<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender GravityZone Endpoint Detection and Response Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>EDR sensor</strong> – Records process, file and network activity on each endpoint.<br /><strong>Incident Advisor</strong> – Plain-language summary of what happened and why.<br /><strong>Root Cause Analysis</strong> – Traces the incident back to its entry point.<br /><strong>Response actions</strong> – Endpoint isolation, process termination and remote shell sessions.<br /><strong>Search and blocklist</strong> – Hunt for indicators and block them across endpoints.<br /><strong>Important</strong> – It has no own antivirus and requires a base licence.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender GravityZone Endpoint Detection and Response Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The add-on extends an existing GravityZone licence with detection, investigation and response, managed from the same cloud Control Center as the prevention modules. Bitdefender previously sold this component as the GravityZone Ultra Add-on (EDR).<br /><br /><strong>No second console</strong> – Detections appear beside the antivirus alerts you already read.<br /><strong>Cross-endpoint correlation</strong> – Links events on several machines into one incident.<br /><strong>Faster triage</strong> – Written incident summaries replace manual log reconstruction.<br /><strong>Guided response</strong> – Suggested containment steps for staff without SOC experience.<br /><strong>Incident history</strong> – GravityZone keeps incident records for ninety days.<br /><strong>MITRE mapping</strong> – Tactics and techniques labelled for later audit reports.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where signature and behaviour based prevention stops, which is exactly the gap an EDR layer is bought to close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender GravityZone Endpoint Detection and Response Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Company size matters less here than two other things: whether you already run a GravityZone base licence, and whether someone in the organisation will actually look at an incident when it appears. The add-on produces findings that need a human decision, so it pays off where an internal administrator or a service provider is responsible for security by name.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Likely</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Someone available to act on an alert</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Endpoint Detection and Response Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In Switzerland the reporting obligation applies to operators of critical infrastructure, not to every company, so the first question is whether your organisation is in scope at all. Under the revised Information Security Act, those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. A 24-hour report needs facts rather than impressions, and that is the concrete contribution of this add-on: the incident record shows which endpoint was affected, which process started the chain, and at what time, so the questions can be answered without reconstructing raw logs first. What it does not do is decide whether an event is reportable, write the report, or see systems where no agent is installed, such as network appliances, most OT equipment and mobile devices. It also cannot tell you whether personal data left the company, which is a separate assessment with its own obligations. This text is not legal advice, and whether your company falls under the reporting obligation should be clarified with a qualified advisor.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Endpoint Detection and Response Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company NIS 2 compliant, because the directive addresses organisational measures, governance and reporting rather than software features. NIS 2 asks for risk analysis, incident handling, business continuity, supply chain security, and procedures for checking whether the chosen measures actually work. This add-on supports the incident handling category in a way you can point to: it detects activity after prevention has failed, retains incident records for ninety days, and offers containment actions that can be taken before an external specialist is on site. It does not support business continuity, because it neither backs up nor restores data, and it contributes nothing to supply chain security or to governance. Reporting duties, deadlines and supervision are defined by each member state when the directive is transposed, so what the product delivers is evidence for a process your organisation still has to write down itself.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Endpoint Detection and Response Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and the split is predictable enough to plan around. Questions it answers with an export from the console: whether endpoint activity is monitored beyond signature-based antivirus, whether detections are investigated centrally, how long incident data is retained, whether a compromised endpoint can be isolated from the network, and which named people are allowed to trigger that action. Questions it does not answer: patch level of third-party applications, disk encryption status, mobile device coverage, mailbox protection, and log retention for anything the endpoint agent does not see. If a questionnaire fails on those points, the cheaper route is usually another add-on from the same family, such as Patch Management or Full Disk Encryption, or a move up to Business Security Enterprise. Mixing in a second vendor means a second console, a second set of exclusions and a second support contact, which costs more administrative time than the licence difference usually saves.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between GravityZone Business Security Premium and GravityZone Business Security Enterprise?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is that Business Security Enterprise already contains the EDR component, while Business Security and Business Security Premium do not. Buying this add-on therefore only makes sense on top of a base licence that lacks EDR; adding it to Business Security Enterprise would duplicate a function you already own. Bitdefender previously sold the same component as the GravityZone Ultra Add-on (EDR), and Business Security Enterprise itself was formerly called GravityZone Ultra, which is why both old names still turn up in older quotes and comparison charts. Prevention behaves the same way in all three routes, so the decision is about detection depth and about which licence you already hold, not about how well malware is blocked.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Business Security Premium</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Premium plus EDR Add-On</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Business Security Enterprise</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Prevention and antivirus modules</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">EDR sensor and incident view</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Root Cause Analysis and Incident Advisor</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint isolation and remote shell</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Extended raw event retention</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Extra add-on</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Extra add-on</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Extra add-on</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In GravityZone Cloud this add-on cannot be operated on its own; it needs a base licence that supplies the prevention layer, and Bitdefender sells a separate standalone EDR product type for organisations that want to keep another vendor's antivirus. Incidents are retained for ninety days, but access to the underlying raw events depends on a separate EDR Data Retention add-on, sold in 90, 180 and 365-day variants, which is the single most common source of a surprise follow-up purchase. On Linux the EDR sensor only works on supported kernel versions and distributions, using auditd on older systems and kprobes on modern ones, so a Linux fleet should be checked against the current support list before rollout rather than after. The add-on also covers nothing outside the endpoint agent: it does not patch third-party software, does not manage disk encryption, does not protect mailboxes, does not include mobile devices, and does not back up or restore anything. Finally, the console is a cloud service running on several separate GravityZone instances, so if data location matters to your customers or auditors, confirm with your reseller which instance your tenant is created on.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the recovery side that no EDR product handles, and why detection and backup are two separate line items in a security budget.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender GravityZone Endpoint Detection and Response Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can we keep our current antivirus and only add this component?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Not with this add-on in GravityZone Cloud, because it is licensed to work alongside a Bitdefender base product that provides prevention. Bitdefender offers a separate standalone EDR product type for exactly that situation, where the sensor is installed next to an existing third-party endpoint platform. That is a different purchase, so check the product type on the quote before ordering.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can we hand the monitoring over to Bitdefender later?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, and the EDR add-on is the prerequisite for it. Bitdefender MDR requires EDR to be present, so companies that start with the add-on and later find nobody has time to read incidents can move to the managed service without replacing the agent or the console.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-endpoint,sec-console" data-audience="b2b" data-count="3"> </div>