Mayer Networks

Cybersecurity

Endpoint Security

Endpoint security protects the computers and servers where most compromises begin. Mayer Networks deploys and manages endpoint protection and EDR so malicious behavior is blocked, recorded and investigated.

Security lifecycle

  1. Identify
  2. Protect (this page)
  3. Detect (this page)
  4. Respond
  5. Recover

Endpoint security is a Protect and Detect control. It reduces what can execute on a workstation or server and records the behaviour investigators need afterwards. See the full Mayer Networks cybersecurity approach.

What it is

Endpoints Are Where Most Compromises Actually Begin.

Workstations, laptops and servers run the browsers, email clients, user sessions, local credentials, scripts and remote-access tools an attacker needs. That makes the endpoint the place where a phishing click, a stolen password or a malicious document turns into something running inside your network.

Endpoint detection and response, or EDR, continuously observes what happens on those machines. Instead of only matching known bad files, it watches behaviour: a process encrypting files rapidly, a script pulling code from an unfamiliar host, an administrative tool being used in a way nobody would use it during normal work. When that behaviour looks like compromise, it can be blocked, the machine can be isolated from the network, and the activity is recorded for investigation.

No endpoint product prevents everything. What EDR changes is how early malicious behaviour is noticed and how much is known about it afterwards.

The problem it solves

What Endpoint Security Is There to Stop

These are the situations EDR is deployed against, and they are ordinary rather than exotic.

  • Ransomware beginning to encrypt files on a server overnight
  • A malicious document launching scripts from a user's mail client
  • Credential-stealing tools run against a workstation after a phishing click
  • Legitimate administrative tools used by an attacker with a valid password
  • A laptop compromised outside the office and carried back onto the network
  • A quiet foothold left behind so access can be resold or used later

How Mayer Networks uses it

How Mayer Networks Operates Endpoint Security

The agent is the easy part. The value is in coverage, tuning and the response path behind a detection.

  • Coverage

    Agents are deployed across workstations, laptops and servers, and coverage is verified against the managed device inventory rather than assumed. An unprotected server is a common finding on environments we take over.

  • Policy

    Protection policies are tuned around the line-of-business applications the organization actually runs, so detection does not break legitimate work and staff do not ask for exclusions that quietly disable the control.

  • Alert review

    Detections are reviewed rather than accumulating in a console nobody opens, and they are escalated into the managed detection workflow when the behaviour warrants an investigation.

  • Isolation

    Where a machine is confirmed compromised, it can be isolated from the network while remaining reachable for investigation, with the containment authority agreed with the client in advance.

  • Remediation

    Rollback and cleanup are handled with the same engineers who manage the endpoint, the directory and the backups, so recovery is not handed between vendors.

  • Context

    Because we also run the network, Microsoft tenant and backups, an endpoint alert is read alongside what else was happening in the environment at the time.

Platform

The Platform: SentinelOne

Mayer Networks deploys and manages SentinelOne as the core endpoint-security layer, with SentinelOne Vigilance available as a specialized 24/7 analyst capability around it.

SentinelOne

SentinelOne

Endpoint detection and response

Behavioural detection on workstations and servers, with device isolation, detection telemetry for investigation and remediation assistance. Managed, tuned and monitored by Mayer Networks.

  • Behavioural and malicious-process detection
  • Ransomware behaviour detection
  • Suspicious script activity
  • Endpoint isolation
  • Investigation telemetry
  • Remediation assistance

SentinelOne is a registered trademark of SentinelOne, Inc. Capabilities depend on the licensed product tier and the policy applied to your environment.

Layered defence

What Endpoint Security Does Not Replace

EDR is one layer. Presenting it as a complete security posture is how organizations end up exposed on the fronts it never covered.

  • Email security, which acts before the message reaches the user
  • MFA and identity protection, because a valid login is not malware
  • SIEM and broader log visibility across systems without an agent
  • Backup and disaster recovery, which is what restores operations
  • Incident response, which is a coordinated process rather than a product
  • User awareness, because people are still targeted directly

Endpoint security works because the other layers exist around it. That is the point of the layered architecture described on the cybersecurity overview.

Cybersecurity overview: the layered Mayer Networks standard

Lifecycle stage: Protect and Detect

The layers most closely connected to this one. Each covers a front this control does not.

We can review which workstations and servers are actually protected today, how the policy is configured, and who is reviewing the detections.

Review Endpoint Coverage

Detection is only as good as the response behind it

Modern endpoint tools detect behaviour rather than known file signatures, which is what catches an attacker using legitimate administrative tools with stolen credentials. The detection itself is a commodity; the difference is whether anything happens when it fires at 11pm on a Saturday.

That is the question worth asking any provider: who reviews the alert, what authority they have to isolate a machine, and how quickly the organization is told. An unmonitored console is a record of the incident, not a defence against it.

Why Mayer Networks

  • Deployed by the team that manages the endpoints
  • Coverage verified, not assumed
  • One organization accountable for support, engineering, security, infrastructure and communications.
  • Responsive remote and onsite support from engineers based in Southern Illinois, not a queue in another time zone.

Security considerations

  • Tamper protection so attackers cannot simply disable the agent
  • Isolation capability for compromised systems
  • Detection history retained for investigation

Questions

Frequently asked questions

Still have a question? Call 618-529-4922 or send us the details.

What is the difference between antivirus and EDR?

Antivirus blocks known bad files. EDR records endpoint behavior, detects suspicious activity patterns, and gives responders the ability to investigate and isolate a machine.

Does EDR slow computers down?

Modern agents are lightweight. Performance issues are usually caused by policy conflicts, which tuning resolves.

Do servers need endpoint protection too?

Yes. Servers are high-value targets and are frequently where ransomware does the most damage.

Who watches the alerts?

With managed detection, alerts are investigated by security personnel rather than left to the client.

Let's talk about your technology

Tell us what you are running and what is not working. We will tell you plainly what we would do about it.