Endpoint Security Foundation in 2026: Why Antivirus Alone No Longer Satisfies CERT-In

By Deepika Nair · 5 May 2026

The Endpoint Threat Landscape in 2026

Endpoints — laptops, desktops, mobile devices, and servers — are the entry point for over 70% of enterprise breaches according to the Verizon 2024 Data Breach Investigations Report. The threat actor toolkit has evolved far beyond what traditional signature-based antivirus can detect: fileless malware that executes entirely in memory, living-off-the-land (LotL) attacks using legitimate system tools (PowerShell, WMI, msiexec), and AI-generated polymorphic malware that changes its signature with every execution. CERT-In Directions 2022 require organisations to deploy and maintain endpoint security controls. ISO/IEC 27001:2022 Annex A.8.7 requires protection against malware using detection, prevention, and recovery controls. "We have antivirus" is no longer an acceptable answer.

Endpoint Security Maturity Model — 2026

LevelCapabilityCompliance Verdict
1 — BasicSignature-based AV only, no centralised managementFails CERT-In, fails ISO 27001
2 — ManagedAV + centrally managed, patching enforced, encryptionPartial compliance
3 — EDREDR with behavioural detection, threat hunting, SIEM integrationMeets CERT-In standard
4 — XDRExtended Detection and Response — endpoint + network + cloud correlatedExceeds — audit-ready

EDR: The 2026 Minimum Standard

Endpoint Detection and Response (EDR) platforms — CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint — provide: behavioural analysis to detect anomalous activity (not just known malware signatures), process tree visibility to trace the full attack chain from initial access to lateral movement, automated response capabilities (isolate endpoint, kill process, quarantine file), and a forensic evidence trail for incident investigation. For CERT-In compliance, EDR provides the detection and response capability the Directions mandate. For ISO 27001, it provides the malware protection evidence auditors require.

Additional Endpoint Foundation Controls

  • Full-Disk Encryption: BitLocker (Windows) or FileVault (macOS) on all laptops and mobile workstations. DPDP Act requires protection of personal data on portable devices. Loss of an unencrypted laptop is a notifiable data breach.
  • Mobile Device Management (MDM): All corporate mobile devices managed via MDM (Microsoft Intune, Jamf). Policy enforcement: PIN/biometric lock, remote wipe capability, prevent data copy to personal apps.
  • Application Whitelisting: Allow only approved applications to execute. AppLocker (Windows) or application control policies prevent unauthorised software — including malware — from running.
  • USB Control Policy: Block or control USB storage devices. Data exfiltration via USB is a persistent insider threat vector. Policy should allow charging only for untrusted USB devices.

Endpoint Security Assessed in IGaaS

InfraVeritas 360 assesses your endpoint security maturity — EDR coverage, encryption deployment, MDM enrolment, and USB control policy — mapping gaps to CERT-In and ISO 27001 requirements.

Assess Your Endpoint Security →