What does antivirus cover, and what does it not cover?
Laptops and desktops are among the main places where employees reach email, files, cloud applications, and business systems. Antivirus helps detect many known threats and suspicious software behaviours on those devices.
Not every security problem arrives as malicious software, though. A business account may be compromised, a browser session stolen, a file shared incorrectly, or an approved application used with more privilege than necessary. Antivirus may produce no alert in some of those situations.
Endpoint security therefore means more than malware detection. It also includes knowing who owns the device, keeping it on a supported version, encrypting business data, and having a defined response when something suspicious happens.
Why does device inventory come before many security decisions?
If the business does not know which devices can reach company data, it cannot confirm whether those devices are patched, encrypted, or protected. A basic device inventory is therefore one of the foundations that comes before buying more security software.
The record can include the owner, model, operating system, support status, encryption state, and protection tool. It does not need to become a perfect database on day one. The immediate value is being able to see which devices are unknown or no longer controlled.
A shared device standard does not mean forcing identical settings onto Windows and macOS. It means defining common outcomes such as supported versions, screen lock, updates, disk encryption, and a sensible approach to local administrator rights.
- Is the device owner and business purpose known?
- Is the operating system still supported by the vendor?
- Is disk encryption enabled with a safe recovery-key path?
- Are security updates arriving regularly?
- Is the approved endpoint protection operating correctly?
- Is there a process for lost and retired devices?
Why is identity security part of endpoint security?
Even a clean and fully patched computer can be used to reach cloud data if the user's business account is compromised. MFA, individual accounts, and review of suspicious sign-ins therefore complete the device layer.
Running permanently as a local administrator can also create unnecessary exposure. Faulty or malicious software can do more with the privileges the user already has. Where administrator access is needed, it is better to elevate for the approved task and for as long as required.
User role matters too. Not everyone needs access to the same applications or file areas. If device privilege and cloud-account privilege are considered separately, tight controls on one side can be undermined by excessive access on the other.
Does installing EDR mean you now have 24/7 monitoring?
No. Modern endpoint tools can flag suspicious processes, unusual connections, or other behaviours. If nobody is responsible for reviewing those alerts and deciding what to do, the product simply becomes another source of notifications.
An incident may require isolating the device, protecting the user's account, preserving relevant records, and checking whether other systems are affected. Those actions are not always performed automatically by the product itself.
When buying EDR or a similar service, the business should understand the monitoring hours, who owns the alerts, and who is authorised to isolate a device. Product capability and the service being purchased are not the same thing.
Which controls should management see together?
Reporting endpoint security only by product name leaves out the important questions. How many devices are unsupported? Is disk encryption actually enabled? Are there critical update gaps or alerts with no owner?
The most expensive licence is not automatically the best outcome. A smaller set of controls that the organisation can consistently operate, review, and respond to is often more valuable.
- Are all devices that reach business data known?
- Are unsupported versions and critical update gaps visible?
- Are disk encryption and recovery keys managed?
- Do users have unnecessary permanent administrator rights?
- Who reviews endpoint-protection alerts?
- Is there a clear process for lost devices and leavers?
- Are backup and recovery connected to the endpoint incident plan?
Endpoint security covers the whole working life of the device.
When the business knows who owns each device, which accounts it can reach, and who responds when an alert appears, choosing the right security controls becomes much easier. Antivirus is an important part of that system, not the whole system.
This article is for general information. It does not replace a technical assessment of your environment, a security guarantee, or legal advice.