---
title: 'Endpoint detection & response (EDR)'
url: 'https://triplepoint.org.uk/security/detect-and-respond/edr'
markdown: 'https://triplepoint.org.uk/security/detect-and-respond/edr.md'
date: '2026-09-28'
description: 'Endpoint detection and response (EDR) for UK businesses. Investigate suspicious activity on a device: what happened, how it got in, and what else it touched.'
---

# Endpoint detection & response (EDR)

The riskWhen something suspicious turns up on a device, the questions that matter come next: how did it get in, what did it touch, and is it still there?

Without the right tools, answering them means guesswork, or wiping the device and hoping that was the end of it.

 What it does- A searchable history of what happened on each device: processes, files and network connections
- AI-written case summaries in plain English, with recommended next steps
- Search across your devices in plain English, without needing to write queries
- Remote command-line access to investigate and fix a device without being there
- Isolate a device from the network while you investigate
- Flags vulnerable and out-of-date devices before they are exploited
- Detections mapped to the MITRE ATT&CK framework

 Who it's forBusinesses with an in-house IT person, or an IT provider, who wants to investigate incidents directly rather than call someone else first.

 How we supply itEDR is part of our [four protection tiers](https://triplepoint.org.uk/security#protection-tiers), so you sign up for it through [our application form](https://triplepoint.org.uk/apply) rather than buying it as a separate licence. If you already have AV-only, moving up is a live change to your account. If you'd rather someone else did the investigating, MDR Essentials adds a 24/7 team.

 What's under the hood**Sophos EDR** — built on the same software as Sophos Endpoint, with its data held in Sophos's cloud data lake. It can also work with Microsoft Defender if that's already on your devices.

 Questions Do we need EDR if we have anti-malware?+Anti-malware stops threats. EDR helps you understand and respond to the ones that get close, and show what did or didn't happen. It's most useful if someone on your side has time to look.

 What's the difference between EDR and MDR?+With EDR, the tools are yours and so is the investigating. With MDR, a 24/7 team of analysts does it for you.

 Is it hard to use?+Less than it used to be. AI case summaries and plain-English search mean you don't need to be a specialist, though some technical confidence helps.

[← Back to Detect and respond](https://triplepoint.org.uk/security/detect-and-respond)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Endpoint%20detection%20%26%20response%20%28EDR%29) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Threat detection and response](https://triplepoint.org.uk/security/detect-and-respond.md)
- Next: [Extended detection & response (XDR)](https://triplepoint.org.uk/security/detect-and-respond/xdr.md)
