ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Antivirus, EDR and MDR: What a Law Firm Actually Needs

Antivirus, EDR and MDR are often confused. Learn how each works, what they miss and how to choose protection that fits a law firm's size and risk.

3 min readBy Counsel Cyber Team

Ask a law firm how its computers are protected and many will say, "We have antivirus." That answer was adequate years ago. Today's attackers often use techniques that traditional antivirus does not catch: stolen credentials, legitimate administrative tools, memory-only malware and hands-on-keyboard activity that looks like normal system use.

The market has responded with terms that can be confusing. Antivirus, endpoint detection and response, and managed detection and response describe different levels of protection. Understanding the differences helps you buy what you need and ask better questions.

Traditional antivirus

Classic antivirus compares files against a database of known malicious signatures and may add basic behavior checks. It is useful against commodity threats and is better than nothing.

Strengths: low cost, familiar, blocks well-known malware.

Limits: it struggles with new or customized malware, fileless attacks and an attacker who is already logged in using valid tools. It generally alerts or blocks, but offers limited visibility into what happened.

Many products marketed as "next-generation antivirus" add machine learning and behavior analysis and sit between antivirus and EDR.

Endpoint detection and response (EDR)

EDR software runs on laptops and servers and continuously records activity: processes starting, files changing, network connections, logins. It uses behavioral analytics to flag suspicious patterns and gives investigators the data to see how an intrusion unfolded. Most EDR tools can also isolate a device from the network and kill malicious processes.

Strengths: deep visibility, detects behavior rather than just known files, enables response.

Limits: it produces alerts, and someone has to read and act on them, often at 2 a.m. A small firm without a security analyst may buy EDR and never look at the console.

Managed detection and response (MDR)

MDR pairs EDR technology with a team of security analysts who monitor alerts around the clock, investigate them and take or recommend response actions. Some services also cover email, identity and cloud logs.

Strengths: human expertise without hiring a security staff, 24-hour coverage, faster containment.

Limits: quality varies. Ask what the team will actually do, what you must approve first, how fast they respond and how they communicate.

Why this matters for law firms

Ransomware and account takeover often unfold overnight and on weekends, when no one at the firm is watching. ABA Formal Opinion 483 discusses a lawyer's reasonable efforts to monitor for breaches, and a service that actually watches alerts is one way to address that. Cyber insurers also frequently ask about EDR or similar monitoring on all endpoints, so the answer may affect coverage and premiums. Always confirm your carrier's current requirements.

Questions to ask any provider

  1. What systems does the service cover: laptops, servers, email, identity, cloud applications?
  2. Who watches the alerts, and when? Is it 24 hours a day, every day?
  3. What actions can they take without calling us, such as isolating a laptop?
  4. How quickly do they respond to a critical alert?
  5. How do they communicate during an incident, and with whom?
  6. What reports will we receive?
  7. Are analysts employees or contractors, and where are they located?
  8. What does the contract say about data handling and confidentiality?
  9. Does the price include incident response help, or is that extra?

Common pitfalls

  • Buying EDR with no one assigned to respond.
  • Leaving gaps: servers, personal devices used for work or older machines without the agent installed.
  • Assuming the product alone prevents ransomware.
  • Choosing the cheapest option without asking how alerts are handled.
  • Not testing: confirm the service detects something benign but suspicious, in a controlled test.

A sizing guide, loosely

  • A very small firm with limited budget should at minimum use a reputable next-generation endpoint product, MFA, backups and email protection, and consider a managed service for monitoring.
  • A mid-size firm with sensitive matters or client requirements should strongly consider MDR.
  • Larger firms may add a security information and event management platform and dedicated staff, while still using an external service for off-hours coverage.

These are general guidelines, not rules. Your risk, clients and budget decide.

Endpoint protection is one layer

No tool replaces MFA, patching, backups, staff training and sound procedures. Think of endpoint tools as the part that catches what slipped past the others.

Next step

Counsel Cyber provides managed detection and response for law firms and can help you evaluate whether your current protection fits your risk. If you want a plain comparison of what you have versus what you need, ask us for a review.