Endpoint Security

What Is Next-Generation Antivirus (NGAV)?

Next-generation antivirus uses artificial intelligence, machine learning, and behavioural analysis to detect threats that evade traditional signature-based antivirus. NGAV is now the standard for business endpoint protection — replacing tools that only recognise known, catalogued malware.

Overview

Next-generation antivirus uses machine learning, behavioural analysis, and cloud threat intelligence to detect threats that traditional signature-based tools miss. Microsoft Defender for Business — included in M365 Business Premium — is an NGAV product that AMVIA deploys and manages for UK SMEs. NGAV requires configuration beyond defaults to deliver its full protective value.

Learn about managed endpoint security

What is next-generation antivirus?

NGAV is endpoint software that detects malware by behaviour and machine-learning analysis rather than by matching a file against a database of known signatures. That shift matters because attackers modify malware constantly — even a tiny change produces a new file hash that no signature will recognise.

Traditional antivirus can only block threats it has already catalogued. NGAV closes that gap, which is why it sits at the core of managed cybersecurity for any UK business taking its security posture seriously. According to the Cyber Security Breaches Survey 2025, "43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and 85% of those breaches involved phishing (DSIT 2025)" — and many phishing payloads are crafted specifically to evade signature detection.

How does NGAV differ from traditional antivirus?

The difference is not incremental. Traditional antivirus is reactive — it blocks what has already been seen and catalogued. NGAV is predictive — it classifies and stops threats it has never encountered before, using machine learning, real-time behavioural monitoring, and shared cloud intelligence. Here is how the two approaches compare across the criteria that actually decide whether an attack gets through.

CapabilityTraditional antivirusNext-generation antivirus (NGAV)
Detection methodKnown malware signaturesMachine learning + behaviour
Novel / zero-day malwareMisses until cataloguedDetects on first encounter
Fileless / in-memory attacksNot detectedDetected via memory + behaviour
Ransomware behaviourLimitedBlocks rapid-encryption patterns
Threat-intelligence updatesScheduled signature pushesCloud updates within minutes
Response capabilityBlock fileBlock, isolate, terminate
  • Machine learning detection classifies an unseen file as likely malicious from its code structure, imported functions, entropy, and packing — protecting endpoints before any signature exists.
  • Behavioural analysis watches running processes and flags malware-like activity: rapid file encryption, LSASS credential access, or unexpected child processes.
  • Cloud threat intelligence aggregates data from millions of endpoints, so a threat seen anywhere becomes detectable everywhere within minutes.

Microsoft details these layers in its endpoint security documentation.

How does NGAV stop fileless attacks?

Fileless malware never writes a file to disk — it runs entirely in memory using legitimate system tools like PowerShell, WMI, and mshta.exe. Signature scanning has nothing to match, so traditional antivirus is blind to it. NGAV catches these "living-off-the-land" attacks by analysing behaviour instead of files.

When PowerShell downloads and executes a payload in memory, or WMI is abused to establish persistence, NGAV behavioural detection identifies the anomalous usage pattern and blocks the activity. The NCSC warns that attackers increasingly favour these techniques precisely because they evade legacy defences and are harder to investigate forensically.

How do NGAV and EDR relate?

NGAV and Endpoint Detection and Response (EDR) are related but distinct. NGAV is prevention — detecting and blocking threats before or early in execution. EDR adds a forensic and response layer: detailed telemetry of all endpoint activity, post-incident investigation, and response actions like device isolation and file quarantine.

Modern products combine both in one agent. Microsoft Defender for Business — the NGAV AMVIA deploys — provides machine-learning detection, behavioural blocking, and cloud intelligence alongside EDR telemetry and automated investigation. For deeper coverage, see how EDR extends endpoint protection and how AMVIA delivers managed detection and response.

Why do UK SMEs need NGAV?

UK SMEs need NGAV because the threats most likely to hit them — phishing payloads and ransomware — are engineered to slip past signature-based tools. Defence that only recognises known malware leaves a permanent blind spot, and the cost of a single breach getting through is steep.

The average cost of a data breach for UK organisations was "£3.58 million in 2024 (IBM 2024)". Worse, only "14% of UK businesses have a formal incident response plan (DSIT 2025)" — meaning most have no structured way to handle what slips past automated defences. NGAV reduces how much gets through; managed monitoring handles what does.

How is NGAV deployed and configured?

NGAV only delivers full value when it is configured deliberately. Default installations — including Defender for Business — leave protective features switched off. Getting it right means turning protections on, not just installing the agent.

  • Attack surface reduction rules set to block mode, not audit-only.
  • Controlled folder access configured to shield critical directories from ransomware encryption.
  • Cloud-delivered protection enabled for real-time intelligence updates.
  • Exclusions reviewed carefully — each overly broad exclusion creates a detection blind spot.

AMVIA reviews exclusions during onboarding and works with application vendors to avoid broad carve-outs wherever possible. Microsoft's own security guidance reinforces that hardening configuration is what separates real protection from a default install.

How much does NGAV cost for UK SMEs?

For UK SMEs on Microsoft 365 Business Premium, Defender for Business is included at no additional endpoint-security cost — one of the most accessible enterprise-grade NGAV products available. Business Basic and Standard tiers do not include it and would require an upgrade or standalone licensing.

Microsoft 365 list prices (ex VAT, annual) are Business Basic £4.60, Business Standard £9.60, and Business Premium £16.90 per user per month, per Microsoft UK. Third-party NGAV products such as "SentinelOne, CrowdStrike Falcon, and Sophos Intercept X" are typically priced "between £3 and £8 per endpoint per month" depending on tier and volume. For most SMEs already on Business Premium, Defender for Business provides comparable protection without extra licensing — but AMVIA assesses each client's requirements before recommending a path.

Why is NGAV alone not enough?

No NGAV product detects 100% of threats. Sophisticated attackers test their techniques against major security products before launching, so novel methods will eventually evade automated detection. NGAV reduces the volume that gets through — it does not eliminate it.

This is why AMVIA pairs NGAV deployment with 24/7 security monitoring and response. Alerts from Defender for Business are surfaced through AmviaIQ, investigated by AMVIA's security team, and acted on without waiting for you to raise a ticket. Monthly reports give visibility of every detection across your managed device estate, and regular configuration reviews keep protection current. This is the difference between a tool and a managed antivirus service: unmanaged NGAV generates alerts that may never be acted on; managed NGAV turns them into resolved incidents. Contact AMVIA on 0333 733 8050 to discuss NGAV protection for your business.

Key Points

What UK businesses need to know about next-generation antivirus.

Why Traditional AV Is Insufficient

Attackers routinely modify malware to evade signature detection. Even small changes produce a different hash — no signature match, no detection.

Behavioural Detection

NGAV monitors process activity, memory usage, and system calls — detecting malicious behaviour regardless of the specific malware variant involved.

Fileless Attack Protection

Fileless malware runs in memory using legitimate tools like PowerShell. Signature scanning cannot detect it — behavioural analysis can.

Cloud Threat Intelligence

NGAV tools connect to cloud threat intelligence platforms — when a new threat is identified anywhere, detection updates across all connected endpoints immediately.

NGAV Implementation Checklist

NGAV deployed on all managed endpoints — laptops, desktops, and servers

Cloud-delivered protection enabled — not relying solely on local detection

Behavioural blocking and containment enabled

Attack surface reduction rules configured — blocking common delivery techniques

Controlled folder access enabled to protect against ransomware

NGAV detections monitored and investigated — not just logged

Frequently Asked Questions

Upgrade to Next-Generation Endpoint Protection

AMVIA deploys and manages NGAV for UK businesses — providing behavioural threat detection, attack surface reduction, and managed alert response across your entire endpoint estate.