Technology explained for CFOs

Computers, servers and response

Microsoft Defender / EDR

Who notices an intrusion, and who can stop it at 2 a.m.?

Reviewed October 9, 2026 · Published by SecureStepPartner

What it is and what it does

Endpoint detection and response, or EDR, monitors activity on supported computers and servers. It gives a responder evidence and actions such as isolating a compromised device. Microsoft Defender for Endpoint is one example. Built-in antivirus alone does not establish that a managed EDR service is deployed. Microsoft: Defender for Endpoint.

What that means for your business

If a finance laptop starts acting like an attacker is using it, a responder can investigate and isolate it before it reaches other systems. The business decision is who may take that action, how quickly, and how operations will continue.

Is this a baseline system?

Managed endpoint protection is a baseline for business computers and supported servers. Treat monitored EDR as a priority where ransomware could stop operations. Older industrial equipment may not support an agent; document the exception and use appropriate network controls with the equipment owner.

Will insurance ask about it?

EDR can be an explicit underwriting question. The example application asks about coverage across the environment. Have IT explain which devices are protected, which are unsupported, and who responds. Some risks merit round-the-clock monitoring; confirm the insurer’s actual wording before promising it.

See the insurance sources and how to interpret the levels.

Minimum operating position

Correctly licensed and onboarded supported devices, healthy sensors, tamper protection, and a named person responsible for alerts and containment.

When the business needs stronger protection

Monitoring and response outside business hours, tested isolation authority, server coverage, and investigation records. MDR means people operate the detection and response service; it is not just another software license.

Evidence to request from IT

  • Device inventory reconciled against EDR coverage.
  • Last sensor health report and exception list.
  • A tested escalation and containment procedure with response times.

What belongs in the budget

Separate the software license from the monitoring service. Confirm server charges, retention, incident response scope, and whether anyone can act overnight.

A documented incident

InfoTrax, 2014–2016: intrusions went unnoticed

The FTC alleged ineffective intrusion detection and file monitoring at InfoTrax. An attacker accessed data repeatedly before the company detected the problem. FTC: InfoTrax monitoring and network separation failures, 2019.

What this case shows: This is a documented detection gap, not a finding that a particular EDR brand was absent. It illustrates why visibility and active response matter alongside prevention.

Sources and scope

The baseline and stronger-protection positions are editorial planning guidance. Confirm your company’s required controls and insurance answers with the accountable IT owner and broker.