“We’re covered, we have antivirus.” We hear that in almost every first conversation with a new client, and it usually comes with genuine confidence. Twenty years ago it would have been mostly justified. Antivirus was built for a world where the threat was a malicious file: a virus attached to an email, a worm on a USB stick. Catch the file, stop the attack.
Here is the uncomfortable update: most modern attacks never involve a malicious file at all. CrowdStrike’s 2026 Global Threat Report found that 82 percent of the intrusions it detected were malware-free. Attackers log in with stolen passwords and then use the same legitimate tools your IT person uses. There is no virus to catch. Your antivirus is not broken. It is faithfully answering a question attackers stopped asking.
What Actually Changed About Attacks
Security people call the new style living off the land. Instead of smuggling in burglar tools, the intruder uses what is already in your house: PowerShell, a legitimate administration tool built into Windows; remote access software of the kind help desks use; scheduled tasks; real user accounts. Verizon’s breach research shows stolen credentials turning up in roughly a third of breaches. To a traditional antivirus scanner, an attacker using a valid login and built-in tools looks like an ordinary Tuesday.
Speed changed too. CrowdStrike clocked the average time from an attacker’s first foothold to moving deeper into the network at 29 minutes, with the fastest observed case at 27 seconds. AI is pushing volume in the same direction: activity by AI-assisted attackers grew 89 percent year over year, a shift we unpacked in how AI-powered cyberattacks are getting smarter. The practical takeaway is simple. Defense now has to watch behavior, not just files, and somebody has to be able to act within minutes, at any hour.
AV, EDR, and MDR in Plain English
The industry loves acronyms, so here is the translation:
- Antivirus (AV) is a bouncer with a photo book. It checks files against a catalog of known troublemakers and blocks the matches. Still useful, still worth having, no longer sufficient on its own.
- EDR (Endpoint Detection and Response) is a set of security cameras on every computer and server. It watches behavior: a login at 3 a.m. from a new location, an accounting PC suddenly running administrator tools, a program touching thousands of files in a minute. When something looks wrong, EDR can raise an alarm and even isolate that machine from the network remotely.
- MDR (Managed Detection and Response) is the team watching the cameras. Around-the-clock analysts who investigate EDR alerts, dismiss the false alarms, and take real action at 3 a.m. while you sleep.
The honest one-line summary: AV blocks known bad files. EDR notices suspicious behavior. MDR makes sure a human does something about it quickly.
Why Cameras Without a Guard Fall Short
Here is the trap some businesses fall into after upgrading: they buy EDR, feel finished, and nobody watches it. EDR produces alerts, and alerts need judgment. Is that remote login the owner working from a deer lease, or an attacker in another country? A 20-person company does not have a night shift to ask. If the average attacker moves deeper within 29 minutes and your alert waits in an unread inbox until Monday, the cameras recorded a crime nobody stopped. Industry-wide, IBM found it still takes organizations an average of 241 days to identify and contain a breach. The tooling is rarely the bottleneck. The watching is.
Now the contrarian part, because overbuying is real too. A 20-person company does not need a six-figure security operations center, a wall of dashboards, or every acronym a vendor can print on a slide. Some providers happily sell all of it. What you need is coverage that matches how attacks actually unfold: solid prevention, fast behavioral detection, and a human response at any hour. That is a short list.
What a 20-Person Company Actually Needs
- Modern endpoint protection, not a legacy scanner. Current products bundle AV and EDR together. The ones to retire are the old signature-only tools quietly renewing on autopay.
- EDR on every computer and server. Including the forgotten machine in the back office. Attackers are drawn to forgotten machines the way water finds cracks.
- Eyes on it 24/7. For a small business, that realistically means MDR delivered through an IT partner, a predictable monthly per-device fee instead of building a security team you cannot staff.
- The unglamorous basics. Multi-factor authentication, prompt patching, and tested backups. EDR catches the intruder who gets in. The basics shrink the number who get in at all.
- A response plan. Detection without an agreed next step is an alarm with nobody assigned to answer it. Decide in advance who isolates a machine, who gets called, and when.
Questions to Ask Whoever Handles Your IT
- “Is what we run EDR, or traditional antivirus?” If the answer is a brand name and a shrug, keep asking.
- “Who sees an alert at 2 a.m., and what do they do?” A good answer names a team and includes the ability to isolate a machine remotely, not just email you about it.
- “What happened the last time an alert fired for a client?” Real providers have real stories, including boring ones about false alarms. Boring stories are a good sign.
- “What does this cost per device per month?” Get it in writing. This market is competitive, and clear pricing is a mark of a provider who expects comparison shopping.
The Bottom Line
Antivirus earned its reputation over two decades, and it still belongs on your machines as one layer. But attackers moved from breaking in to logging in, and from days to minutes, and a photo book of known viruses cannot see a stolen password being used politely. For a modern small business, behavioral detection watched by real people around the clock is the new baseline, the same way cybersecurity itself stopped being optional a while back. Keep the bouncer. Add the cameras. Make sure someone is watching them.
Want a straight answer about whether what you have today is real EDR, managed detection, or just a familiar logo on autopay? Harrison Ward Technology will look and tell you in plain English, including the parts you do not need to buy. Contact us today
Sources:

Comments are closed