ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Endpoint Detection and Response vs. Antivirus: Q&A for Law Firms

A plain-English Q&A comparing traditional antivirus with EDR and managed detection and response, and what law firms should ask when evaluating each option.

3 min readBy Counsel Cyber Team

Many law firm administrators have heard that "antivirus is dead" and that they need something called EDR. Vendors use similar terms for different products, which makes the conversation confusing. This Q&A explains the differences in plain English and offers questions to ask when evaluating options.

What does traditional antivirus do?

Traditional antivirus software scans files and compares them to a database of known malicious signatures. Modern versions add some behavioral checks and web protection. It is good at stopping commodity malware that has been seen before, and it is better than having nothing.

Its limit is that attackers frequently change their tools, use techniques that do not involve obvious malicious files, or abuse legitimate software already present on the machine. Those methods can slip past signature-based checks.

What is EDR?

Endpoint detection and response records detailed activity on each computer, such as processes started, files changed, network connections and logins. It analyzes that activity for patterns that suggest an attack, such as a document spawning a command shell or a process dumping credentials. It also gives responders tools to investigate and act: isolate a machine from the network, kill a process or roll back changes.

Think of antivirus as a locked door with a list of known burglars, and EDR as a camera system with the ability to lock down a room when someone behaves suspiciously.

What is MDR?

Managed detection and response adds people. A team of analysts monitors EDR alerts, decides which are real, and takes or recommends action, usually around the clock. Most small and mid-size law firms do not have security staff able to watch alerts at 2 a.m. and decide whether to isolate a partner's laptop. MDR provides that capability as a service.

An EDR tool that generates alerts nobody reads provides little protection. The monitoring is as important as the software.

Do we still need antivirus?

Many modern EDR products include antivirus-style prevention, and some firms use the built-in protection in Windows alongside EDR. Ask your provider what prevention your EDR includes so you do not run overlapping tools that conflict. The goal is not a particular label but a layered result: prevent what can be prevented, detect the rest quickly and respond.

Why does this matter for law firms?

Ransomware operators and data thieves often spend time inside a network before they act, sometimes days. Detection during that window can stop an incident before files are encrypted or exfiltrated. Because law firms hold confidential client data, a theft of data can be as damaging as encryption, and backups alone do not address it.

Cyber insurers also ask whether firms use EDR and who monitors it. Many applications treat it as an important control, so having it can influence coverage availability.

The ABA's Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information, and Formal Opinion 483 discusses a lawyer's duty to monitor for breaches. Detection tooling is one practical way to meet the spirit of those expectations, though you should confirm specifics with your state bar.

What should we ask a vendor or provider?

  1. Who monitors the alerts, and when? Around the clock, or business hours only?
  2. What are the response actions? Can analysts isolate a device on their own authority, or must they wait for you to answer a call?
  3. How fast is response? Ask for time targets, not slogans.
  4. What is covered? Laptops, desktops, servers, and maybe phones. Are Macs included?
  5. How does it handle remote and home devices?
  6. What reporting do we get? Look for monthly summaries of detections and actions.
  7. How does it integrate with email and identity monitoring? Many attacks begin in the cloud, not on a laptop.
  8. What happens to our data? Telemetry from your devices goes to the vendor, so review confidentiality and data location terms.
  9. What is the exit plan? Can you remove the agent cleanly and retrieve your records?

Will EDR stop everything?

No. No product does. EDR works best alongside MFA, patching, email security, least privilege and backups. Think of it as the layer that catches what the others miss.

Quick decision guide

  • Solo or very small firm with no security staff: managed EDR or MDR from an IT provider is generally more useful than unmonitored software.
  • Mid-size firm with an IT team: EDR with a managed overnight service may fill the coverage gap.
  • Any firm facing client or insurer requirements: confirm the specific wording they use and map it to your tools.

Next step

Counsel Cyber provides managed detection and response for law firms and can compare your current tools against your coverage needs. If you are unsure what your computers are running today, we can start with a quick inventory and a plain-English summary.