Skip to Content

Antivirus vs EDR

What Your Machine Shop Needs
September 29, 2025 by
Jay Stoltzfus
Jay Stoltzfus

The first person to notice is almost never in the office. It's the guy at the machine, pulling up a print for the next job, getting an error instead. He tries the folder again. The file names look wrong, like somebody stuck junk on the end of every one of them.

By the time he walks up front to ask whether anyone moved something, the encryption has been running for half an hour, and the antivirus on that PC has not made a sound. It was doing exactly what it was built to do. That gap, between what antivirus blocks and what actually stops an attack already underway, is the whole antivirus vs EDR question.

It's worth understanding, because manufacturing keeps getting picked. In its 2025 survey of manufacturing and production companies hit by ransomware, Sophos found that exploited vulnerabilities were the single most common root cause, behind 32% of attacks, with malicious email close behind. When those companies were asked why they got hit, the answer that came back most often was not "bad software." It was a lack of anyone with the expertise to catch it in time.

Here's the plain-English version we give shop owners around Parkesburg and across Chester and Lancaster County.

Antivirus vs EDR: What Each One Actually Does

Antivirus is a bouncer with a photo book. Somebody shows up at the door, the bouncer flips through the book, and if the face matches a known troublemaker, they don't get in. That works well, and it's fast, and it catches an enormous amount of everyday garbage: the infected download, the macro in a spreadsheet, the file that has been floating around the internet for two years.

The limit is right there in the description. The bouncer has to have the picture. Every attack that is new, or repackaged, or quietly different from last week's version, walks straight past. So does the attacker who never brings a "file" at all, which is now the normal way this works.

EDR stands for endpoint detection and response. Instead of checking faces at the door, it watches behavior everywhere in the building. It records what programs start, what they touch, what they talk to, and which account told them to do it. When something starts acting like an attack, it doesn't wait for a match in a photo book. It cuts the machine off the network, kills the process, and tells somebody.

Three things EDR does that antivirus does not:

  • It reacts to behavior, not names. A program that starts opening and rewriting hundreds of files in a row is a problem regardless of what it's called.
  • It can isolate one machine. The PC in the front office gets pulled off the network in seconds, which is the difference between one workstation and the file server the whole floor depends on.
  • It keeps the record. After the fact you can answer the questions that matter: how did it get in, what did it touch, did anything leave the building. Try answering that from an antivirus log.

That last one stops being academic the moment a customer asks whether their drawings were exposed.

Antivirus vs EDR on a Real Shop Floor: Three Scenarios

1. A known virus comes in on an attachment

The office manager opens something that shouldn't have gotten through. Antivirus: catches it at the door, quarantines it, done. EDR: also catches it, and then checks whether it did anything at all in the seconds before it was stopped. In this one, honestly, plain antivirus is fine. Most days are this day.

2. Ransomware starts encrypting the engineering share at 9:40 on second shift

Something new gets in and starts working through the folder where the prints and the CAM programs live. Antivirus: if it's a variant already in the book, blocked. If it's a fresh build, and the ones that hit manufacturers are constantly rebuilt, nothing happens. EDR: sees one process rewriting file after file at machine speed, decides no legitimate program behaves this way, stops it and drops that PC off the network. The difference between these two outcomes is usually the difference between a bad hour and a week of re-entered work.

Machinist opening a job print at a shop floor workstation

3. Nobody installs anything at all

This is the one that surprises owners. Someone buys or phishes a password, logs in through the remote access you set up during COVID, and then uses tools that are already on the computer: the built-in Windows utilities, the remote support software your last IT guy left behind, the admin account nobody ever disabled. Antivirus: sees a legitimate user running legitimate programs and says nothing, correctly. EDR: flags that the shipping account just did something the shipping account has never done, at an hour it never does it.

That third scenario is why CISA and the FBI, in their November 2025 advisory on Akira ransomware, tell organizations to patch their VPN and backup systems, require multi-factor authentication on remote access, and deploy endpoint detection and response. Akira has been chewing through small manufacturers specifically. The advisory names the pattern: get in through remote access, look around quietly, then encrypt.

So Which One Does Your Shop Actually Need?

The honest answer is that this stopped being a choice a few years ago. Antivirus is now a component inside EDR, not a competing product. When we set up a shop, one agent does both jobs. The real question is whether anyone is watching what it reports.

You need EDR if any of this describes you:

  • Your prints, CAM programs, quality records, and ERP database all live on one server, and the floor stops when that server does
  • You run a second or third shift, so a 9pm problem is still lost production
  • A big customer has sent you a vendor security questionnaire, or will
  • Your cyber insurance renewal is coming up
  • You have remote access into the shop for yourself, a vendor, or the accountant
  • Somebody once told you "we're too small to be a target," and you'd like that to be true

You might get by with antivirus alone if:

  • You're a one-person operation with a laptop and no shared files
  • Nothing you'd lose would take more than an afternoon to recreate
  • You could rebuild from scratch next week without a customer noticing

Very few shops in Chester or Lancaster County are in that second list. If you're quoting jobs, holding customer drawings, and running machines off a network, you're in the first one.

Worth saying plainly: EDR is not a force field. It shortens attacks and limits how far they get. You still need a backup and recovery plan you could really restore the floor from, and you still need to shut the front door on someone sending email in your shop's name. EDR is the layer that catches what the other layers miss.

The Part That Shows Up on Your Insurance Application

There's a practical reason this matters beyond the technical one. Pull out your last cyber insurance application. Somewhere on it is a question about endpoint detection and response, or "next-generation" endpoint protection, or whether a third party monitors your endpoints around the clock. Traditional antivirus does not answer that question the way carriers want it answered anymore, and checking the box wrong is not something you want to discover during a claim.

The same thing shows up in OEM vendor questionnaires. When a Tier-1 customer sends the security packet, "we have antivirus" is the answer that generates a follow-up call. We put together the documentation for both, so you can hand it to your broker or your customer's supply chain group without a scramble. Our monitoring runs 24/7, which matters when your floor does too. If you want the wider picture, we wrote up what carriers are actually asking manufacturers for at renewal.

Antivirus vs EDR FAQs for Small Manufacturers

Is Microsoft Defender enough for a small machine shop?

For a shop with 5 to 25 computers, the free version built into Windows is a reasonable antivirus and a weak detection tool. It blocks known malware, but nobody is watching the alerts at 9pm on second shift, and it will not isolate an infected PC on its own. Managed EDR adds the watching and the response, which is the part that actually stops an attack in progress.

Do I still need antivirus if I have EDR?

In practice you already have it. Modern EDR products include the antivirus engine, so you are not buying and running two separate things. What you should not do is run two full security products side by side. They fight each other, throw false alarms, and slow down the exact workstation that runs your CAM software.

How much does EDR cost for a 20-person shop?

Expect roughly 5 to 15 dollars per computer per month for EDR that somebody is actually monitoring and responding to, so about 100 to 300 dollars a month for 20 endpoints. Unmonitored, license-only EDR sits at the low end of that. The question worth asking any vendor is who answers the alert at 2am, because the software by itself does not stop anything.

Will EDR slow down our ERP or CAD workstations?

Properly tuned, no. The slowdowns shops complain about almost always come from scanning enormous CAD and CAM directories or the ERP database files over and over. Those paths get exclusions during setup, which takes about twenty minutes and gets skipped constantly. If your machines got slower after a security install, that is a configuration problem, not a reason to strip the protection back out.

What is the difference between EDR and MDR?

EDR is the software on the computer. MDR, managed detection and response, is the people watching what that software reports and acting on it. A shop with no IT staff gets very little out of EDR alerts nobody reads, which is why it usually makes sense as part of a monitored plan rather than a standalone license you install and forget.

Does EDR mean I can stop worrying about backups?

No. EDR shortens an attack and limits the damage, but the entire premise is that something eventually gets through. Backups are what get the floor running again after a bad night, and tested backups are what let you say no to a ransom demand. Insurance carriers ask about both, and they ask whether you've tested the restore.

Not Sure What's Actually Running on Your Shop's PCs?

Most owners we talk to aren't sure whether they have antivirus, EDR, or an expired license from four years ago that stopped updating when the credit card on file changed. That's a normal place to be. It's also a fixable one, and it takes about ten minutes to find out.

Starlux IT has been the IT partner for Pennsylvania manufacturers since 2004, working with shops in Parkesburg, Coatesville, Downingtown, Gap, and across Chester and Lancaster County. Local techs, on site the same day, monitoring that covers your off shifts, and the managed IT plans we build for shops this size at a fixed monthly price per computer. Give us thirty minutes and no pressure: we'll check what you have running, show you the gaps, and you'll know exactly where you stand, whether you hire us or not.

Book your free 30 minutes →

Jay Stoltzfus
Jay Stoltzfus September 29, 2025
Share this post
Archive