Cyber Security Basics · Lesson 5 of 10
Quick answer: Understand the role of antivirus, endpoint detection and response, managed monitoring and firewalls in a layered business security strategy.
Antivirus and firewalls are familiar security terms, but modern business protection usually involves several connected layers. Understanding what each control does makes it easier to ask whether your devices are genuinely protected.
What does antivirus do?
Traditional antivirus looks for malicious software using known signatures and behavioural techniques. Modern built-in protections are significantly more capable than early antivirus products, but businesses still need to ensure the protection is enabled, updated and monitored.
What is endpoint protection?
An endpoint is a laptop, desktop, server or other managed device. Endpoint protection combines controls that reduce the chance of malware, ransomware, malicious scripts and other suspicious activity causing harm.
What is EDR?
Endpoint Detection and Response, or EDR, records more security activity and is designed to help detect, investigate and contain suspicious behaviour. It can provide useful evidence about what happened before and during an incident.
What is MDR?
Managed Detection and Response, or MDR, adds people and operational response around detection technology. The important business question is not simply whether alerts exist, but who reviews them, how quickly, and what they are authorised to do.
What does a firewall do?
A firewall controls network connections. Businesses may have a perimeter firewall at the office, host firewalls on Windows devices and additional cloud controls. Firewalls should block unnecessary exposure and allow only the connections required for legitimate business activity.
Do not disable protection to make something work
If a security tool blocks an application, investigate the cause. Permanently switching off antivirus or a firewall to solve an application issue creates a new risk. Where a genuine exception is required, make it controlled and documented.
Technology still needs ownership
A dashboard full of alerts that nobody checks provides limited protection. Security controls need named owners, monitoring, escalation routes and periodic review.
What to do after this lesson
Choose one business device and verify that its operating system security, antivirus or endpoint protection and firewall are active. Then confirm whether somebody is responsible for responding to security alerts.
Frequently asked questions
Is antivirus enough for a small business?
Antivirus is one layer. Businesses should also consider updates, MFA, email protection, backups, access controls, firewalls and incident response.
What is the difference between EDR and MDR?
EDR is endpoint detection and response technology. MDR adds managed investigation and response around security telemetry.
Should Windows Firewall be turned off if we have an office firewall?
Normally no. Host and network firewalls protect different layers and can work together.
Useful UK guidance
Put the lesson into practice
39Security helps small businesses turn cyber security guidance into practical controls and owned actions.
- Take the free cyber security assessment
- View practical cyber security training dates
- Explore Cyber Essentials readiness support
- See managed cyber security services
- Read the small business cyber security FAQ