack succeeded?

Endpoint protection is not simply installing antivirus. It is keeping devices secure, detecting suspicious activity, and making sure someone can respond. For individuals and small businesses, the fundamentals matter more than collecting security products: know your devices, maintain their defenses, investigate warnings, and prepare to recover.

What Is Endpoint Protection?

An endpoint is a device that accesses or processes information: a laptop, desktop, smartphone, tablet, or server. Protection needs vary by device, but the objective stays consistent—reduce opportunities for compromise and limit the damage when prevention fails.

Three terms help clarify what you are buying:

  • Antivirus or anti-malware: Detects, blocks, or removes malicious software. This is a foundational prevention layer.
  • Endpoint detection and response, or EDR: Collects device activity, identifies suspicious behavior, and supports investigation and containment.
  • Managed detection and response, or MDR: Adds a service team to investigate and respond to threats. Coverage and response authority depend on the agreement.

Microsoft’s EDR documentation illustrates the distinction between blocking malware and investigating an attack. More visibility helps only when someone acts on it.

The most important endpoint-security buying question is not “How many threats can this detect?” It is “Who will act on a serious alert?”

1. Know Which Devices You Are Protecting

You cannot verify protection on equipment you have forgotten. Start with an inventory that includes office computers, remote laptops, servers, and personal devices authorized to handle business information. CIS Controls treats asset inventory and management as foundational safeguards.

Record enough information to make decisions:

  • Device name, owner, and business purpose.
  • Operating system and whether it still receives security updates.
  • Security software or management service.
  • Last successful update and management check-in.
  • Approved exceptions, their owners, and review dates.

Compare that inventory with your security dashboard. For example, a contractor’s laptop might access company files without appearing in your management console. That gap needs an explicit decision—not an assumption that somebody else is handling it.

Supported software matters independently of antivirus. Windows 10’s ordinary support ended on October 14, 2025. If devices remain on Windows 10, verify their applicable Extended Security Updates enrollment and migration plan. Consumer and commercial programs have different requirements. Microsoft explains why continued Defender protection does not replace operating-system security updates.

2. Verify the Defenses Already on Your Devices

Built-in security can provide a useful foundation. Whether it is sufficient depends on the device, the information it accesses, and your monitoring needs.

Windows

Open Windows Security → Virus & threat protection. If Microsoft Defender Antivirus is your active provider, review its settings, confirm real-time protection is enabled, check protection updates, and examine Protection history. Review cloud-delivered protection and tamper protection as well.

To identify the registered provider, use Windows Security → Settings → Manage providers. On managed devices, follow IT policy rather than trying to override settings. Microsoft documents supported antivirus compatibility arrangements; do not install competing real-time antivirus engines unless the vendors support that configuration.

Mac

macOS includes Gatekeeper, notarization, and XProtect. These help assess downloaded software and detect or remediate malware. Keep macOS and its security updates current, and do not bypass warnings merely to make an unfamiliar installer run. Apple’s malware-protection guidance explains these layers.

A business may still need centralized visibility and response. Built-in protection and organization-wide monitoring solve different problems.

Android, iPhone, and iPad

On Android devices with Google Play, open Play Store → profile icon → Play Protect → Settings and confirm app scanning is enabled. Google recommends keeping Play Protect on.

On iPhone and iPad, app sandboxing prevents third-party security apps from inspecting the device like desktop antivirus. Prioritize supported software, automatic updates, strong device passcodes, and appropriate business management. Evaluate mobile security products by their actual capabilities, not an “antivirus” label.

3. Make Protection a Routine, Not a Purchase

Enable automatic operating-system and application updates wherever practical. Include browsers, document readers, and other frequently used software. Plan required restarts; an update waiting indefinitely for a reboot is not a completed maintenance task.

For businesses, central management helps answer questions that individual installations cannot: Which devices stopped checking in? Which have outdated protection? Where has a policy been disabled? CIS recommends centrally managed anti-malware and automatic updates, along with behavior-based protections where available.

Use standard user accounts for everyday work, reserving administrative privileges for tasks that require them. Keep device firewalls enabled. Document security exclusions and review them rather than letting temporary workarounds become permanent blind spots.

Test stronger restrictions before broad deployment. For example, Windows Controlled Folder Access can help prevent unauthorized changes to protected files, but a legitimate business application may need an allowance. Microsoft’s Windows Security guidance explains the feature. Prefer narrow, reviewed allowances over excluding entire folders from scanning.

4. Choose Tools You Can Operate

For an individual, maintained built-in protection may be a reasonable baseline. A business needs to consider shared policies, sensitive data, contractual requirements, and response coverage—not just whether malware scanning is available.

Before buying EDR or an MDR service, ask:

  • Does it support every operating system and server type we use?
  • How does it identify missing, outdated, or unhealthy devices?
  • Which protections work offline, and which require connectivity?
  • Who investigates serious alerts outside business hours?
  • Can the provider isolate a device, or only recommend action?
  • Which capabilities require additional licenses?

Visibility has privacy implications. EDR can collect process, network, login, and file activity. Establish what is collected, where it is stored, who can access it, and how long it is retained. For personal devices, agree on boundaries before enrollment; a company-issued device may be the cleaner solution.

Automation also has operational consequences. Isolating a compromised laptop can limit damage, but isolating a critical server can interrupt business. Define authorization and escalation rules. If internal staff cannot reliably investigate alerts, NIST’s small-business guidance recommends considering outside monitoring support.

5. Protect Accounts, Data, and Recovery

Endpoint software cannot compensate for every stolen password, unsafe permission, or missing backup. Maintain the supporting safeguards:

  • Multifactor authentication: Protect email, business applications, and administrative accounts; prefer phishing-resistant options where supported.
  • Least privilege: Give people only the access their work requires.
  • Full-disk encryption: Protect data on lost or stolen devices, and securely retain recovery keys. Encryption does not stop malware operating in an unlocked session.
  • Protected backups: Maintain recovery copies that an infected everyday device cannot readily alter or delete.

A synchronized folder is not automatically a resilient backup: unwanted changes may synchronize too. CISA’s ransomware guidance recommends offline, encrypted backups and regular recovery testing. A successful restore is stronger evidence than a successful backup notification.

6. Decide What Happens When an Alert Appears

Not every blocked file signals a major incident. But credible compromise needs a defined response:

  • Report: Contact the designated responder using the established procedure.
  • Contain: Disconnect affected network connections or have an authorized administrator isolate the device.
  • Preserve: Record the alert, device, time, and actions taken. Avoid wiping or casually rebooting before responders assess the situation.
  • Recover: Investigate the scope, address the cause, and restore from verified clean sources before reconnecting.

For ransomware, CISA advises powering down affected devices if they cannot be disconnected from the network, while noting that shutdown loses volatile evidence. Follow the incident plan and responder direction rather than improvising.

Endpoint Protection Checklist

Use this checklist for your next device review:

  • ☐ Every authorized device has an owner and inventory record.
  • ☐ Operating systems and applications are supported and updated.
  • ☐ Appropriate device protections are active and healthy.
  • ☐ Business devices check in to management where applicable.
  • ☐ Exceptions and exclusions have approval and review dates.
  • ☐ Administrative access is limited and device encryption is enabled.
  • ☐ Someone owns serious alerts and after-hours escalation.
  • ☐ Employees know how to report suspicious activity.
  • ☐ Responders understand containment and evidence preservation.
  • ☐ Protected backups have passed a restore test.

The Bottom Line: Verify, Assign, and Test

Brilliance in the basics means making essential protections dependable. Know your devices, verify their defenses, assign responsibility for alerts, and test recovery.

Start with your inventory and security dashboard. Find the gaps between them, give each gap an owner, and set a completion date. The goal is not more installed software. It is fewer unprotected devices—and a response that works when prevention does not.

Browse all insights · Contact Bart McDonough