Endpoint Detection & Response – EDR for SMEs.

Traditional antivirus is no longer enough. EDR detects attacks by behaviour – also without known signatures. For clients and servers, fully managed by KPX AG.

SentinelOne Singularity Complete – Gartner Magic Quadrant Leader for endpoint protection
Behaviour-based AI detection – also catches zero-day exploits without signatures
Automated response: isolation, quarantine and one-click rollback in seconds
NIS2- and FADP-compliant reporting – with cyber-insurance documentation included
20+

Years of IT experience

Personal

fixed point of contact

FADP

compliant IT services

Specialised

in Swiss SMEs

Classic antivirus no longer keeps up with modern attacks

We deploy SentinelOne Singularity Complete – behaviour-based AI detection instead of signature matching. Attacks are recognised before damage occurs.

Fileless attacks bypass signature-based antivirus

Modern malware often runs exclusively in memory – no file, no fingerprint for legacy scanners to match. Attacks stay invisible until the damage is done.

Living-off-the-Land abuses legitimate tools

Attackers use PowerShell, WMI, certutil and other built-in Windows tools for their purposes. Classic antivirus sees no foreign code – because there is none. Only behaviour analysis spots the patterns.

Zero-day exploits strike before patches exist

Vulnerabilities are actively exploited before vendors can react. By the time a signature update is rolled out, systems are already compromised. EDR detects exploitation regardless of patch status.

Ransomware moves faster than signature updates

New ransomware families appear every day. Between emergence and signature update, hours or days pass – in which attackers encrypt your file servers. EDR stops the encryption at the start, not at detection.

AI-driven endpoint protection with SentinelOne

The SentinelOne Singularity platform combines signatureless AI detection with automated response and one-click rollback – for clients and servers.

AI-driven behaviour analysis

SentinelOne analyses every process on the endpoint in real time. Attacks are detected by behaviour – regardless of whether the malware is known or not. Zero-day exploits have no chance.

Automated incident response

Detected threats are immediately and automatically isolated, neutralised and cleaned up. Affected processes are stopped, malicious files quarantined – without manual intervention.

One-click rollback

If ransomware has already encrypted files, SentinelOne restores the affected system to the state before the attack – without data loss and without paying a ransom.

Full forensics with Storyline™

Every attack is automatically documented as a complete attack chain. Your IT team or KPX AG can trace exactly what happened, which systems were affected and how the attack progressed.

Threat intelligence & IoC feeds

SentinelOne connects to global threat intelligence networks. Known attack indicators (IoCs) are automatically blocked before they can cause damage.

What does modern endpoint protection look like?

We analyse your current endpoint landscape – free of charge and without obligation.

From audit to fully managed EDR in four steps

01

Free endpoint audit

You describe your current endpoint environment – clients, servers, mobile devices. We listen, ask the right questions and build a clear picture of your actual attack surface.

Free
02

Pilot deployment

We deploy SentinelOne on a representative group of endpoints, configure policies to your environment and tune detection thresholds. You see real detections within days, not months.

Hands-on
03

Full rollout

After your team signs off on the pilot, we roll out the EDR agent to every endpoint and server. Deployment typically completes within one to two working days.

Predictable
04

Managed 24/7 by KPX

Our SOC monitors every alert, responds to incidents and tunes policies as threats evolve. NIS2- and FADP-compliant reporting is included – with cyber-insurance documentation on request.

Proactive

Three support models – matching your security needs

All three models run on the same SentinelOne platform. The difference is the depth of support – from pure provisioning to fully managed SOC operations.

Fully Managed

SMEs without in-house IT staff

We take care of everything

Platform & LicencesManaged by KPX

KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)

Monitoring & AlertingManaged by KPX

Monitoring of your entire IT infrastructure

Incident Resolution & OperationsManaged by KPX

Incident resolution, updates and ongoing development

End-User Support (Helpdesk)Managed by KPX

Remote support, on-site when needed

Hybrid Model

SMEs with their own IT team

We share responsibilities with your team

Platform & LicencesManaged by KPX

KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)

Monitoring & AlertingShared

KPX monitors servers & backup, you handle workstations

Incident Resolution & OperationsShared

Incidents handled by responsibility & joint development

End-User Support (Helpdesk)Shared

Your team helps remotely and on-site – KPX on demand

Self-Service

Larger IT teams

You operate independently – on our platform.

Platform & LicencesManaged by KPX

KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)

Monitoring & AlertingManaged by your team

Monitoring of your entire IT infrastructure

Incident Resolution & OperationsManaged by your team

Incident resolution, updates and ongoing development

End-User Support (Helpdesk)Managed by your team

Remote support, on-site when needed

General information about Endpoint Detection & Response for SMEs

What EDR is, how it differs from traditional antivirus, and why NIS2 and FADP compliance make it a mandatory building block for Swiss SMEs.

What is EDR?

Endpoint Detection & Response is the next evolution of endpoint security. Instead of comparing files against a database of known malware, EDR continuously monitors the behaviour of every process on every endpoint. Attacks that have never been seen before – zero-day exploits, fileless malware, Living-off-the-Land techniques – are recognised in real time and stopped automatically. The Swiss National Cyber Security Centre (NCSC) recommends EDR as a baseline control for organisations with elevated security requirements.

EDR vs. classic antivirus

Classic antivirus relies on signature databases – it only detects malware that has already been catalogued. Attackers know this and craft their payloads accordingly: fileless attacks, encrypted payloads, abuse of legitimate system tools. EDR analyses behaviour, not signatures. A process that suddenly starts encrypting thousands of files in seconds is stopped – regardless of whether the encryption tool is a known ransomware family or a brand-new variant. EDR does not replace antivirus; it is the next generation of endpoint protection.

NIS2, FADP and cyber insurance

The NIS2 directive (implemented in Switzerland via the revised ISG) requires affected organisations to implement technical measures for detecting and responding to security incidents. The Swiss Federal Act on Data Protection (FADP) imposes strict rules on how security events are logged and documented. Many Swiss cyber insurers now require active endpoint protection – typically EDR – as a prerequisite for coverage. SentinelOne satisfies all three requirements with lückenlosem logging, audit trails and certified integrations.

SentinelOne – EDR features

  • Behaviour-based AI detection – signatureless, in real time
  • Automated incident response: isolation, quarantine, rollback
  • Storyline™ forensics – full attack chain for every incident
  • Threat intelligence and IoC matching against global feeds
  • Kernel-level monitoring for fileless and rootkit attacks
  • Windows, macOS and Linux – on endpoints and servers
  • NIS2- and FADP-compliant audit logs

NinjaOne – RMM features

  • Automated patch management for Windows, macOS and Linux
  • 3rd-party patching for browsers, Adobe, Java, Office add-ins
  • Hardware inventory with warranty tracking
  • Software distribution and licence management
  • Remote support with consent-based secure access
  • Script automation for recurring maintenance tasks
  • IT insights and reporting dashboards

Sources: NCSC Switzerland · SentinelOne · NinjaOne · MITRE ATT&CK

Managed EDR for SMEs – what you get

  • 1

    Real-time threat detection

    AI-driven behaviour analysis catches ransomware, zero-day exploits and fileless attacks the moment they start – not hours later when the signature database catches up.

  • 2

    Automated response without intervention

    Detected threats are isolated, neutralised and cleaned up automatically. Your team only sees real incidents – not thousands of false positives.

  • 3

    Ransomware rollback on demand

    Encrypted files are restored to their pre-attack state with a single click. No data loss, no ransom payment, no extended downtime.

  • 4

    NIS2- and FADP-compliant reporting

    Every security event is logged with a full audit trail. Reports satisfy regulatory requirements and serve as documentation for your cyber insurer.

  • 5

    Cyber insurance compliance

    Many Swiss insurers now require EDR as a prerequisite for coverage or offer significantly better premiums when EDR is in place. We provide all required documentation.

  • 6

    Managed 24/7 by KPX in Switzerland

    Our Swiss SOC monitors every endpoint around the clock. One fixed contact, one fixed monthly price, one fixed SLA – your endpoint security never depends on a single absent employee.

Frequently asked questions about EDR

Service area

KPX AG

Grindelstrasse 6, 8304 Wallisellen

Canton of Zurich, Switzerland

We deliver managed EDR to SMEs throughout Switzerland from Wallisellen – remote and on-site when needed. Main hub: greater Zurich area.

KPX AG · Wallisellen ZH

Ihre IT in zuverlässigen Händen

KPX runs managed EDR for Swiss SMEs on SentinelOne Singularity Complete – behaviour-based AI detection, automated response, NIS2- and FADP-compliant reporting and cyber-insurance documentation from a single Swiss partner.

Feste Reaktionszeit (SLA)Datenschutz nach DSG & DSGVOVor-Ort Service aus Wallisellen