← Knowledge Base

Antivirus vs EDR: What Home Users and Businesses Actually Need

  • Endpoint Security
  • Antivirus
  • EDR
  • Windows
  • Security

TL;DR

There are two very different answers here depending on who you are, so this guide is split in two: home users first, businesses below.

(If you run or support a business, skip straight to the For business users section below.)


Now for the more technical explanation

For home users

Do you need to pay for antivirus?

Let me say the quiet part loudly: on a modern Windows PC, Microsoft Defender is all the antivirus most people need, and it is free and already there.

It is worth appreciating how far this has come. Defender started life as Microsoft Security Essentials, which, back in the day, was frankly a bit of a joke: it sat near the bottom of every detection test. Today, Microsoft Defender consistently scores at or near the top of the independent AV comparatives, alongside the big paid names. The default, free, built-in option went from punchline to genuinely excellent. Most people never got the memo.

The shop upsell you should walk away from

Here is where I get grumpy. When I worked as a bench tech at a big electronics chain, I watched salespeople talk people into a ten-device antivirus licence for over $600 when the customer owned a single phone. The product cost the store around fifty-odd dollars; the rest was margin and a personal commission for the person selling it. It was fear dressed up as protection, and it still makes my blood boil.

So, plainly: the heavyweight consumer “security suites” (Norton being the classic example) are, for most home users, unnecessary, overpriced, and heavy. A few things worth knowing:

The setup I’d recommend: Defender with every feature enabled, and if you need a VPN, a separate, purpose-built VPN, never a bundled one.

The best security habit: install less

Here is the principle underneath all of this, and almost nobody frames it as security: install as little software as possible. It applies to every operating system, Windows, Mac, and Linux alike. Every program you install is more attack surface: more code that can carry a vulnerability, more background processes running, and one more thing you have to keep patched. The goal on any computer should be the minimum set of software you genuinely need, and nothing else.

Third-party antivirus is the perfect example. It is an extra, deeply privileged install that, for most people, adds risk and overhead without adding protection Defender does not already provide. The same logic applies to VPNs: most people do not need one running at all, so it is not something to install by default. (When you genuinely do need one, that is its own decision, see the VPN guide.)

Fewer installs means a smaller attack surface, less to patch, and a faster machine. Before you install anything, the honest question is simply: “do I actually need this?” That question is a security control.

Where you get your software matters

Most infections walk in through the front door, in the installer you downloaded. So:

Step one: stop running as administrator

Before any settings, the highest-value change is boring: use a standard (non-admin) account for daily use. Most malware can only do its worst if it runs with admin rights. A standard account means a dodgy program has to ask (and you get to say no), which stops a huge amount of damage before it starts.

Turn these built-in protections on

Modern Windows ships with a stack of genuinely good protections, and some are not on by default. Open Windows Security and switch these on. Most of them live under Device security, a click or two deep, and are shown below.

Smart App Control shows its three states (On, Evaluation, Off) on its own page:

Smart App Control settings page showing On, Evaluation, and Off options Smart App Control runs an Evaluation phase first, then usually turns itself on. Once it is off, re-enabling it needs a Windows reset.

The Device security page is the hub for most of the rest. It shows Core isolation, your security processor (the TPM, or trusted platform module), Secure Boot, and drive encryption in one place:

Windows Security Device security page showing Core isolation, Security processor (TPM), Secure Boot, and Data encryption Windows Security, then Device security: the hub for most of these settings.

Open Core isolation details for the individual toggles. A couple are off by default; turn them on if your hardware supports them:

Memory integrity toggle under Core isolation, shown switched off Memory integrity: often off by default, turn it on.

Kernel-mode Hardware-enforced Stack Protection toggle Kernel-mode hardware-enforced stack protection.

Local Security Authority protection toggle, shown switched on Local Security Authority (LSA) protection: guards your sign-in credentials.

Microsoft Vulnerable Driver Blocklist toggle, shown switched on Microsoft vulnerable driver blocklist: leave this on.

Encrypt your drive (and guard the recovery key with your life)

If your laptop is lost or stolen and the drive is not encrypted, whoever finds it can read everything. Turn on drive encryption. A couple of Windows-specific wrinkles:

Ransomware protection: handy, occasionally nagging

Windows has a Ransomware protection feature (Controlled Folder Access, under Virus & threat protection). It stops untrusted programs from modifying files in your protected folders, which is exactly what ransomware tries to do.

Ransomware protection page showing Controlled folder access switched off Ransomware protection, under Virus & threat protection. Controlled folder access is off by default.

It genuinely works, but be warned: it can be annoying. Legitimate apps sometimes get blocked because Windows cannot tell “you saving a document” from “malware encrypting it”, so Word saving to a protected folder, or a browser trying to save a download, can get stopped. When that happens, you go into the setting and allow that specific app through. Slightly fiddly, but worth it for the protection.

One caveat: Controlled Folder Access helps, but the genuine last line of defence against ransomware is a good backup, one that is independent enough that malware cannot reach and encrypt it too.

Home users, the short version

You do not need to buy antivirus. Run as a standard user, keep Defender on with all its extra protections enabled, encrypt your drive and protect the recovery key, get software from the Store or genuine vendor sites, and skip the overpriced suites, if you want a VPN, buy a real one separately.


For business users

(Everything below steps up from “protect one PC” to “protect a fleet you are accountable for.” This section is the starting draft, the strong opinions here are the bones; the flesh gets refined.)

Antivirus is table stakes. EDR is the baseline.

For a business, “we have antivirus” is not a security posture, it is 2005. Traditional AV mostly matches known signatures, and modern attacks are built specifically to slip past that. The baseline for any business now is EDR (Endpoint Detection and Response), and the important word is the last one.

EDR is not just “better antivirus.” It continuously records what is actually happening on every endpoint (processes, network connections, file and registry changes), spots behaviour that looks like an attack rather than a matching signature, and lets you respond: isolate a machine from the network, kill a process, and investigate with real forensic timeline data. That telemetry and response capability is the entire point.

The bit everyone skips: the “R” needs a human

Here is the hill worth dying on. EDR with nobody watching it is theatre. The tool generates detections; if no one is triaging and responding to them, around the clock, you have bought an expensive dashboard that logs your own breach for later reading.

This is why MDR (Managed Detection and Response), EDR plus an actual staffed team (yours or an outsourced SOC) watching and acting 24/7, is what most businesses genuinely need. Deciding factor for a small business is rarely “which EDR product”; it is “who is going to respond at 2am?” Answer that first.

Is Defender enough for business too?

Often, yes, with a caveat. Microsoft Defender Antivirus (the engine) is already excellent, so ripping it out for a third-party AV rarely buys you anything. What a business is really buying is the EDR and management layer on top:

The honest framing: the AV underneath is a solved problem. Spend your decision energy on EDR + response + management, not on the antivirus brand.

Cross-platform: Windows, Mac, and Linux all need it

This is where businesses have blind spots. Endpoint protection is not a Windows-only conversation.

Business, the short version

AV is assumed; EDR is the baseline, and EDR without someone responding is pointless, so sort out MDR/response before you shop for products. Defender’s AV is already strong, so you are really buying the EDR + management layer (MDE is often already in your licensing). And cover every OS: Windows, Mac, and the Linux servers everyone forgets.

Written by Tom Langston, IT Infrastructure and Cybersecurity.