Skip to main content
Service

Managed EDR — detection that notices behaviour, and a human who acts on it

Traditional antivirus recognises known malware. EDR recognises what an attacker does. Included at no extra cost on our Standard and Enterprise plans.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Managed endpoint detection and response — behavioural threat detection backed by human analysis and containment, included on the Standard and Enterprise plans.

Why antivirus stopped being sufficient

For roughly two decades, endpoint protection worked by recognising files. A researcher found a piece of malware, extracted a signature, and every machine running the product learned to block it. That model works precisely as well as its list is current, and it fails completely against three things that now dominate: malware nobody has catalogued yet, attacks that use no malicious file at all, and attackers who log in with valid credentials and use the tools already installed on your machines.

The last of those is the important one. An attacker who has your password does not need malware. They need PowerShell, which is already there, and the same remote access tools your IT provider uses.

What EDR does instead

EDR watches what happens on the endpoint rather than what arrives on it. Process creation chains, credential access, network connections, file operations, registry changes — recorded continuously and evaluated against patterns of attacker behaviour.

That is why it catches things a signature never will: an ordinary process suddenly enumerating credentials, encryption beginning simultaneously across a mapped drive, a legitimate administration tool being run at 2am from an account that has never used it.

The word that matters is “managed”

Detection technology is broadly commoditised. Every serious EDR product will spot the obvious cases. The variable that actually determines outcomes for a business of 20 to 200 staff is whether anybody looks at the detection.

An unmanaged EDR deployment generates alerts into a console that nobody has opened since the week it was installed. That is not a security control, it is a subscription.

We run Huntress specifically because it includes a security operations team reviewing detections around the clock. For a business of your size, a competent human reviewing a moderate sensor beats an excellent sensor reporting to an empty room, every time.

Containment without a site visit

When a machine is confirmed compromised, the priority is stopping lateral movement. EDR allows an endpoint to be network-isolated remotely — cut off from everything except the management channel — within minutes, wherever it is, including a laptop on a home connection in another state.

That single capability is frequently the difference between one rebuilt machine and an environment-wide incident.

What it costs

Nothing additional. EDR is included in the Standard and Enterprise plans at no per-device charge on top of the plan rate. It is not available on Basic, which covers monitoring and reporting only.

That is worth stating plainly because EDR is commonly sold as a per-endpoint add-on. Bundling it reflects a straightforward view: a managed fleet without endpoint detection is not one we want to be responsible for.

What you get with JTIT

Concrete deliverables, not vague promises.

Catches what antivirus cannot

Signature-based tools recognise known files. EDR recognises behaviour — credential dumping, unusual process chains, encryption starting across a share.

A person behind the alert

Detection without response is a notification. Managed EDR means an analyst reviews the detection and can isolate a machine before you know anything happened.

Isolation in minutes

A compromised endpoint can be cut from the network remotely while remaining reachable for investigation, which stops lateral spread without a site visit.

Forensic history

Process, network and file activity retained, so after an incident you can establish what was actually accessed rather than assuming the worst for the notification.

Included, not upsold

EDR is part of the Standard and Enterprise plans at no additional per-device charge. It is not available on Basic.

Meets the insurance question

Cyber insurers increasingly ask whether you run EDR specifically, not just antivirus. Answering yes accurately is now part of getting covered.

How it works

A predictable, no-surprises process.

  1. 01

    Deploy across the fleet

    Agents rolled out to workstations, laptops and servers, replacing or running alongside existing protection during transition.

  2. 02

    Baseline and tune

    Legitimate line-of-business software frequently looks suspicious. The first weeks establish what normal is for your environment so alerts mean something.

  3. 03

    Monitor and triage

    Detections are reviewed by an analyst rather than auto-emailed to you. Severity determines whether it is contained immediately or investigated first.

  4. 04

    Contain, investigate, report

    Affected endpoints isolated, root cause established from retained telemetry, and a written account of what happened and what changed as a result.

Frequently asked questions

How is EDR different from antivirus?

Antivirus compares files against a list of known-bad signatures. It works well against commodity malware and not at all against anything new or fileless. EDR watches behaviour instead: a process spawning PowerShell that reaches out to an unfamiliar host, credential access patterns, mass file encryption beginning across a network share. It detects the activity rather than the file, which is why it catches attacks that have never been seen before.

Do we still need antivirus if we have EDR?

Modern EDR platforms include next-generation antivirus capability, so in practice EDR replaces the traditional product rather than sitting on top of it. Running two competing endpoint agents usually causes more problems than it solves — conflicts, performance loss and gaps where each assumes the other is handling something.

What does JTIT use for EDR?

Huntress is our managed EDR platform. The reason is the managed part: the detection technology matters less than whether a competent human reviews the alert, and a platform with a monitoring team behind it is materially more useful to a business of your size than a better sensor with nobody watching it.

Will EDR slow our machines down?

Not noticeably on hardware from the last several years. The agent is lightweight relative to the older heavyweight antivirus suites many businesses are still running, and clients replacing one of those often report machines feeling faster.

What happens when a threat is detected out of hours?

Detections are monitored continuously by the platform's own security operations team, which is the specific reason we chose a managed product. Automated containment for defined high-severity conditions can isolate an endpoint at any hour. Our engineers then pick it up under the after-hours terms in your agreement, and you get a written account of what happened.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote