If your practice is relying on the antivirus that came with your computers, you are defending against yesterday's threats. Antivirus was designed for a world where malware was a known file you could recognize on sight. Modern attacks do not look like that anymore. The tool that actually stops them is endpoint detection and response, or EDR, and the difference between the two is worth understanding before you find out the hard way.
What antivirus actually does
Traditional antivirus works by signature. It keeps a list of known-bad files and scans for matches. If the malware is on the list, antivirus catches it. That model works fine against old, widely-known threats, and it is better than nothing. The problem is the assumption underneath it: that the threat has been seen before and added to the list. Increasingly, that assumption is wrong.
What EDR does differently
EDR does not rely on recognizing a file. It watches behavior. It monitors what processes are doing on the machine, and when a process starts acting like an attack, encrypting files rapidly, trying to disable security tools, reaching out to a suspicious server, EDR catches the behavior and can stop it, even if that specific file has never been seen before. That is the crucial difference. Antivirus asks "have I seen this file?" EDR asks "is this behavior an attack?" Modern threats, including most ransomware, are built specifically to slip past the first question. They cannot easily hide from the second.
Why this matters more in healthcare
Healthcare is the most attacked sector for ransomware, and the attacks have shifted toward stealing data rather than just encrypting it. In 2025, according to Sophos, 66 percent of healthcare organizations were hit by ransomware and 96 percent of those attacks involved data exfiltration. These are not off-the-shelf viruses that a signature scanner would recognize. They are behavior-driven intrusions, which is exactly what EDR is built to catch and antivirus is not.
There is also the insurance angle. Cyber insurance carriers have moved EDR from recommended to required. If your practice carries a cyber policy, or wants to, running EDR is increasingly a condition of coverage, not an upsell.
EDR is only as good as who is watching it
Here is the part that gets skipped. EDR generates alerts, and an alert nobody sees at 3 a.m. is the same as no alert at all. EDR delivers its value when it is paired with monitoring: a Security Operations Center with real analysts investigating the alerts around the clock and responding fast. The technology detects. People contain. You need both.
What Galleon runs
We run managed EDR across every device we protect, and we operate it together with a 24/7 Security Operations Center monitored by real human analysts, email security that goes past the Microsoft 365 defaults, and tested backup and disaster recovery. We run antivirus and EDR as layers, not as an either-or, because each catches what the other misses. Base-level cybersecurity is included in our managed IT pricing, with tiered packages for practices that need more robust protection.
If you are not sure whether your endpoints are running real EDR or just antivirus, that uncertainty is worth resolving. Explore our Cybersecurity service, take the free IT Risk Assessment, or schedule a discovery call.