Many law firms still think of endpoint security as antivirus software that scans files and quarantines known bad ones. That model worked reasonably well when threats were mostly known viruses. Today's attackers use stolen credentials, legitimate administrative tools and fileless techniques that traditional antivirus may not recognize. That gap is why you will hear the terms EDR and MDR in nearly every security conversation.
This post explains what they mean in plain language and how to evaluate them without being pulled into jargon.
Antivirus, EDR and MDR in one minute
- Traditional antivirus compares files to a list of known threats and sometimes flags suspicious behavior. It focuses on preventing known malware from running.
- Endpoint detection and response (EDR) continuously records what is happening on a laptop or server: processes starting, files changing, network connections, logins. It looks for suspicious patterns and can isolate a device.
- Managed detection and response (MDR) adds people. A security operations team watches EDR alerts around the clock, investigates and takes action or calls you.
The difference between EDR and MDR matters for small firms. EDR produces alerts. Somebody has to read them at three in the morning. Most firms have no one who can.
Why law firms are a specific target
Law firms hold sensitive information about clients, deals and disputes, and typically operate with lean IT staff. Attackers know that a small firm may lack monitoring. The point of EDR and MDR is to shorten the time between an intruder arriving and someone noticing, because the longer an attacker has access, the more they can see, steal and encrypt.
What good looks like
Coverage
Every laptop, desktop and server should have the agent installed, including attorney home laptops that access firm data and rarely used machines. An unprotected device is the easiest way in.
Response actions
Ask what happens when something suspicious is found. Can the service isolate a device from the network automatically? Who authorizes it? Will they call someone, and who? A fast, pre-agreed response is more valuable than a long alert list.
24/7 monitoring
Attacks often begin outside business hours, particularly on weekends and holidays. Confirm that monitoring is truly continuous and ask where the security operations staff is located.
Reporting
You should receive regular reports showing coverage, detections, actions taken and outstanding issues. These reports also support insurance applications and client questionnaires.
Questions to ask a provider
- Is the monitoring done by the provider's own staff or subcontracted?
- What is the typical time from detection to action?
- What actions can the team take without calling us?
- How does the service handle laptops that are offline or traveling?
- Does it integrate with Microsoft 365 sign-in monitoring, or only the endpoint?
- What is included in an incident, and what is billed extra?
- How is our data handled, and where are logs stored?
What EDR and MDR do not do
No tool replaces basic hygiene. They do not stop an employee from approving an MFA prompt for an attacker, they do not fix a missing patch, and they do not recover your data after ransomware. They work best alongside:
- Multi-factor authentication.
- Regular patching.
- Email security and training.
- Tested, isolated backups.
- A written incident response plan.
Cyber insurance considerations
Many carriers now ask about EDR or MDR on applications, and some treat it as a condition of coverage or pricing. Confirm that your deployment meets the definition your carrier uses. "We have antivirus" and "we have 24/7 monitored EDR" are different answers.
A sensible rollout
- Inventory all devices that touch firm data.
- Pilot with a handful of users to catch compatibility issues with practice management or document tools.
- Deploy to everyone, servers first.
- Agree on response rules: what is isolated automatically, who is called and in what order.
- Review the first month's reports with partners.
Expect some noise at first
Early alerts may flag legitimate software, such as a billing add-in or a scanning utility. Good providers tune these quickly. Be wary of one that never explains what it is seeing.
Think about people, too
Tell staff that monitoring is for security, not performance management, and be clear about what the tool does and does not see. Trust matters in a law office.
How Counsel Cyber can help
Counsel Cyber includes 24/7 managed detection and response in its cybersecurity services for law firms. If you are evaluating your current endpoint protection, we can review it and explain the gaps in plain terms.