← Back to blog

2026-09-28 · Security Basics

EDR Glossary for Small Businesses: Plain-Language Terms and Questions for Your IT Provider

A plain-language EDR glossary for 5–50 person businesses: what endpoint detection and response is, how it differs from antivirus, and what to ask your IT provider.

This is a glossary, not a buying guide.

If your IT provider has mentioned EDR, MDR, or a SOC and you nodded along, this page explains the words so you can ask better questions.

It's for businesses of about 5–50 people and draws on CISA (the Cybersecurity and Infrastructure Security Agency), NIST (the National Institute of Standards and Technology), and the FTC (Federal Trade Commission). It doesn't recommend any product or vendor, and no tool can promise that nothing will go wrong.

What is EDR, in one sentence? EDR (endpoint detection and response) is software on your computers and servers that records what's happening on each device, flags activity that looks like an attack, and gives someone a way to respond, such as cutting that device off from the network.

What EDR is, in plain language

"We have antivirus" and "we have EDR with someone watching the alerts" are different answers. Know which one you're paying for. EDR has three parts.

  1. Record. A small program on each device logs activity: programs starting, files changing, network connections, and sign-ins.
  2. Detect. The software compares that activity to known attack patterns and normal behavior, and raises an alert when something doesn't fit.
  3. Respond. A person or an automatic rule acts on the alert, for example by stopping a program or isolating the device.

CISA's #StopRansomware Guide recommends using "application allowlisting and/or endpoint detection and response (EDR) solutions on all assets" and says to consider EDR for cloud-based resources too.

The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide asks a question every owner can answer: "How is our business monitoring its logs and alerts to detect potential cyber incidents?" It also suggests engaging a service provider to monitor computers and networks if you don't have the resources to do it yourself.

What EDR catches that traditional antivirus may not

Is EDR a replacement for antivirus? Not exactly. It adds a record and a response on top of blocking known threats. Many products bundle both, so ask what yours includes.

Traditional antivirus mostly works from signatures. NIST's glossary describes a signature as "a set of characteristics of known malware instances that can be used to identify known malware and some new variants of known malware." CISA's Four Cybersecurity Essentials for Businesses and the NIST quick-start guide both still tell businesses to run it. Its limit is in the definition, because it works best on threats someone has already seen.

Attackers don't always bring a new file. The #StopRansomware Guide's threat-hunting list includes misuse of built-in system tools to impair backups, which it calls "a common ransomware technique to inhibit system recovery." It also lists unexpected use of remote monitoring and management software, and notes that attackers often give the Windows processes of one penetration-testing tool the same names as legitimate Windows processes to hide their presence. On another day, those same tools might be doing ordinary work, so it's the behavior that gives an attack away.

CISA's Cybersecurity Performance Goals 2.0 (goal 4.A, Establish Malicious Code Detection) describes both approaches. It calls for signature-based mechanisms and "non-signature-based mechanisms (focusing behavior, heuristics, or anomalies)" to detect and eradicate malicious code at system endpoints.

In short, antivirus asks whether a file is known to be bad. EDR also asks whether the activity looks like an attack, and keeps the record.

The EDR glossary

These are written for owners, not engineers, with government definitions linked where they exist.

Endpoint

Any device that connects to your network or accounts. NIST's glossary entry for endpoint lists "laptops, desktops, mobile phones, tablets, servers, Internet of Things devices, and virtual environments."

Antivirus and EPP

NIST defines antivirus software as "a program that monitors a computer or network to identify all major types of malware and prevent or contain malware incidents." Many antivirus products now add some behavior checks too. EPP (endpoint protection platform) is the industry term for a broader prevention bundle on each device.

EDR (endpoint detection and response)

Tools that record activity on each endpoint, detect suspicious behavior, and support a response. An alert only helps if someone acts on it.

Telemetry

The activity data an EDR agent sends to a central console. NIST's glossary defines telemetry broadly as measuring something, "transmitting the results to a distant station," and recording it.

Behavioral detection

Spotting an attack by what a program does rather than by recognizing the file. CPG 2.0 describes these as non-signature-based mechanisms that focus on "behavior, heuristics, or anomalies."

Indicator of compromise (IoC)

A clue that something went wrong. The glossary in NIST SP 800-61 Rev. 3 calls these "technical artifacts or observables that suggest that an attack is imminent or is currently underway or that a compromise may have already occurred."

Event, alert, and incident

SP 800-61 Rev. 3 defines an event as "any observable occurrence involving computing assets," such as a login attempt. An alert is the tool flagging an event as suspicious. An incident actually or imminently jeopardizes your information or systems. Many alerts turn out not to be incidents.

Alert triage

Deciding which alerts and reports matter first. SP 800-61 Rev. 3 says incident reports should be triaged, starting with a preliminary review "to verify that a cybersecurity incident has occurred, then estimate the severity of the incident and the level of urgency needed to respond to it."

False positive

An alert that turns out to be harmless. NIST's glossary entry for false positive includes "an instance in which a security tool incorrectly classifies benign content as malicious." SP 800-61 Rev. 3 recommends tuning monitoring tools "to reduce false positives and false negatives to acceptable levels." A false negative is the opposite: a real attack that raises no alert.

Isolation and containment

Cutting a device off from the network so a problem can't spread. SP 800-61 Rev. 3 says containment "refers to preventing the expansion of an incident." It suggests setting up tools to do some of this automatically, such as "quarantining malware" or "transferring a compromised endpoint to an isolated remediation network."

SOC (security operations center)

The team that watches alerts and responds. SP 800-61 Rev. 3 notes that incident handlers can be on contract, for example by outsourcing a SOC to an MSSP (managed security services provider).

MSP and MSSP

An MSP (managed service provider) runs your IT day to day. An MSSP focuses on security services such as monitoring. The NIST quick-start guide mentions an MSSP as a possible source of help.

MDR (managed detection and response)

EDR plus people. A provider runs the tools, triages alerts, and takes agreed actions. What "managed" covers varies, so get it in writing.

XDR (extended detection and response)

Detection and response that also pulls in email, cloud account, and network data, so related alerts are seen together.

KEV (Known Exploited Vulnerabilities) catalog

CISA's KEV catalog is "the authoritative source of vulnerabilities that have been exploited in the wild." CISA's Cyber Guidance for Small Businesses says to monitor it and prioritize those vulnerabilities. EDR doesn't replace patching.

What to ask your IT provider or MSP

What should I ask my IT provider about EDR? Ask what's installed and where, who reads the alerts and when, what they're allowed to do without calling you, and how they'll show you it's working.

CISA's Cyber Essentials lists "learn how your data is protected" as an action for leaders, and in-house containment measures as something to set up with IT. The FTC's Cybersecurity for Small Business page says to put vendor security provisions in writing and to verify compliance: "Don't just take their word for it."

  1. Which devices have it? Ask for a dated list of covered endpoints, and which ones aren't covered.
  2. Is it antivirus, EDR, or both? Ask whether behavioral detection is turned on, not just included.
  3. Who reads the alerts, and when? Business hours only, or around the clock? Is it your provider's own staff or another company's SOC?
  4. What can they do without calling you? For example, can they isolate a laptop at 2 a.m.? Write down who approves bigger steps.
  5. How fast do they notify you? Ask who they call first, too.
  6. How do they handle false positives? Ask how they tune the tool and tell you about false alarms.
  7. How long is the telemetry kept? Anyone investigating a problem will need it.
  8. Can they show you a recent example? A redacted alert and what they did tells you more than a slide deck.
  • Covered and uncovered endpoints listed, with a date
  • Alert hours and who watches, named
  • Automatic actions agreed in writing
  • One recent example alert reviewed

Printable EDR questions card

Copy or print this table. Leave blanks as unknown. Don't guess.

#QuestionAnswerProofDate
1Devices with the agent (and without)
2Antivirus, EDR, or both
3Who reads alerts, and what hours
4Actions allowed without calling us
5How and when we're notified
6False positive handling
7Telemetry retention
8Recent example alert shown

Save it as EDR-questions-YYYY-MM-DD next to your IT-host renewal card.

Related guides


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666 — Houston Secure IT / shop line