Our pick either way · Verified 18 August 2026
Bitdefender GravityZone — strong at both layers, and it scales down to a small team
Per-device annual licensing — see current offer
Bitdefender consistently places at or near the top of the independent AV-Comparatives and AV-TEST evaluations, which is the only vendor-neutral evidence in this category. GravityZone matters here because the same platform covers plain endpoint protection and full EDR, so you can start at the layer your data classification actually requires and add the other later without re-tooling. That flexibility is worth more to a thirty-machine research group than any single feature.
See GravityZone pricing Opens on the vendor’s site · CASRAI referral link
See the full endpoint security guide → — Covers the research security context, the instrument-PC problem, and what to do before buying anything.
Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.
In summary
- Antivirus matches files against known-malware signatures. EDR records endpoint behaviour and detects attacks by what they do.
- The decisive difference is forensic: EDR can tell you which machines and data an intruder reached. Antivirus cannot.
- “We do not know what was accessed” is what turns a contained incident into a full breach notification.
- A large share of modern intrusions use no malicious file at all — stolen credentials plus legitimate admin tools.
- Do not buy EDR if nobody will read the alerts. Unmonitored EDR is forensics, not prevention.
Side by side
The differences that change what you can answer after an incident
| Dimension | Antivirus / EPP | EDR |
|---|---|---|
| Core question it asks | Is this file known to be malicious? | Does this behaviour look like an attack? |
| Detects novel attacks | Poorly — needs a signature first | Yes, by behaviour rather than recognition |
| Detects attacks using no malware | No | Yes — this is the main reason it exists |
| Keeps a history | Detection logs only | Continuous process, network and file activity |
| Answers “what did they touch?” | No | Yes |
| Can roll back changes | Limited ransomware remediation | Often yes, with the recorded timeline |
| Staff burden | Install and largely forget | Someone must triage alerts for it to prevent anything |
| Right when | No controlled, identifiable or contractually-restricted data | Controlled data, human-subjects data, or a funder/contract cybersecurity expectation |
What antivirus actually does
Traditional antivirus is a recognition system. It holds signatures — distinctive patterns drawn from known malicious files — and compares what appears on the machine against them. Modern products supplement this with heuristics and machine-learning classifiers that flag files resembling known-bad ones, plus behavioural blocking for a handful of obviously-hostile actions such as mass file encryption.
This works genuinely well against commodity threats, which are still the overwhelming majority of what a university endpoint encounters: opportunistic malware, drive-by downloads, infected attachments, the malicious USB stick. It is cheap, needs almost no administration, and stops a great deal.
Its structural limitation is in the model. Recognition requires having seen something before. A file that has never been catalogued, a legitimate tool used for an illegitimate purpose, or an attack that involves no file at all gives it nothing to match against.
What EDR adds
Endpoint detection and response inverts the question. Instead of asking whether a file is known-bad, it continuously records what happens on the machine — which processes launched, what launched them, what network connections opened, which files and registry keys changed, which accounts were used — and looks for sequences that indicate an attack in progress.
The reason that matters is that a modern intrusion frequently involves no malware whatsoever. An attacker with valid stolen credentials logs in. They use PowerShell, remote administration tooling, scheduled tasks and built-in system utilities to look around, escalate privilege and move to other machines. Every one of those tools is legitimate; a system administrator uses them daily. There is no file to catch, and antivirus stays silent throughout.
EDR catches this by pattern rather than by identity: an account authenticating from an unusual location, then enumerating the network, then accessing a file share it has never touched, then opening an outbound connection — none of those is suspicious alone, and the sequence is.
The second capability is the retained history, and for research institutions it is arguably the more important of the two. Because EDR has been recording continuously, you can reconstruct what happened after the fact.
The question that actually settles it
Most comparisons frame this as “how much protection do you need”. For a research institution that is the wrong frame. The better question is: after a suspected compromise, what will you be required to say, and will you be able to say it?
Consider what follows a security incident in a research setting. Your data protection officer needs to know whether personal data was accessed, because under GDPR a notification obligation and a 72-hour clock may attach. Your ethics committee needs to know whether participant data was exposed, because participants may need telling. A commercial partner needs to know whether their confidential material was reached, because your contract almost certainly says so. A funder may need to know whether controlled or export-restricted information was involved. And your own leadership needs to know whether to notify anyone at all.
Every one of those questions is a question about what the intruder reached. With antivirus alone, the honest answer is usually “we cannot determine that” — and organisations that cannot determine it generally have to assume the worst and notify broadly. That assumption is what converts a contained technical incident into a public breach, with the reputational and regulatory consequences attached.
With EDR, you frequently can answer it: this machine, these accounts, these files, this window of time, and no lateral movement beyond it. Sometimes that answer means you have less to notify. Sometimes it means you have more. Either way you are making decisions on evidence rather than on assumption, and that is what the money buys.
Which layer does your group need?
Work from your data classification rather than from a threat feeling.
Endpoint protection is probably sufficient where the group holds no identifiable human-subjects data, no controlled or export-restricted material, no commercially confidential partner data, and has no contractual or funder cybersecurity requirement. A lot of basic science genuinely sits here, and spending an EDR budget on it instead of on multi-factor authentication and tested backups would be a poor trade.
EDR is the appropriate layer where you hold identifiable participant or patient data; where research is export-controlled or involves controlled unclassified information; where a contract or funder condition requires monitoring or incident-response capability; where you hold a commercial partner’s confidential material under an agreement with notification terms; or where a previous incident has already shown you could not answer the questions above.
Managed detection and response is the honest answer when you have a genuine requirement and genuinely nobody to watch the console. This is extremely common in research institutions, and it is better to pay for analysts than to buy a tool that quietly alerts into an unread inbox.
One warning worth repeating: an unmonitored EDR deployment is not prevention. It will give you excellent forensic data after the fact, which is not nothing, but the detection value depends entirely on someone acting on alerts. If you cannot name who that is and when they will look, buy MDR or stay at endpoint protection and spend the difference on the fundamentals.
What to do before either
Neither product is the highest-value control available, and buying one first is a common way to spend a security budget without much reducing risk. In rough order of value:
- Multi-factor authentication on email and remote access. Credential compromise is still the most common initial access route by a wide margin, and this is the single most effective control you can deploy.
- Backups that are offline or immutable, and that you have actually restored from. Ransomware leverage depends entirely on your backups being reachable. An untested backup is a hypothesis.
- Patching, and network isolation for what cannot be patched — which in a research environment means instrument controllers running long-unsupported operating systems. See the endpoint security guide for how to handle those, because no agent solves it.
- An inventory of what sensitive data you hold and where. You cannot protect or classify what you have not listed, and a research security review will ask for this regardless.
- Then the endpoint layer, chosen against that classification.
Price it against your real endpoint count
GravityZone has no public per-device list price — it is quoted at checkout based on how many endpoints you are covering. Count your machines first, including any instrument controllers you may decide to isolate rather than protect.
Per-device annual licensing — see current offer
See GravityZone pricing Opens on the vendor’s site · CASRAI referral link
Frequently asked questions
What is the difference between EDR and antivirus?
Antivirus matches files against signatures of known malware. EDR continuously records endpoint behaviour — process launches, network connections, file and registry changes — and detects attacks by their pattern rather than by recognising a file. EDR also retains that history, which is what lets you reconstruct what an intruder reached.
Do we still need antivirus if we have EDR?
In practice you get both. Modern EDR products include the preventive anti-malware layer rather than replacing it — the endpoint agent blocks known-bad files and records behaviour for detection. You are adding a capability, not swapping one for another.
Why does EDR matter for research institutions specifically?
Because of what you must say after an incident. Your DPO, ethics committee, commercial partners and funders all need to know what an intruder actually reached. With antivirus alone the answer is usually “we cannot determine that”, which forces you to assume the worst and notify broadly — turning a contained incident into a public breach.
Is EDR worth it for a small research group?
It depends on your data, not your size. If you hold identifiable participant data, controlled or export-restricted material, or partner data under contractual notification terms, then yes. If you hold none of those and have no funder cybersecurity condition, endpoint protection plus multi-factor authentication and tested backups is a better use of the same money.
What happens if nobody monitors our EDR alerts?
You get forensic data after an incident and very little prevention during one. That is not worthless, but it is not what you paid for. If you have a real requirement and no capacity to triage alerts, managed detection and response — where the vendor supplies the analysts — is the more honest purchase.
Can antivirus detect attacks that use no malware?
Generally not. An intrusion using stolen credentials plus legitimate tools such as PowerShell, remote administration software and built-in system utilities gives signature matching nothing to match. Detecting that requires looking at the sequence of behaviour, which is what EDR does.







