In its publication ITSM.70.003, the Canadian Centre for Cyber Security describes EDR as software that "goes hand-in-hand with EPP in that it's software that is used on endpoint devices to detect and prevent malicious activity, however, it can go beyond and remediate endpoints to their pre-infection state." In Protect your organization from malware (ITSAP.00.057), the Centre recommends that you "use anti-virus, anti-malware and endpoint detection and response tools."
Short answer
You describe your devices and how you manage IT: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The tools and level of monitoring are chosen with you.
What the quote should cover
- An inventory of the desktops, laptops and servers to protect
- The proposed protection tool: antivirus, EDR or both, and its management console
- Who monitors alerts, when, and what happens outside business hours
- The response procedure when a device is compromised
- Management of operating system and software updates
- Disk encryption and each device's firewall
- Rules for personal devices that access company data
Antivirus or EDR: what's the difference
According to the Centre, in ITSAP.10.300, security software like anti-virus software "scans systems and files for malware, blocks it from downloading, and detects anomalies or malicious behaviour." "Next-generation antivirus" is a marketing term: ask what the proposed tool actually detects and how. EDR works hand in hand with this protection and, according to the Centre, can also return a device to its pre-infection state. Also ask whether the tool can isolate a workstation from the network remotely.
The Centre's baseline cyber security controls call, at a minimum, for organizations to "enable anti-malware solutions that update and scan automatically" (BC.3.1) and to activate the software firewalls included on devices (BC.3.2). EDR does not replace these basics: it complements them.
Who monitors the alerts
EDR generates alerts. If no one reads them or responds, its usefulness is limited. The quote should therefore state who receives alerts, at what hours, how a serious alert is handled and who is authorized to isolate a device.
In Foundational cyber security actions for small organizations (ITSAP.10.300), the Centre notes that managed service providers can "monitor and patch security devices and systems, as well as take actions on your IT systems to prevent compromises." It also asks whether you know who is responsible for handling incidents. The contract should answer that question clearly.
What to do when a device is infected
According to ITSAP.00.057, the immediate actions are:
- Contact your IT security service desk or IT provider immediately
- Disconnect the infected device from all networks: Wi-Fi, Ethernet and mobile data
- If malware appears to be active or spreading, power off the device
- Refrain from using the infected device to sign into sensitive accounts
The Centre then recommends restoring data only from known, clean backups created before the infection, resetting the passwords associated with the device and re-enrolling multi-factor authentication. If the proposed tool can isolate a workstation remotely, the quote should describe who can do this and how.
Updates and personal devices
A protection tool does not make up for a system that no longer receives updates. The baseline controls call for enabling automatic patching for all software and hardware, or establishing full vulnerability and patch management (BC.2.1). The Centre also advises installing software, OS and firmware updates immediately (ITSAP.00.057).
If employees access your data from their own devices, the baseline controls call for enforcing separation between work and personal data (BC.8.2) and considering an enterprise mobility management solution (BC.8.5). Decide what is allowed: email only, file access, or no access without a managed device.
Questions to ask yourself before requesting a quote
- How many desktops, laptops and servers do you have, and on which operating systems?
- Which antivirus do you use today, and who manages it?
- Who would receive a serious alert on an evening or a weekend?
- Do your workstations receive updates automatically?
- Do employees use their personal devices for work?
- Does your insurer or a client require EDR or specific monitoring?
Pitfalls to avoid
- Installing EDR without planning who reads the alerts
- Leaving workstations or servers unprotected because they were missed in the inventory
- Giving administrator rights to every user: the baseline controls call for restricting those privileges to an as-required basis (BC.12.1)
- Keeping systems that no longer receive updates with no replacement plan
- Never checking that the tool is still running on each device
What to specify in your request
- The number and type of devices to protect, including servers
- The operating systems in use
- Your current protection tool and when its subscription ends
- The level of monitoring you want: business hours or around the clock
- Your policy for personal devices
- Whether update management should be included
- Requirements from a client, an insurer or a contract that must be met
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
Is antivirus still enough?
It remains a baseline: the Canadian Centre for Cyber Security's baseline controls call for anti-malware solutions that update and scan automatically (BC.3.1). The Centre nonetheless recommends, in ITSAP.00.057, also using endpoint detection and response tools.
What is EDR, in simple terms?
It is software installed on each device, alongside the antivirus or protection platform, to detect and prevent malicious activity. According to the Centre, it can also return a device to its pre-infection state.
Do servers need protection too?
Yes. Servers often hold sensitive data and can be targeted in ransomware attacks. The quote should state whether the proposed tool covers servers and under which rules.
Who should respond to alerts?
A qualified person who can be reached, either in-house or at your IT services company. In ITSAP.10.300, the Centre asks whether you know who is responsible for handling incidents. Ask which hours are covered and what happens outside them.
Should the tool be installed on employees' personal devices?
That is a business decision. The baseline controls call for deciding on an ownership model for mobile devices and documenting the associated risks (BC.8.1). Another option is to limit access to company data to managed devices.