Endpoint Detection and Response EDR Switzerland – KPX AG SentinelOne
Managed Security – KPX AG

Endpoint Detection & Response (EDR)

Traditional antivirus is no longer sufficient. Modern ransomware and zero-day attacks bypass signature-based detection. KPX AG provides managed EDR for your clients and servers – powered by SentinelOne Singularity Complete.

20+

Years of IT experience

Personal

not a hotline

DSG

compliant IT services

1h

response time (SLA)

Why EDR?

Why traditional antivirus is no longer enough

Modern cyberattacks no longer rely on known malware with detectable signatures. Attackers use fileless techniques, exploit legitimate system tools (Living-off-the-Land) and deploy zero-day exploits that bypass all signature-based detection. EDR detects attacks based on behaviour – in real time, before damage occurs.

Ransomware
Detected before mass encryption begins
Zero-Day Attacks
Behaviour-based detection without signatures
Fileless Malware
Kernel-level monitoring catches memory attacks
Client Protection

SentinelOne Singularity Complete – Client EDR

SentinelOne Singularity Complete provides AI-powered endpoint protection for laptops, desktops and Mac devices. All features are included – no additional modules required.

Behaviour-based AI detection

SentinelOne analyses every process on the endpoint in real time. Attacks are detected based on behaviour – regardless of whether the malware is known or not. Zero-day exploits have no chance.

Automated incident response

Detected threats are immediately and automatically isolated, neutralised and cleaned up. Affected processes are stopped, malicious files quarantined – without manual intervention.

Storyline™ attack visualisation

Every attack is automatically documented as a complete attack chain. Your IT team or KPX AG can trace exactly what happened, which systems were affected and how the attack progressed.

1-click rollback

If ransomware has already encrypted files, SentinelOne can restore the affected system to the state before the attack – without data loss and without paying a ransom.

Threat intelligence & IoC feeds

SentinelOne connects to global threat intelligence networks. Known attack indicators (IoCs) are automatically blocked before they can cause damage.

Low system load

The SentinelOne agent runs efficiently in the background and does not affect the performance of your devices. Compatible with Windows, macOS and Linux.

Server Protection

SentinelOne Singularity Complete – Server EDR

Servers are the most valuable targets in any corporate network. SentinelOne provides the same protection level for servers as for clients – on-premises, in the cloud and in hybrid environments.

Windows Server & Linux support

Full EDR coverage for Windows Server 2012 R2 and newer as well as common Linux distributions (Ubuntu, CentOS, RHEL, Debian). On-premises and in the cloud.

Kernel-level monitoring

SentinelOne monitors at kernel level – the deepest layer of the operating system. Fileless attacks, rootkits and living-off-the-land techniques are reliably detected.

Ransomware protection for file servers

Honeypot files and behavioural analysis detect ransomware on file servers at the earliest stage – before mass encryption begins.

Network isolation

Compromised servers are automatically isolated from the network within seconds – without manual intervention. This prevents lateral movement and limits the blast radius of an attack.

SIEM integration

All events are forwarded to your SIEM or to KPX AG's SOC. Full audit trail for compliance requirements (NIS2, ISO 27001, cyber insurance).

Compliance logging

Detailed event logs for all server activities. Supports compliance with Swiss nDSG, GDPR and industry-specific requirements.

Compliance

NIS2 and cyber insurance: EDR as a mandatory building block

The NIS2 directive requires companies to implement appropriate technical security measures – EDR is explicitly mentioned as a recommended measure. Swiss cyber insurers increasingly require EDR as a minimum standard for coverage. SentinelOne is accepted by all major insurers.

NIS2 compliance
EDR fulfils the NIS2 requirement for technical endpoint protection measures.
Cyber insurance
KPX AG provides all documentation required by your insurer.
Swiss nDSG
All data is processed in compliance with the Swiss Data Protection Act.
ISO 27001 support
EDR events and audit trails support ISO 27001 certification.
FAQ

Frequently asked questions about EDR

What is the difference between EDR and traditional antivirus?

Traditional antivirus relies on signature databases – it only detects known malware. EDR (Endpoint Detection & Response) uses AI and behavioural analysis to detect unknown threats, zero-day exploits and fileless attacks in real time. EDR also provides automated response capabilities that go far beyond simple quarantine.

Does SentinelOne replace our existing antivirus?

Yes. SentinelOne Singularity Complete is a complete replacement for traditional antivirus solutions. It provides all the functions of classic endpoint protection plus advanced EDR capabilities. Running both solutions in parallel is neither necessary nor recommended.

How quickly can EDR be deployed?

The SentinelOne agent can typically be rolled out to all endpoints within one to two working days. KPX AG handles the complete deployment, configuration and initial tuning – you don't need to do anything.

Is EDR required for cyber insurance?

Many Swiss cyber insurers now require EDR as a minimum requirement for coverage or offer significantly better premiums with EDR in place. SentinelOne is accepted by all major insurers. KPX AG can provide the necessary documentation for your insurer.

Does EDR also work for home office and remote workers?

Yes. The SentinelOne agent works independently of the corporate network. Laptops and remote workstations are protected regardless of where they connect from – home office, hotel or public Wi-Fi.

What does KPX AG do in the event of a security incident?

KPX AG monitors all EDR alerts and responds immediately to critical incidents. We isolate affected systems, analyse the attack chain using Storyline™, clean up the threat and restore normal operations. You receive a detailed incident report after every significant event.

How much does managed EDR cost?

The cost depends on the number of protected endpoints (clients and servers). KPX AG offers transparent per-device pricing with a fixed monthly fee – no hidden costs. Contact us for a personalised quote.

Free EDR consultation

We analyse your current endpoint protection and show you how SentinelOne EDR can protect your business – without obligation.

Request free consultation044 589 695 5
IT security analyst monitoring endpoint threats – KPX AG Switzerland

What KPX AG provides

  • Deployment and configuration on all devices
  • Ongoing monitoring of the EDR console
  • Incident response: isolation, clean-up, rollback
  • Policy tuning to address new threats
  • Reporting for compliance and cyber insurance
  • Coordination with your internal IT team

Technology partner

SentinelOne

Singularity Complete

  • Gartner Magic Quadrant Leader
  • MITRE ATT&CK: Highest detection rate
  • Windows, macOS, Linux
  • Client & Server equally protected
  • Automated rollback (Windows)

Transparent pricing

Per-device monthly fee – no hidden costs. Contact us for a personalised quote based on your fleet size.

Request pricing

Service area

KPX AG

Grindelstrasse 6, 8304 Wallisellen

Canton Zurich, Switzerland

We serve SMEs throughout Switzerland – remote and on-site when needed.

Protect your endpoints today

We serve SMEs throughout Switzerland – remote and on-site.