Antivirus blocks files that match a known threat signature. EDR watches behavior across a device and can isolate or roll back an attack in progress, and that gap in capability is exactly what cyber insurers now probe for separately on renewal applications.
Ten years ago, “we have antivirus” closed that line item. Nobody asked twice. Now the same answer gets a form kicked back for clarification, or a renewal that quietly costs more than last year’s did. Same word, different weight. The tool didn’t get worse. The question just got more specific. It’s the same shift VJNetworks walks clients through under cybersecurity planning generally, just showing up on an insurance form instead of a network diagram.
What Antivirus Actually Catches, and Where It Stops
Antivirus works by comparison. A file lands on a machine, gets checked against a library of known-bad signatures, and either passes or gets quarantined. Fast. Reliable, against threats someone has already cataloged. That’s the whole model. Genuinely useful, as far as it goes.
The problem shows up with anything that hasn’t been cataloged yet. A brand new ransomware variant. A “fileless” attack that runs entirely in memory and never drops a file to scan. Credentials stolen and reused by a legitimate-looking login. None of that trips a signature match, because there’s no known-bad file to compare against. Traditional antivirus, by design, is blind to exactly this category of threat, and this category is where most serious incidents originate now.
What EDR Adds That Antivirus Never Could
Endpoint Detection and Response, EDR for short, doesn’t wait for a file match. It watches what’s actually happening on a device, continuously, and flags patterns that look wrong even when nothing on the machine matches a known threat. A process trying to encrypt hundreds of files in sequence. A login attempting to disable security tools. Credential use from a location that doesn’t fit the pattern. Behavior, not signatures.
The detection half only gets you halfway there, though. Halfway isn’t enough. The response half is the part antivirus was never built to do at all. Real EDR can isolate an infected machine from the network in seconds, kill a malicious process mid-run, and roll a device back to its last clean state, all without someone physically walking over to unplug it. CrowdStrike, SentinelOne, and Microsoft Defender for Business all do this. Antivirus alone does none of it. Not one piece. It can quarantine a bad file. That’s the ceiling. It cannot fight back once something is already moving.
| Capability | Antivirus | EDR |
|---|---|---|
| Detection method | Known-bad file signatures | Behavior and pattern monitoring |
| Catches fileless or novel attacks | Rarely | Yes, by design |
| Response capability | Quarantine the file, nothing more | Isolate device, kill process, roll back |
| Investigation trail | Minimal logging | Full timeline of what happened, device by device |

Why Insurers Started Asking the Question Differently
New York’s Department of Financial Services spelled this out directly in its 2021 ransomware guidance. Control 7 on the Department’s list isn’t “antivirus.” It’s Endpoint Detection and Response by name, described as a solution that monitors for anomalous activity. DFS said this in 2021, not last month. That’s a control most regulated companies were expected to have, whenever possible, years before it started showing up as a distinct line on an insurance questionnaire.
Underwriters have their own data backing the same conclusion now. A 2025 Marsh McLennan Cyber Risk Intelligence Center report found that every 25% jump in EDR deployment across an organization’s workstations and laptops correlated with an additional 10% drop in breach likelihood. Trade coverage of that same Marsh dataset puts EDR implementation at 91% in 2025, up from 82% just two years earlier. That cuts the other way for anyone still running antivirus alone. Skipping it doesn’t just miss an upgrade anymore. Now it’s the exception. It stands out.
There’s a sharper reason underwriters care about the response half specifically, not just detection. NetDiligence’s Ransomware Advisory Board, a panel of forensics vendors and law enforcement partners that reviews live claims data, reported that attackers are increasingly disabling security tools early in an incident and persisting after a reset. Speed is the whole game. Detection that can’t act fast enough to stop that gets treated, from a claims standpoint, as barely better than no detection at all.

How to Tell If What You Have Is Real EDR
Plenty of products get marketed with “protection” and “security” in the name without doing what an underwriter means by EDR. A few ways to check before the renewal form asks:
- Ask whether the tool can isolate a single device from the network remotely, not just alert someone that something looks wrong.
- Confirm it’s deployed on every laptop, server, and workstation, not a subset left over from a pilot rollout that never finished.
- Check whether it logs a full timeline of what happened on a device, which is what an investigator needs after something goes sideways.
- Ask your provider directly: is this EDR, or is this antivirus with a newer name on the box? The honest ones will tell you.
- If nobody can show you a dashboard of what it’s actually caught in the last 90 days, that’s a real answer too.

What Happens When “Antivirus” Is the Answer on the Renewal Form
Nothing dramatic, usually. That’s almost the more frustrating version. Outright rejection is rare. It gets a follow-up question instead, and the renewal that used to take a week now takes three. Some underwriters price the uncertainty directly into the premium, since they can’t confirm response capability from a one-word answer. Others send it back asking for the actual product name and deployment percentage before they’ll finish underwriting.
None of that requires anything to have gone wrong first. Nothing has to break. It’s a paperwork problem before it’s ever a security problem, which is exactly the kind of gap that’s cheap to close in advance and expensive to explain during a renewal deadline.
Before You Answer the EDR Question Again
Our antivirus flags things sometimes. Isn’t that basically the same detection EDR does?
If EDR catches more, why did antivirus stick around this long?
Does switching to EDR mean ripping out the antivirus we already have?
How would we even know if what we’re running counts as real EDR?
Is MDR the same thing as EDR, or something else entirely?
Antivirus was never designed to answer the question insurers are asking now, and that’s not really antivirus’s fault. It was built for a threat landscape that mostly stopped looking like this years ago. VJNetworks helps clients across the Tri-State area sort out what they’re actually running before a renewal deadline forces the question, not during it. A free assessment confirms whether what’s installed today would actually pass, alongside VJNetworks’ managed IT services. For the fuller picture, the same detection gap shows up in how fast ransomware actually moves once it lands.
Further reading: NY DFS’s 2021 ransomware guidance lists EDR alongside the Department’s other expected controls in full.
A free assessment checks what’s actually installed against what your renewal application will ask for, no guesswork required. No obligation, no sales pitch.
