QS-WAN · Compare

Best endpoint protection: eight questions, not a leaderboard

Best endpoint protection is a fit, not a league table, and any vendor that ranks itself first is selling you the ranking. These are the eight questions we’d put to a supplier, the mechanism behind each one, and where our own answers are weak. Run them against what you already own.

Credit

What the product you already run is good at

Give the incumbent its due, because most have earned it.

Years of detection research

A mature suite brings years of detection research.

A pipeline nobody on your team feeds

It brings a signature pipeline nobody on your team feeds.

They see the bad thing

Nearly all of them see the bad thing.

What separates them is the two seconds after.

The questions

The eight questions

Each has an answer a supplier can give in one sentence. Ask for the mechanism, not the adjective.

Does it contain before it asks?

A prompt is a pause, and encryption doesn’t pause with it. Ask which thread suspends the suspect process tree, and whether that happens before the decision card is drawn or after the event reaches a server.

Where does the rule set live, and who writes to it?

Malware that can switch the agent off has already won. Ask which directory holds the rule store, whether the privileged service takes orders from a caller that isn’t elevated, and whether the driver unloads mid-scan.

Quarantine, or delete?

Every engine is wrong sometimes. A verdict that deletes costs a restore from backup; one that moves the file costs two minutes. Ask who may list quarantine and who may restore.

Does it defend files, or only judge processes?

Detection watches behaviour, so it won’t stop a program the engine already trusts. Ask whether named folders close to unrecognised programs at the file system, and whether bait files sit where nothing legitimate would touch them.

What happens when it can't finish the analysis?

A fail-open product gives the file the benefit of the doubt when a scan times out or a driver didn’t load. A fail-closed one refuses and says on screen that it’s degraded.

Can the console tell "recorded" from "applied"?

A saved setting is an intention, and the laptop in the back of somebody’s car hasn’t heard it. Ask whether policy is signed before it leaves the console, and what the screen says about a machine that never answered.

What does it do on each platform, layer by layer?

Ask for capability by layer, not a tick per operating system. Which detection engines run on the Linux build, what monitoring reaches macOS, what a phone gets.

Product, or service?

A managed service means somebody else is watching. A product means you are. The expensive mistake is buying one while believing you bought the other.

Your desk

What the answers change on your desk

Questions 1 and 5 decide whether a detection at 16:40 on a Friday ends your week or your weekend. Question 3 decides whether a false positive costs you two minutes or the backup team an afternoon.

Order of operations Ask first, then act Contain first, then ask the suspect process, all the way down 01 An engine is sure identical in both architectures 03 The decision card is drawn a person is asked what to do 02 The event is written and sent the process keeps running 04 The action follows the answer the writing ran all along writes stop 02 The process tree is suspended on the catching thread writes stop 04 Quarantine, or released back a wrong verdict stays reversible
what it buys you

Nothing is ever frozen by mistake.

The writing stops before the question is asked.

what it costs you

A prompt is a pause, and encryption does not pause with it.

Something harmless gets frozen now and then, and that is a restore.

What this compares is the order of containment and the question. It does not compare how well anything detects, and nothing here is a measurement.

The writing stops after the answer

The diagram compares two orderings of the same four moments after a detection engine is sure about a process. A rail runs down the left side and stands for the suspect process still writing; it is drawn in the live colour while the writing continues and in the stopped colour once it has been contained. In the first ordering the engine is sure, the event is written and sent, a decision card is drawn for a person, and the action follows their answer, so the writing only stops at the fourth moment. What that ordering buys you is that nothing is ever frozen by mistake, and what it costs you is that a prompt is a pause and encryption does not pause with it. In the second ordering the catching thread suspends the process tree at the second moment, the decision card is drawn afterwards about something already frozen, and the answer sends the file to quarantine or releases it back. What that buys you is that the writing stops before the question is asked, and what it costs you is that something harmless gets frozen now and then, which is a restore. What the diagram compares is the order of containment and the question. It does not compare how well anything detects.

Our answers

Where we answer these well, and where we don't

Containing, and who can write to the rules

On 1, the process tree is suspended on the thread that caught it, before the card is drawn. On 2, the rule store sits in a machine directory only administrators can write to, and the shield won’t unload while a scanner is attached.

Verdicts, and the folders themselves

On 3, findings go to quarantine rather than deletion: listing needs no privilege, restoring does. On 4, Documents, Pictures and Desktop can be closed to unrecognised programs, with decoy files planted in the same pass.

Where the answer is split

On 5 the answer is split: file analysis is fail-closed, and the service says when it’s running in user mode only, but folder protection is off by default. On 6, company policy is signed before it leaves the console, though a green response proves the instruction was recorded, not that a sleeping laptop obeyed it.

Platforms, and product or service

On 7 the answer runs by layer, and one layer is narrow. Client, tunnel and policy: Windows complete, Linux a genuine port with gaps we’ll name, macOS and Android covered, iOS next. Monitoring and CIS benchmarks: Windows complete, Linux and macOS covered. The detection engines run on Windows only. On 8 we’re a product, and nobody here watches your fleet.

Switching

What switching actually involves

Pilot

The pilot has to include the thing that is off

A pilot group first, with folder protection deliberately turned on, because it's off by default and a pilot that skips it tests the wrong product.

Then a week or so of trust-list work while the engines meet your Windows line-of-business software.

Policy

Where the policy is written, and where the control plane sits

Policy is written once and scoped by gateway, user or device, and a device override only changes the ids it sets.

The control plane runs on your own infrastructure: on-premise, private cloud or air-gapped.

Stay put

Don't switch if

Your current product answers 1, 2 and 5 well

Those three are structural and you can’t configure your way into them. The other five you can usually fix where you are, and moving a fleet for them is a bad trade.

You want somebody on the end of an alert at three in the morning

We don’t do that, and we’re not inventing a rota to win a deal. Buy a managed service.

The machines you're worried about aren't Windows

Client, policy and monitoring reach the rest of the fleet. The detection engines don’t, and you’d meet that gap in month one.

You only want the endpoint half

If the VPN, the password vault and the remote support tool are bought and fine, consolidation is most of what we bring, and it isn’t yours to collect.

Questions

Questions people ask

Is there a single best endpoint protection product?

No. There's a best fit for a given fleet, team size and tolerance for false positives. The eight questions are how you find yours.

Is it worth changing what we already run?

Only if the answers to 1, 2 or 5 are bad, because those are design decisions rather than settings. Independent test scores won't tell you: they cover detection rate and say nothing about 2, 5 or 6.

How many agents should endpoint protection be?

Ask what one signed agent would have to carry for the VPN client, the remote support tool and the password vault to stop being three more update paths. That case is endpoint protection.

Does this cover removable media and posture?

Both are usually separate purchases. Here they're a policy rule that blocks drives without blocking keyboards, and a posture score with named drivers.

Bring your answers to the eight

We’ll go through ours beside them, including where we come off worse. The demo is free, with nothing to sign and no clock running.

Scroll to Top