Traditional antivirus is no longer enough. EDR detects attacks by behaviour – also without known signatures. For clients and servers, fully managed by KPX AG.
Years of IT experience
fixed point of contact
compliant IT services
in Swiss SMEs
We deploy SentinelOne Singularity Complete – behaviour-based AI detection instead of signature matching. Attacks are recognised before damage occurs.
Modern malware often runs exclusively in memory – no file, no fingerprint for legacy scanners to match. Attacks stay invisible until the damage is done.
Attackers use PowerShell, WMI, certutil and other built-in Windows tools for their purposes. Classic antivirus sees no foreign code – because there is none. Only behaviour analysis spots the patterns.
Vulnerabilities are actively exploited before vendors can react. By the time a signature update is rolled out, systems are already compromised. EDR detects exploitation regardless of patch status.
New ransomware families appear every day. Between emergence and signature update, hours or days pass – in which attackers encrypt your file servers. EDR stops the encryption at the start, not at detection.
The SentinelOne Singularity platform combines signatureless AI detection with automated response and one-click rollback – for clients and servers.
SentinelOne analyses every process on the endpoint in real time. Attacks are detected by behaviour – regardless of whether the malware is known or not. Zero-day exploits have no chance.
Detected threats are immediately and automatically isolated, neutralised and cleaned up. Affected processes are stopped, malicious files quarantined – without manual intervention.
If ransomware has already encrypted files, SentinelOne restores the affected system to the state before the attack – without data loss and without paying a ransom.
Every attack is automatically documented as a complete attack chain. Your IT team or KPX AG can trace exactly what happened, which systems were affected and how the attack progressed.
SentinelOne connects to global threat intelligence networks. Known attack indicators (IoCs) are automatically blocked before they can cause damage.
We analyse your current endpoint landscape – free of charge and without obligation.
You describe your current endpoint environment – clients, servers, mobile devices. We listen, ask the right questions and build a clear picture of your actual attack surface.
FreeWe deploy SentinelOne on a representative group of endpoints, configure policies to your environment and tune detection thresholds. You see real detections within days, not months.
Hands-onAfter your team signs off on the pilot, we roll out the EDR agent to every endpoint and server. Deployment typically completes within one to two working days.
PredictableOur SOC monitors every alert, responds to incidents and tunes policies as threats evolve. NIS2- and FADP-compliant reporting is included – with cyber-insurance documentation on request.
ProactiveAll three models run on the same SentinelOne platform. The difference is the depth of support – from pure provisioning to fully managed SOC operations.
SMEs without in-house IT staff
We take care of everything
KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)
Monitoring of your entire IT infrastructure
Incident resolution, updates and ongoing development
Remote support, on-site when needed
SMEs with their own IT team
We share responsibilities with your team
KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)
KPX monitors servers & backup, you handle workstations
Incidents handled by responsibility & joint development
Your team helps remotely and on-site – KPX on demand
Larger IT teams
You operate independently – on our platform.
KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)
Monitoring of your entire IT infrastructure
Incident resolution, updates and ongoing development
Remote support, on-site when needed
SMEs without in-house IT staff
We take care of everything
KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)
Monitoring of your entire IT infrastructure
Incident resolution, updates and ongoing development
Remote support, on-site when needed
SMEs with their own IT team
We share responsibilities with your team
KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)
KPX monitors servers & backup, you handle workstations
Incidents handled by responsibility & joint development
Your team helps remotely and on-site – KPX on demand
Larger IT teams
You operate independently – on our platform.
KPX Smart Managed platform incl. licences (e.g. NinjaOne, SentinelOne)
Monitoring of your entire IT infrastructure
Incident resolution, updates and ongoing development
Remote support, on-site when needed
What EDR is, how it differs from traditional antivirus, and why NIS2 and FADP compliance make it a mandatory building block for Swiss SMEs.
Endpoint Detection & Response is the next evolution of endpoint security. Instead of comparing files against a database of known malware, EDR continuously monitors the behaviour of every process on every endpoint. Attacks that have never been seen before – zero-day exploits, fileless malware, Living-off-the-Land techniques – are recognised in real time and stopped automatically. The Swiss National Cyber Security Centre (NCSC) recommends EDR as a baseline control for organisations with elevated security requirements.
Classic antivirus relies on signature databases – it only detects malware that has already been catalogued. Attackers know this and craft their payloads accordingly: fileless attacks, encrypted payloads, abuse of legitimate system tools. EDR analyses behaviour, not signatures. A process that suddenly starts encrypting thousands of files in seconds is stopped – regardless of whether the encryption tool is a known ransomware family or a brand-new variant. EDR does not replace antivirus; it is the next generation of endpoint protection.
The NIS2 directive (implemented in Switzerland via the revised ISG) requires affected organisations to implement technical measures for detecting and responding to security incidents. The Swiss Federal Act on Data Protection (FADP) imposes strict rules on how security events are logged and documented. Many Swiss cyber insurers now require active endpoint protection – typically EDR – as a prerequisite for coverage. SentinelOne satisfies all three requirements with lückenlosem logging, audit trails and certified integrations.
Sources: NCSC Switzerland · SentinelOne · NinjaOne · MITRE ATT&CK
Real-time threat detection
AI-driven behaviour analysis catches ransomware, zero-day exploits and fileless attacks the moment they start – not hours later when the signature database catches up.
Automated response without intervention
Detected threats are isolated, neutralised and cleaned up automatically. Your team only sees real incidents – not thousands of false positives.
Ransomware rollback on demand
Encrypted files are restored to their pre-attack state with a single click. No data loss, no ransom payment, no extended downtime.
NIS2- and FADP-compliant reporting
Every security event is logged with a full audit trail. Reports satisfy regulatory requirements and serve as documentation for your cyber insurer.
Cyber insurance compliance
Many Swiss insurers now require EDR as a prerequisite for coverage or offer significantly better premiums when EDR is in place. We provide all required documentation.
Managed 24/7 by KPX in Switzerland
Our Swiss SOC monitors every endpoint around the clock. One fixed contact, one fixed monthly price, one fixed SLA – your endpoint security never depends on a single absent employee.
These managed services complement Endpoint Detection & Response perfectly
Managed Endpoint
Zentrale Verwaltung aller Arbeitsgeräte – Updates, Monitoring, Support.
Learn more →Managed Security Operations
SOC-gestützte IT-Sicherheit über alle Ebenen – Endpoint, Netzwerk, Cloud, Mensch.
Learn more →Managed Email Security
Schutz vor Phishing, Ransomware und CEO-Fraud – mit SPF, DKIM und DMARC.
Learn more →Managed Microsoft 365
Lizenzierung, Einrichtung, Migration und laufende M365-Betreuung.
Learn more →Managed Backup
Automatisierte, geprüfte Datensicherung – lokal, cloud oder hybrid.
Learn more →Managed Firewall
Next-Gen Hardware-Firewall mit drei Schutzstufen – aktiv betreut.
Learn more →Service area
KPX AG
Grindelstrasse 6, 8304 Wallisellen
Canton of Zurich, Switzerland
We deliver managed EDR to SMEs throughout Switzerland from Wallisellen – remote and on-site when needed. Main hub: greater Zurich area.
EDR is most effective as part of a layered security strategy. These services work hand in hand with managed endpoint detection and response.
Centralised device management with automated patching, inventory and remote support – the operational layer beneath EDR.
Learn more →24/7 Security Operations Centre covering endpoint, network, cloud and human risk – EDR as one layer of a complete defence.
Learn more →Automated, tested backups with immutable storage – the safety net that complements EDR when an incident escalates.
Learn more →Next-generation firewall management with IDS/IPS and VPN – the network layer that filters traffic before it reaches your endpoints.
Learn more →KPX runs managed EDR for Swiss SMEs on SentinelOne Singularity Complete – behaviour-based AI detection, automated response, NIS2- and FADP-compliant reporting and cyber-insurance documentation from a single Swiss partner.