<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender GravityZone EDR Cloud?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>EDR sensor</strong> – Records endpoint activity and sends events to the cloud console.<br /> <strong>GravityZone Control Center</strong> – Single web console for policies, incidents and response actions.<br /> <strong>Cross-endpoint correlation</strong> – Joins related detections on several machines into one incident.<br /> <strong>Sandbox Analyzer</strong> – Detonates suspicious files in an isolated cloud environment.<br /> <strong>Search and telemetry</strong> – Historical and live search across recorded EDR raw events.<br /> <strong>Important</strong> – No firewall, device control, patch management or encryption included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender GravityZone EDR Cloud?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Bitdefender GravityZone EDR Cloud is a standalone endpoint detection and response product that records what happens on Windows endpoints and turns those events into investigable incidents. It is managed entirely from the cloud-hosted GravityZone Control Center and is built to run next to an endpoint protection platform that is already in place, including one from another vendor.<br /> <br /> <strong>No AV replacement</strong> – Deploys without removing the antivirus you already run.<br /> <strong>Faster root cause</strong> – Shows where an incident started and how it spread.<br /> <strong>Fewer separate alerts</strong> – Related detections arrive as one incident, not dozens.<br /> <strong>Direct response actions</strong> – Isolate a host or stop a process from the console.<br /> <strong>MITRE ATT&amp;CK mapping</strong> – Detections are labelled with recognised attacker techniques.<br /> <strong>Path to MDR</strong> – Bitdefender MDR builds on the same EDR deployment.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Why Windows Defender alone is not enough</strong><br />Explains why prevention on its own leaves attacks unnoticed, which is the gap an EDR layer is meant to close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender GravityZone EDR Cloud suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether someone will actually look at the incidents. EDR produces findings that a human has to triage, so a company without that capacity should pair the product with a managed service rather than buy detection it will never read.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Staff available to triage EDR alerts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">MDR advised</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">With MDR</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone EDR Cloud meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The obligation that matters here applies to operators of critical infrastructure, not to every Swiss company. Since 1 April 2025 the revised Information Security Act requires those operators to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. A 24-hour deadline is an evidence problem before it is a paperwork problem, and that is the part this product supports: the incident view reconstructs which process started the attack, which endpoints it reached and in what order, which is the substance of a first notification. What it does not do is decide whether an event is reportable, produce the notification itself, or say anything about systems its Windows sensor is not installed on, so a Linux server or a Mac outside the sensor scope contributes nothing to that timeline. It also does not replace the internal duty roster that has to notice an alert on a Saturday night. This describes product capabilities and is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone EDR Cloud meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, processes and evidence rather than tooling. NIS 2 requires a set of risk management measures from essential and important entities, among them incident handling, detection and reporting, business continuity and backup, supply chain security, cyber hygiene and training, access control, and the use of cryptography. Bitdefender GravityZone EDR Cloud contributes to the detection and incident handling category: it records endpoint activity, correlates it into incidents, and supports response actions and post-incident analysis. It contributes nothing to backup and continuity, encryption, multi-factor authentication, awareness training, patching or supplier assessment, and it produces no evidence at all for endpoints outside its Windows sensor scope. Treat it as one measure inside a larger programme, not as a compliance component.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone EDR Cloud help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a specific and fairly narrow group of questions. It answers the items on endpoint detection and response coverage, alert triage, attack chain reconstruction, incident retention, response actions such as host isolation, and whether security events can be forwarded to a SIEM. It does not answer the items on antivirus and malware blocking, firewall and device control, patch levels, disk encryption, mobile device management, backup and restore testing, or coverage of macOS and Linux machines, and answering those with this product in place means naming the other tools that carry them. If a questionnaire keeps failing on those points, moving up to GravityZone Business Security Enterprise is usually cheaper than pairing this product with a second vendor, because the prevention layer, the add-on options and the EDR data then sit in one console under one supplier relationship.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: how backups help you avoid outages</strong><br />Covers the backup and recovery side that endpoint detection does not touch, and that questionnaires ask about separately.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between GravityZone EDR Cloud and GravityZone Business Security Enterprise?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is that GravityZone Business Security Enterprise includes the blocking endpoint protection platform and GravityZone EDR Cloud does not; EDR Cloud is the detection and investigation layer you place next to protection you already own. The second difference is reach: the Enterprise edition extends EDR to macOS and Linux and accepts XDR sensors for identity, network, cloud and productivity applications, while EDR Cloud stays on Windows. Buyers who remember the older catalogue should note that the bundled protection and EDR product Bitdefender sold as GravityZone Ultra was renamed GravityZone Business Security Enterprise in April 2022, with no change to what it contained. Choose EDR Cloud when a third-party antivirus is staying in place for now, and the Enterprise edition when you are prepared to replace it.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">GravityZone EDR Cloud</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Business Security Enterprise</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Blocking antivirus on the endpoint</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">EDR sensor and incident correlation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">EDR platform coverage</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows only</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows, Mac, Linux</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Runs beside a third-party antivirus</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Firewall and device control</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Patch management and encryption add-ons</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">XDR sensors</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The EDR sensor runs on Windows endpoints only, so macOS and Linux machines stay outside the recorded telemetry and need either a different Bitdefender edition or a different tool. The prevention modules that come with this licence model, including Advanced Threat Control, Network Protection and Fileless Attack Protection, are preset to report only, which means the product tells you what happened but is not the component that stops it. Investigable incidents are retained for 90 days, while the searchable raw event history depends on a separate data retention entitlement sold in 90, 180 and 365 day steps, so decide on the look-back window before you promise an auditor a specific one. Patch management, full disk encryption, storage protection and the Report Builder are not available on this product, and that is where most follow-up purchases originate. The cloud console runs in several hosting regions and Bitdefender also offers an EU-hosted variant, so confirm which region your tenant is created in before signing a data processing agreement.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>Best antivirus programs for Windows 2025</strong><br />Helps you choose the prevention layer this product expects to find already installed on the endpoint.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender GravityZone EDR Cloud</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it work with any antivirus already installed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">It is designed to work alongside competing endpoint security products, with one documented exception: products that use the Bitdefender SDK under the hood. Several vendors license Bitdefender engines for their own suites, so check what your current product actually runs on before you plan the rollout.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which response actions can an administrator take from the console?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">From an incident you can isolate the affected host, terminate a running process, and add a file hash to a blocklist that applies across the company. Beyond that, custom detection rules and YARA rules let you turn a finding from one investigation into an ongoing detection.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can EDR events be forwarded to an existing SIEM?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The Security Telemetry feature streams EDR raw events out of the console, and Bitdefender documents integrations for Splunk, IBM QRadar and Microsoft Sentinel. This matters if your incident evidence has to be retained centrally rather than only inside the GravityZone console.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-endpoint,sec-console" data-audience="b2b" data-count="3"> </div>