Many law firms still rely on traditional antivirus software and consider endpoints protected. Antivirus has its place, but attackers have adapted. Modern intrusions often use legitimate tools, stolen credentials and fileless techniques that signature-based scanners were never built to catch. That is why cyber insurers, clients and security professionals increasingly ask about endpoint detection and response, or EDR.
What traditional antivirus does
Classic antivirus compares files against a database of known malicious signatures and, in newer versions, uses some behavior-based checks. It is good at blocking known commodity malware. It is less effective against novel malware, attacks that abuse built-in system tools, or an intruder who logs in with a valid password and behaves like an administrator.
What EDR adds
EDR software runs on laptops, desktops and servers and continuously records activity: processes launched, files changed, network connections made, accounts used. It looks for suspicious patterns of behavior rather than just known files. When it spots something, it can isolate the device from the network, kill a process, and give investigators a timeline of what happened.
Key capabilities to look for:
- Behavioral detection of suspicious activity
- Device isolation to contain an infection quickly
- Historical telemetry for investigation
- Ransomware rollback or protection features, where offered
- Integration with your identity and email security tools
The staffing question
EDR generates alerts, and alerts need someone to read them. A small firm with no security staff may buy a powerful tool and then ignore the dashboard. That is where managed detection and response, or MDR, comes in. In an MDR arrangement, a team of analysts monitors alerts, investigates, and either responds directly or tells you exactly what to do. Ask whether monitoring is around the clock, since attackers often act at night and on weekends.
Questions to ask any vendor
- Who monitors the alerts, and during what hours?
- What actions can the provider take without calling us first, such as isolating a device?
- How quickly do they notify us of a confirmed incident?
- What coverage exists for servers, Macs and mobile devices?
- Where is telemetry stored, how long is it kept, and who can access it?
- What does the service cost per device, and what is excluded?
- Is incident response included, or billed separately?
Common mistakes
- Buying a tool and never tuning it. Detection depends on proper configuration and exclusions.
- Leaving gaps. Unprotected servers, personal laptops used for work and forgotten devices create blind spots.
- Turning off protection for convenience. Attorneys sometimes ask for exclusions when software slows an application. Each exclusion should be documented and reviewed.
- Treating EDR as the only layer. It works best alongside multi-factor authentication, patching, email filtering and backups.
A hypothetical scenario
Consider a hypothetical firm where a paralegal opens a malicious attachment on a laptop. Antivirus does not recognize the file. An EDR platform notices a document spawning a command shell and reaching out to an unusual server, flags the behavior, and an MDR analyst isolates the laptop within minutes and tells the firm which accounts to reset. Compare that to a scenario where nobody sees anything until files are encrypted.
How it relates to firm obligations
ABA Model Rule 1.6(c) addresses reasonable efforts to prevent unauthorized access to client information, and Comment 8 to Rule 1.1 addresses understanding technology risks. The ABA has not prescribed EDR, but detection capabilities are a commonly expected control, and insurers often ask about them. Confirm any local expectations with your state bar.
Budget perspective
EDR and MDR typically cost more per device than basic antivirus, and are generally priced per endpoint per month. Weigh that against the cost of downtime, recovery and client notification after an incident. Ask for a quote that includes the monitoring service, not only the software license, so you can compare like with like.
Rolling it out
- Inventory all devices that touch client data.
- Deploy EDR to every endpoint and server, verifying coverage.
- Confirm monitoring and escalation contacts.
- Test response with a controlled simulation.
- Review reports quarterly.
Next step
Ask your current provider whether you have EDR or antivirus, who watches the alerts, and what happens at 2 a.m. Counsel Cyber includes managed detection and response in its legal cybersecurity services and can compare your current protection against what a firm of your size needs.