When it comes to Endpoint Detection and Response (EDR), the good news is coverage is no longer the problem. Just over 96% of all endpoints carry some form of protection. The new hurdle is the strength of that protection. While only a small number of assets run no protection at all, there is another, much larger minority that still relies on basic protections that are no longer enough in the face of complex modern threats.
The reassuring finding first: the fully unprotected endpoint is nearly extinct. Lansweeper’s data team looked at several million endpoints across 30,000 organizations, spanning different sizes, industries and countries and found that only 3.9% carry no endpoint protection of any kind, and we counted strictly. VPN clients, vulnerability scanners, patch agents and privilege managers don’t qualify as endpoint protection in this analysis, although they do contribute to the overall security profile.
A much more uncomfortable finding sits directly behind that. When you look at what’s actually installed, and how strong that protection really is, 28% of endpoints run only a basic, signature-era antivirus without modern detection-and-response. In the face of modern, increasingly complex cyber attacks, these simply won’t cut it.
That leaves just 68.1% of endpoints running modern protection: the full EDR and next-generation antivirus (NGAV) tools that are built to recognize unusual behavior, not just threat signatures. As one ISC2-cited analysis of endpoint programs argues, coverage beats capability, but only up to a certain point. Near-universal coverage is a great achievement, but when the tooling is just baseline protection or outdated, it still leaves nearly one in three machines exposed in the modern threat landscape.

The 3.9% of endpoints that have no protection at all are not spread evenly. On laptops and desktops, coverage is close to universal. Only 2.6% of laptops and 3.6% of desktops run bare. The issue, unfortunately, lies with the assets that a SOC can least afford to lose sight of: 7.6% of servers have no detected protection. That’s three times the laptop rate.

Those numbers go against instinct. The servers are an organization’s beating heart, so they should be first in line for protection. Independent research shows otherwise. Elastic’s 2025 Global Threat Report found that endpoint coverage for servers, virtual machines and containers trails behind Windows-workstation coverage at most enterprises.
The causes are operational, not strategic. Laptops and desktops, especially Windows machines, lean heavily on basic, out-of-the-box protection like Windows Defender. Server-class EDR tools, on the other hand, are often a separate, costlier license that gets overlooked. Host protection for cloud infrastructure sits in an ownership dispute between security and infrastructure teams, where each assumes the other has it covered.
The stakes are what make this coverage gap expensive. Cyber-insurance underwriters now treat server-class endpoint protection as a hard requirement. Attestations that quietly cover only laptops are one of the biggest reasons claims get denied. A server without EDR coverage is not a rounding error. It is exactly the thing an attacker is looking for and an insurer will ask about.
When we look at the tools installed, a sharp regional split appears. In North America, 80.7% of endpoints run full EDR or NGAV. In Europe, that’s only 63.8%. 31.6% of European endpoints sit on basic antivirus, against 16.6% in North America. Put plainly, a European endpoint is almost twice as likely to run basic protection, or none at all, than a North American one.

The gap is, again, widest on servers: 9.6% of European servers have no detected protection at all. That is nearly double the rate of North America’s 5.7%. Independent market analysis already treats Europe as a distinct endpoint-security region.
North America’s stronger posture is partly due to Executive Order 14028, passed in 2021, which mandated modern EDR across federal civilian agencies. Regulation in Europe is still catching up. Since NIS2 came into the picture in 2024, an estimated 160,000-plus EU organizations are expected to demonstrate certified endpoint controls or face penalties reaching into the millions. However, enforcement of NIS2 has faced roadblocks and delays, meaning it is still rolling out unevenly across member states, so that the pressure hasn’t yet closed the gap.
If we look at the coverage by industry, the full-EDR-versus-basic-AV split is not settled by budget, but by how modern the estate is. Education & Non-Profit has the least modern protection of any sector, with only 55% on full EDR / NGAV. Energy & Utilities follows closely at 57% and both sit more than ten percent below everyone else. At the front of the pack, Manufacturing (74%), Finance & Insurance (74%) and Technology & Telecom (73%) lead, with Government (71%) close behind.

The North-America/Europe divide also compounds by sector: in Energy & Utilities, only 32% of European endpoints run full EDR protection against 88% in North America. European Government (42% vs. 87%) and Healthcare (50% vs. 85%) show the same chasm. The one counter-example is Education, where Europe (75%) actually outruns North America (63%).
Protection strength is not only a matter of what is installed but when. Many devices come with a basic, built-in antivirus. Stronger protections, on the other hand, don’t ship with the device by default. They are added later, and unfortunately, it’s often much later. To measure how fast they are added, we looked at assets first discovered in the last three months, recent enough that the first tool we see on a device really is the first it ever had.
The good news is deployment discipline is real. 59% of newly seen assets get full EDR or NGAV installed on day one, and 78% within their first month. But the tail is long: more than one in five assets (22%) needs to wait for over a month for modern protection. Until then, they rely only on what endpoint protection shipped in the box, which for many is a basic, signature-era antivirus, or worse, nothing at all.

The implication is problematic. The upgrade to real detection-and-response tools depends on someone knowing the device exists and getting to work. Anything that slips between the cracks in the inventory tends to stay on the basic tier indefinitely.
That tail is, once again, not evenly distributed either. Government (32%) and Healthcare (31%) leave the largest share of new machines exposed past their first month. The median new healthcare device waits nearly a week for real protection while the median device in most other sectors gets it on day one.
Let’s dig deeper into what tools are installed in our data set. The first surprise is how often tools overlap. Most protected machines run more than one security product at once: a device with CrowdStrike Falcon for detection-and-response almost always has Windows Defender antivirus active underneath it.
Modern endpoint security is built as a stack: anti-malware forms the base, with behavioral analysis and detection-and-response capabilities layered on top. Even the EDR vendors themselves define their solutions as just one layer within the endpoint security stack. That’s why the built-in antivirus should be treated as the foundation everything else builds upon. The divide in our data, between full EDR / NGAV and basic AV, is the difference between machines that stopped at that foundation and machines that built the stack.
It comes as no surprise then that the single most common piece of endpoint protection software is not an EDR platform, but the built-in Windows Defender antivirus, found on 68.8% of assets. The leading tool in our full-EDR category, CrowdStrike Falcon, follows at 22%. The two coexisting on the same machine is the norm, not the exception.

If we split the the numbers by device class, the picture remains stable. The leading EDRs hold roughly the same share on servers as on laptops. CrowdStrike leads with at 22–23% everywhere. For anti-virus the numbers change a little. The built-in Defender covers 72% of laptops but only 59% of servers, and we see the same gap between laptops and servers for tools like Sophos Intercept X. Unfortunately, that’s not because servers run a different stack. They simply have less of any sort of protection, which is exactly how 7.6% of them end up with nothing as we mentioned earlier.
When we list the EDR tools by vendor we see that the market is concentrated but regional. In North America, CrowdStrike Falcon leads with 32% of all assets followed by Rapid7 Insight Agent with 15% and SentinelOne on 13%. Together, they carry over 60% of the continent’s EDR-protected machines.
Europe is markedly more fragmented. CrowdStrike still leads and SentinelOne and Rapid7 still play, but only at half of their North American shares. They have to share the table with European and Asian vendors like Sophos Intercept X, Cortex XDR, Trend Micro Apex One, and Heimdal each holding a much larger slice of European assets than of NA ones.

Older reports framed the difference between North America and Europe as “Sophos-led Europe versus CrowdStrike-led North America.” This version no longer holds. CrowdStrike leads in both regions, but the fragmentation is the main difference. North America concentrates on two US pure-plays, while Europe spreads across a wider field where Sophos, Palo Alto, Trend Micro and regional players like Heimdal all matter.
The market overall is concentrated but not closed. The top five vendors hold roughly 58% of it, with a long tail of smaller vendors following. CrowdStrike’s lead is notable for having survived the July 2024 outage that took millions of Windows devices offline. The company managed to retain around 97% of customers the following quarter, and the anticipated exodus never came.
The tier for the more basic signature-era anti-virus is undeniably dominated everywhere by a single product: the built-in Windows Defender antivirus, detected on 66.3% of North American and 69.2% of European assets. It typically runs as the default base layer beneath, or instead of, a third-party tool. Because Defender co-exists with other software, these are not exclusive shares.
For a large share of the dataset this is what “protected” means, it’s the antivirus that came in the box, never joined by a more sophisticated EDR.

This problem with upgrading your endpoint protection isn’t just about what tool you are using, it’s about visibility. You cannot upgrade, or even grade, an endpoint if you cannot see it. The most exposed assets in this dataset are the ones that are drifting outside standard management: servers, unmanaged devices, and machines that never made it into the console.
Lansweeper’s role is to give IT and Security teams one continuously validated view of every asset that they can build on. See the whole estate, including the servers and unmanaged devices where the gaps concentrate. Know each asset’s real protection tier, whether it’s full EDR, basic AV, or none at all. Act to close the strength gap before an auditor, an insurer or an attacker finds it first
The numbers and statistics in this piece come from that foundation: data from millions of assets, across 30,000 organizations, deduplicated and normalized into real insights. That same view can help you find the gap in your organization, find the unprotected or insufficiently protected machines.
If your coverage number is already close to 100%, the next more useful question is how much of that coverage is at it’s strongest, and how much is relying on what came in the box.
Explore the full platform, free for 14 days.
No credit card required.