Skip to content
Security Engineering & Protection

Endpoint Protection Platforms

End-user devices protected end to end: detection, response and recovery. Most modern attacks start on an employee's laptop rather than a server, so that is where protection should be concentrated.

What we deliver

  1. Signature-based antivirus catches known malware; EDR watches behavior and catches the unknown. When a suspicious process chain is detected the device is isolated from the network and the record is retained for forensics.

  2. Allow-listing, where only approved applications may execute, blocks ransomware at its first step. It is restrictive, so the scope is matched to what the business actually needs.

  3. Malicious links and attachments are filtered before they reach the user. If something gets past the filter, the browser layer is the second line of defense. With a single layer, one failure leaves no protection at all.

  4. Full-disk encryption with BitLocker or FileVault is what separates a lost laptop from a data breach. Recovery keys are managed centrally.

  5. Operating system and third-party application patches are distributed centrally. Most of the vulnerabilities attackers exploit had a patch available months earlier.

  6. Isolation, evidence collection, cleanup and reimaging steps are written before they are needed. Deciding during an incident is always worse than deciding before one.

99.7%Detection Rate
<3 minThreat Containment
50K+Endpoints Managed
Operational architecture

How it works

Every engagement follows the same five steps: baseline the current state, design the target model, roll out in stages, operate it, and improve against measurements.

01

Assess

Baseline the current state, name the gaps and put the success criteria in writing.

02

Design

Architect the target operating model and the toolchain it needs.

03

Deploy

Implement, configure and validate in a staged rollout.

04

Operate

24/7 management with contracted response times and proactive monitoring.

05

Improve

Continuous improvement driven by metrics, incidents and changes in the business.

Contracted service levels

Every engagement runs under a written SLA: a commitment, not a best-effort promise.

Run by engineers

Dedicated engineers who know your stack. No generalist help-desk tier in between.

Continuous improvement

Service reviews every two weeks, roadmap updates every quarter.

The concepts behind this service

Antivirus
Security software that detects, blocks and removes malicious code.
Managed antivirus
Endpoint protection deployment, updates, policy management and incident follow-up delivered as a service.
Ransomware
Malware that encrypts data and demands payment.

This section explains the technical terms used on this page. The definitions come from Eclit's own technology glossary, and each term links through to its full entry there.

The full technology glossary →
01What is the difference between EDR and traditional antivirus?

Antivirus recognizes known malware by signature and misses the unknown. EDR looks at behavior (what a process actually does) and can catch suspicious behavior without a signature. It also lets you look back at what happened after an incident; antivirus keeps no such record.

02Will the agent slow devices down?

There is a measurable cost, but typically a few percent on modern agents. We measure it on a pilot group before rollout; if users report slowness, the data shows which scan clashes with which process, so nobody adds an exclusion blindly.

03What can you do if a device is compromised?

It can be isolated from the network: management connectivity stays up while all other traffic is cut. That stops the spread while allowing investigation to continue without powering the device off; powering it off destroys the evidence in memory.

04Do exclusions need to be defined?

Sometimes, but every exclusion is a hole. Narrow exclusions based on signature or hash are preferred over broad path-based ones, and each one is recorded with its justification.

05Who watches the alerts?

It depends on the model: platform operation only, or 24/7 monitoring connected to a security operations center. An EDR nobody watches only shows you the incident once you have noticed it yourself.

Let's work out where to start

Within two weeks you get it in writing: what works, what carries risk, and a prioritized roadmap.

Request a conversation