Traditional antivirus stops ransomware binaries it recognizes and very little else. That is a serious limitation because a modern ransomware operation is not one bad file arriving and immediately encrypting a computer. The operator often enters through a stolen account or exposed remote access service, uses built-in administration tools, maps the network, reaches privileged accounts, locates backups, and prepares several systems before encryption begins.
Signature antivirus can remain quiet through most of that sequence because many of those actions use legitimate programs. Endpoint detection and response, or EDR, records behavior and relationships between processes, accounts, devices, and network connections. When it is configured and monitored, it gives a responder a chance to contain the intrusion before the final encryption step. For the broader capability comparison, read our guide to EDR vs antivirus.
How ransomware unfolds inside a small medical practice
The exact path changes, but the operating sequence is consistent enough to plan for. Each stage creates different evidence. The distinction between antivirus and EDR is clearest when the attack is viewed as a chain rather than an encryption event.
Stage 1: initial access
The entry point may be a phishing message that captures a Microsoft 365 password, a malicious attachment, an internet-facing remote desktop service, a remote support tool protected by a weak password, or a reused vendor credential. An attacker who signs in with a valid account may not place malware on a device at all.
Signature antivirus sees a known malicious attachment if the file matches its intelligence. It sees nothing when the attacker signs in successfully through a legitimate remote service. EDR can show an unusual process launched by an Office document, a script interpreter starting from an unexpected parent, or a remote tool appearing on a workstation where it has never run. Identity and email controls are still needed because endpoint software cannot inspect every cloud sign-in.
Stage 2: credential theft
The first account is often only a foothold. The operator looks for saved browser passwords, cached administrative credentials, open remote sessions, shared local administrator passwords, and service accounts in scripts or scheduled tasks. A front desk login becomes useful when the same password opens a server or when a privileged technician previously signed into that workstation.
Antivirus may detect a known credential-dumping utility. It may not object when the attacker uses a renamed tool, built-in commands, or direct access to stored secrets. EDR sees the behavioral chain: a user-facing application launches a script, that process touches a protected credential area, and a new network connection follows. The value is not one alert. It is the connected evidence and the ability to stop the device from communicating while the activity is reviewed.
Stage 3: privilege escalation and persistence
With a better credential, the attacker attempts to become a local or domain administrator and establish a way back in. They may create an account, change group membership, install a service, schedule a task, alter a remote-access rule, or abuse a tool the practice already trusts. Each action can look like routine administration when viewed alone.
Signature antivirus looks for a malicious file. EDR looks for an unusual account changing security settings, a new service launched from a temporary folder, a command shell spawned under an uncommon user, or an administration tool used outside its normal pattern. A monitored platform lets an analyst isolate the endpoint, disable a compromised account through the response process, and search other devices for the same indicators.
Stage 4: reconnaissance of the practice
The operator now learns what the practice cannot work without. They enumerate devices, shared folders, mapped drives, administrator groups, virtualization hosts, the EHR or practice-management server, imaging repositories, and backup systems. In a small clinic, the server name and shared folders can reveal the structure quickly. The operator may also test access between locations over a VPN.
Antivirus generally regards directory queries, network discovery, and share access as normal operating-system activity. EDR can identify a workstation rapidly querying many devices, listing privileged groups, or touching file shares that its assigned user does not ordinarily need. Network logging and identity telemetry add context, but EDR supplies the endpoint process tree that shows what initiated the activity.
Stage 5: backup deletion or corruption
Backups are not an afterthought for the attacker. They are a target. The operator looks for backup consoles, repositories, attached storage, snapshots, cloud credentials, and retention settings. They may delete restore points, disable jobs, shorten retention, encrypt a reachable repository, or wait until clean copies age out.
Signature antivirus may see no malware because legitimate backup commands and administrator tools are doing the damage. EDR may expose the sequence of a new process stopping backup services, deleting shadow copies, connecting to the repository, or launching under an account that has not performed those actions before. EDR cannot rescue a backup architecture that lets one stolen administrator account delete every copy. That requires immutability, isolation, separate credentials, and restore tests.
Stage 6: encryption and disruption
Encryption is launched only after the operator believes access, privilege, reach, and recovery interference are ready. The final payload may be a known ransomware binary, a modified build, or legitimate tools used to encrypt or destroy data. Multiple endpoints can be triggered close together to maximize disruption.
Antivirus has its best chance here. If the binary or its behavior matches a rule, it can quarantine the file. If not, it may react only after files have begun changing. EDR looks for rapid file rewrites, mass renaming, deletion of recovery mechanisms, unusual process injection, and similar behavior. A response policy can terminate the process and isolate the endpoint. That does not undo the earlier intrusion, but it can keep one affected workstation from becoming a practice-wide outage.
Encryption is the end of the attack, not the beginning
By the time there is a ransomware file for antivirus to recognize, the attacker may already have valid credentials, knowledge of the network, access to the EHR server, and a plan for the backups. That is the central operational difference. Antivirus asks whether a file is known to be bad. EDR asks whether activity on the endpoint is forming an attack pattern and gives a responder a place to investigate and contain it.
EDR is not the whole defense. Multi-factor authentication, restricted remote access, separate administrator accounts, segmentation, email protection, secure backup, and a rehearsed response plan address parts of the sequence that endpoint tooling cannot. Our explanation of why ransomware targets medical practices puts those layers into the broader healthcare threat model.
Why “we have backups” is not a complete answer
A backup helps only if it contains the needed systems and data, is recent enough, can be restored within the practice's tolerance for downtime, and remains beyond the attacker's reach. A nightly copy on a network share under the same administrator account is not independent. A cloud backup with deletion available through the same compromised console may not be independent either.
A defensible design keeps at least one immutable or otherwise isolated copy, uses separate protected credentials, alerts a real person when jobs or retention settings change, and proves recovery with documented tests. It also covers the systems people forget, including imaging archives, file shares, cloud email, and configuration data. Our guide to a HIPAA compliant backup for a medical practice explains the recovery objectives, testing, and evidence in detail.
Backups do not answer whether patient data was viewed or removed before encryption. Restoring the server brings operations back. It does not erase an unauthorized disclosure or produce the forensic timeline needed for a breach assessment. That is another reason endpoint telemetry and retained logs matter alongside recovery.
The practical difference early containment makes
Consider two response paths. These are operational illustrations, not a Galleon client case or a promise of response time. In the first, suspicious behavior begins on one workstation. A monitored EDR alert is reviewed around hour two, the workstation is isolated, the affected account is disabled, and responders search for the same activity elsewhere. Staff move that user to a clean device while the original machine is investigated and rebuilt.
In the second, no useful signal appears until encryption at day three. Twelve workstations and the server are now suspect. The practice cannot safely reconnect a machine just because its files still open. Responders must determine the entry point, reset credentials, validate backups, rebuild devices, restore the server, test the EHR and interfaces, and confirm that persistence has been removed before normal work resumes.
For scheduled patients, that difference is concrete. One isolated front-desk station may mean moving check-in to another desk and following a short local procedure. A server and twelve-device restoration can mean paper schedules, unavailable histories, manual eligibility checks, delayed prescriptions, canceled procedures, and a backlog that lasts after systems return. Containment protects clinical capacity, not just data.
What to verify with your IT provider
Do not ask only, “Do we have antivirus?” Ask for answers that describe who acts and what happens when a real signal appears.
- Which endpoints and servers report into EDR today, and how is missing coverage found?
- Who reviews alerts after hours, and can that person isolate a device immediately?
- What behaviors trigger automatic containment, and where is human approval required?
- How long is endpoint telemetry retained for a HIPAA incident investigation?
- Can responders search every endpoint for the same account, process, file, or connection?
- Are administrator accounts, remote access, and backup consoles protected separately?
- Which backup copy cannot be deleted with the practice's normal administrator credentials?
- When was the last full restore test, and what evidence documented the result?
- Where is the written ransomware response plan, and who can invoke downtime procedures?
Specific answers indicate an operated security program. A license installed on every computer without monitoring, response authority, and recovery proof is still an unattended alarm. Review the practical first steps in our medical-practice ransomware playbook and compare the controls against current healthcare cyber insurance requirements.
Build for detection before encryption and recovery after it
The right question is not whether antivirus can stop ransomware. It sometimes can stop the final file. The useful question is whether the practice can detect the earlier behavior, contain one endpoint before the attacker reaches the rest, preserve evidence, and restore from a copy the attacker could not change.
Galleon's vendor-neutral approach pairs appropriately configured endpoint protection with active monitoring, identity controls, segmentation, tested recovery, and a documented response process. Learn how those layers fit together in our managed cybersecurity services.
Traditional antivirus can stop a known ransomware file when its signature, hash, or a simple rule matches. It usually cannot expose the credential theft, remote administration, reconnaissance, backup tampering, and other legitimate-looking activity that happens before encryption. Modern ransomware defense requires prevention, behavioral detection, monitored response, network controls, and recoverable backups working together.
EDR can identify and contain behaviors associated with ransomware before widespread encryption, such as suspicious scripting, credential access, rapid file changes, and unusual connections. It can isolate an endpoint and preserve the activity timeline. It is not automatic immunity. Policies must be configured, alerts must be monitored, and someone must have authority to respond quickly.
Backups provide a recovery path only when the attacker cannot delete or corrupt every copy and when the practice has tested a restore. At least one copy should be isolated or immutable, protected by separate credentials, monitored for failures, and retained long enough to reach a clean recovery point. Backups do not prevent data theft or remove breach-response duties.
There is no safe universal number. An operator may move quickly or may stay long enough to steal credentials, map systems, reach backups, and prepare several devices before launching encryption. The practical lesson is that encryption is usually late in the sequence. Detection should focus on the actions that precede it, not on a countdown.
Stop the spread without destroying evidence. Disconnect affected devices from wired and wireless networks, contact the designated incident lead and IT response team, preserve what is on screen, and move staff to the written downtime procedure. Do not sign back into affected systems, start deleting files, or restore backups until the scope and clean recovery point are understood.