Every European endpoint protection tool reviewed
Bratislava, Slovakia
Founded 1992
Per seat per year, published for business tiers
Free 30-day trial
Best for: Any organisation that wants proven detection with a console a normal IT team can run
ESET, spol. s r.o. has been writing detection software in Bratislava since 1992, which makes it older than most of the American vendors it now competes with and older than the category as a marketing term.
The engine is the reason to take it seriously: it sits at or near the top of AV-Comparatives and AV-TEST year after year, with a consistently low false-positive rate, which matters more in practice than a headline detection percentage because false positives are what makes an IT team switch the product off.
What makes it the pick here rather than merely a good option is the combination of that engine with a product a normal team can actually operate.
The console is manageable without a security specialist, the agent is light enough that people do not notice it, business pricing is published rather than quoted, and there is a real EDR tier for organisations that grow into needing one. The limits are the ones that come with breadth: it is not the deepest threat-hunting platform on this list, and a large enterprise with its own security operations centre will find TEHTRIS or WithSecure aimed more precisely at them.
What ESET does well
- Consistently near the top of independent AV-Comparatives and AV-TEST results
- Low false-positive rate, which is what keeps it switched on
- Published business pricing rather than a quote
- Light agent and a console a general IT team can run
- Slovak company, EU processing, building detection since 1992
Where ESET falls short
- Not the deepest threat-hunting platform here
- EDR tier is priced separately from the base protection
- Aimed at broad usability rather than at a mature security team
Standout feature. Thirty years of engine, not thirty months: the detection has been tested publicly and independently for longer than most competitors have existed.
Bucharest, Romania
Founded 2001
Per seat per year, published
Free trial
Best for: Companies wanting top-tier detection with strong managed and MSP options
S.C. Bitdefender S.R.L. in Bucharest is the other European vendor that consistently tops independent testing, and on raw detection there is very little between it and ESET. Where it differs is the shape of the business around the product: a large managed detection and response offering, a deep MSP channel, and a habit of licensing its engine to other security vendors, which is why Bitdefender technology turns up inside products that do not carry its name.
For a company without security staff, the managed option is the genuinely interesting part, because it answers the question the rest of this category leaves open — who reads the alerts.
The trade-offs are worth knowing: the product range is wide enough to be confusing at first, some capabilities sit behind tiers that are not obvious from the pricing page, and the console has more in it than a small IT team will use. None of that touches the detection, which is excellent.
What Bitdefender does well
- Detection scores at the very top of independent testing
- Strong managed detection and response for companies without security staff
- Deep MSP channel and published per-seat pricing
- Romanian company, EU processing
Where Bitdefender falls short
- Wide product range that takes work to navigate
- Capabilities split across tiers in ways the pricing page does not make obvious
- Console offers more than a small team needs
Standout feature. Someone else reads the alerts: the managed option answers the question that sinks most endpoint detection projects.
Paris, France
Founded 2010
Enterprise pricing on request
Demo on request
Best for: European organisations with real security maturity and sovereignty requirements
TEHTRI-Security SAS in Paris built its platform for organisations where the sovereignty question is not a preference but a requirement — French public sector, defence-adjacent industry, critical infrastructure. It covers endpoints, servers, mobile and containers under one detection and response platform, with components qualified by ANSSI, the French national cybersecurity agency, and a stated position of not sending data outside France.
That focus explains both the appeal and the limits. For a European organisation that has to demonstrate where its security telemetry lives, this is a far shorter conversation than with any American vendor, and the platform is genuinely broad.
But it assumes you have people who can run a detection and response platform, pricing is quoted per engagement, and outside France the brand and the partner network are much thinner than ESET or Bitdefender. It is not a product to buy because it looked good in a comparison table.
What TEHTRIS does well
- Detection and response across endpoints, servers, mobile and containers
- ANSSI-qualified components and a clear French data position
- Built for organisations with sovereignty requirements rather than preferences
- French company, French processing
Where TEHTRIS falls short
- Assumes a security team that can run it
- Enterprise pricing on request
- Thin partner network outside France
Standout feature. Sovereignty as a specification: ANSSI qualification is an external check on the claim rather than a marketing line about it.
Montrouge, France
Founded 2020
Free and open source / paid plans for the threat feed
Free
Best for: Teams protecting internet-facing servers who want shared threat intelligence without a licence
CrowdSec SAS in Montrouge is the odd one in this category and belongs here anyway.
It is open source under MIT, it runs on servers rather than laptops, and it works by reading your logs, spotting attack behaviour, and blocking the addresses behind it — then sharing that signal with everyone else running CrowdSec, so an address hammering a server in Poland is blocked in Portugal before it arrives. Think of it as Fail2ban with a community behind it and a modern architecture.
It does not scan files, it does not protect laptops, and comparing it with ESET on malware detection is comparing two different jobs. What it does do is remove a whole class of noise from internet-facing infrastructure for nothing, with paid plans only for the enriched threat feed and enterprise features. The catch is the usual open-source one: you run it, you configure the scenarios, and the quality of what you get out depends on the attention you put in.
What CrowdSec does well
- Free and open source under MIT, with paid tiers only for the enriched feed
- Community threat intelligence: one attacker blocked everywhere at once
- Built for servers and internet-facing services
- French company, EU processing
Where CrowdSec falls short
- Not endpoint anti-malware; it does not protect laptops
- You run and tune it yourself
- Young company compared with the rest of this list
Standout feature. The network effect turned defensive: every participant blocking an attacker makes the block faster for everyone else.
Bochum, Germany
Founded 1985
Per seat per year, published
Free 30-day trial
Best for: German organisations that want detection built and processed entirely in Germany
G DATA CyberDefense AG has been in Bochum since 1985 and claims, with a reasonable case, to have shipped one of the first anti-virus products at all. Everything about the company is built around a German position: development in Germany, data processing in Germany, and a published no-backdoor guarantee alongside the German TeleTrusT "IT Security made in Germany" seal, which is an external commitment rather than a slogan.
For a German public body or a Mittelstand company with procurement rules that ask where software is written and where the telemetry goes, that combination is the whole argument, and it is a strong one.
Elsewhere the case is narrower: detection is good but not consistently at the ESET and Bitdefender level in independent testing, the interface is functional rather than modern, and the international partner network is smaller. Bought for the right reason it is an excellent fit; bought on a feature comparison it will look middling.
What G DATA does well
- Developed and processed entirely in Germany
- Published no-backdoor guarantee and TeleTrusT seal
- Independent since 1985, one of the oldest vendors in the field
- Published per-seat pricing and a 30-day trial
Where G DATA falls short
- Detection scores solid but below ESET and Bitdefender in recent testing
- Interface is functional rather than modern
- Smaller partner network outside German-speaking markets
Standout feature. A written no-backdoor guarantee: a commitment almost nobody else in this market is willing to put in writing.
Helsinki, Finland
Founded 1988
Per seat, quoted through partners
Trial on request
Best for: Mid-sized and larger European organisations buying through a partner
WithSecure Corporation in Helsinki is the business half of what used to be F-Secure, separated in 2022 so the consumer and corporate sides could go their own ways. It sells almost entirely through partners and managed service providers, with endpoint protection, EDR and co-monitored detection where WithSecure analysts watch alongside your team — which is a sensible middle ground between running detection yourself and handing it over completely.
The partner-led model is the thing to plan around. It means the quality of what you get depends substantially on which partner you buy through, pricing is quoted rather than published, and a small company buying direct is not really the target. For a mid-sized European organisation that already works with an IT partner, it is a strong and unusually mature option from a company that has been doing this since 1988.
What WithSecure does well
- Co-monitored detection: their analysts alongside your team
- Long track record, established 1988, Finnish company
- Mature partner and managed-service channel across Europe
- EU processing
Where WithSecure falls short
- Sold through partners, so your experience depends on which one
- Quoted pricing rather than published
- Not aimed at small companies buying direct
Standout feature. Co-monitoring rather than all-or-nothing: their analysts watch with you instead of instead of you.
Hanover, Germany
Founded 2007
Per seat per month, quoted
Free trial
Best for: Microsoft 365 tenants where the real risk arrives by email
Hornetsecurity GmbH in Hanover comes at endpoint security from the direction most compromises actually take: the inbox. The product set is built around Microsoft 365 — email filtering, advanced threat protection, backup for mailboxes and SharePoint, security awareness training and permission management — rather than around an agent on the laptop.
Listing it here needs the caveat stated plainly: it is not an endpoint anti-malware suite and will not replace ESET or Bitdefender on your machines.
It sits in front of them, and for many organisations it prevents more incidents than the endpoint agent ever will, because phishing and business email compromise do not arrive as files to be scanned. Pricing is quoted per seat through partners, and the whole proposition assumes you are on Microsoft 365, which makes it either a perfect fit or irrelevant.
What Hornetsecurity does well
- Aimed at where compromise actually starts, which is email
- Backup, awareness training and permission management alongside filtering
- German company, EU processing, ISO 27001
- Deep Microsoft 365 integration
Where Hornetsecurity falls short
- Not endpoint anti-malware; it complements rather than replaces it
- Only relevant if you run Microsoft 365
- Quoted pricing through partners
Standout feature. It guards the door the attackers use: for most organisations the inbox compromises more machines than the machines do.
Issy-les-Moulineaux, France
Enterprise pricing on request
Best for: French and EU public-sector buyers needing sovereignty guarantees
Stormshield Endpoint Security Evolution is built by a company that already belongs to this directory's most demanding audience: Stormshield is a wholly-owned subsidiary of Airbus Defence and Space Cyber Programmes, and its endpoint agent holds a CSPN qualification from ANSSI, the French national cybersecurity agency, plus a Producto Cualificado approval from Spain's CCN-LINCE.
Those are external checks TEHTRIS's ANSSI-qualified components share but that ESET, Bitdefender and G DATA do not publish, which makes Stormshield the second sovereignty-grade option in this category, aimed at the same French public-sector and critical-infrastructure buyers TEHTRIS serves.
Where SES Evolution differs from TEHTRIS is emphasis: signatureless behavioural detection, device control and an agent architecture hardened against direct attacks on itself, rather than a platform reaching into mobile and containers.
Stormshield's own privacy notice says data is processed mostly within the EEA, with standard contractual clauses covering the rest. Pricing is quoted rather than published, there is no trial listed, and — like TEHTRIS — the partner network thins out fast outside France; a buyer without a sovereignty requirement will find ESET or Bitdefender easier to simply buy and run.
What Stormshield does well
- ANSSI CSPN qualification and CCN-LINCE (Spain) approval
- Signatureless behavioural detection built to survive attacks on the agent itself
- Backed by Airbus Defence and Space
- Device control included to reduce the attack surface
- Data processing mostly within the EEA
Where Stormshield falls short
- Quoted pricing only, no published price list
- No trial listed
- Thin partner network outside France, like TEHTRIS
Standout feature. A second sovereignty-grade option next to TEHTRIS: ANSSI's CSPN and Spain's CCN-LINCE have both signed off on the same agent.
Munich, Germany
Per endpoint, quoted
Free trial available
Best for: German mid-market wanting device control and antivirus in one console
DriveLock SE in Munich sells a broader platform than a pure antivirus vendor: device control, application whitelisting, vulnerability management, BitLocker and disk encryption management, and Microsoft Defender orchestration sit alongside its own protection engine in one console. That breadth is the pitch for a company that currently runs device control, encryption management and antivirus as three separate products from three separate vendors, each with its own console and its own renewal date.
The company carries ISO 27001 and ISO 9001 certification and the TeleTrusT "IT Security made in Germany" and "made in EU" seals — the same category of external commitment G DATA makes with its no-backdoor guarantee, applied to a wider product.
Its cloud platform runs on Microsoft Azure with data centres in Europe, and a free trial is available, though standard pricing is quoted rather than published. The trade-off is configuration: application whitelisting and device control policies take real setup work, and a company that only wants antivirus is buying more platform than it needs.
What DriveLock does well
- Device control, application whitelisting, encryption and antivirus in one console
- ISO 27001 and ISO 9001 certified
- TeleTrusT "made in Germany" and "made in EU" seals
- Free trial available
- Azure hosting in European data centres
Where DriveLock falls short
- Quoted pricing, not published
- Application and device control policies need real configuration work
- More platform than a buyer who wants only antivirus needs
Standout feature. One console for device control, encryption and antivirus: DriveLock replaces three separate vendor relationships with one German one.
Vienna, Austria
Founded 1986
Per seat, quoted through sales
Trial available on request
Best for: Austrian and DACH organisations wanting a long-established AV engine
IKARUS Security Software GmbH has been writing detection in Austria since 1986, with its first product, IKARUS virus.utilities, shipping in 1988 — a longer unbroken history than every other vendor in this category except G DATA. IKARUS anti.virus, the cloud-managed business product, blocks malicious downloads, isolates threats automatically and denies external connections from infected files, managed through a portal that handles device management, licensing and configuration profiles.
The independent signal worth weighing is OPSWAT Platinum certification and a Virus Bulletin VB100 award, plus the Austrian "Cyber Trust Austria" label — external checks on a vendor that does not publish AV-Comparatives or AV-TEST results as consistently as ESET or Bitdefender do.
Pricing is quoted through sales rather than published, and a trial has to be requested by phone or email rather than started from the site. For an Austrian or wider DACH buyer who wants a genuinely independent, long-running AV vendor rather than a reseller of someone else's engine, that is a reasonable trade.
What IKARUS Security Software does well
- Detecting malware from Austria since 1986
- OPSWAT Platinum certified and Virus Bulletin VB100 award
- Cyber Trust Austria label
- Cloud-managed portal for devices, licensing and configuration
- Also offers mail security and mobile device management
Where IKARUS Security Software falls short
- No published pricing; quoted through sales
- Trial requested by phone or email, not self-serve
- Independent test results published less consistently than ESET or Bitdefender
Standout feature. Detection work traced back to 1986: IKARUS is the second-longest-running vendor in this category, behind only G DATA.
Copenhagen, Denmark
Founded 2014
Per endpoint, quoted
Free trial available
Best for: Teams wanting endpoint, patch and DNS security in one platform
Heimdal Security A/S in Copenhagen sells one of the widest platforms in this category: next-generation antivirus, endpoint detection and response, patch management, DNS security, ransomware encryption protection, privileged access management and managed XDR all sit under one Heimdal console rather than across separate tools. For a team that currently patches with one product, filters DNS with another and runs antivirus with a third, consolidating onto Heimdal removes two vendor relationships rather than adding one.
The point to weigh before buying is where the data actually sits.
Heimdal's own privacy policy lets a customer choose the storage region per product, and the European options are Microsoft Azure in the Netherlands or Amazon Web Services in Germany — but the same choice list includes the UK, the United States and the UAE.
That is a materially weaker default than ESET's or Bitdefender's straightforward EU processing, and a buyer choosing Heimdal for European jurisdiction reasons has to actively select the European region rather than assume it. A free trial is available; standard pricing is quoted rather than published.
What Heimdal does well
- Antivirus, EDR, patch management, DNS security and PAM in one platform
- Free trial available
- Can choose an EU storage region (Netherlands or Germany)
- Managed XDR option for teams without a security operations centre
- Danish company, founded in 2014
Where Heimdal falls short
- EU hosting is a choice, not the default — UK, US and UAE regions are offered too
- Quoted pricing, not published
- Broad platform means less depth than a specialist in any one module
Standout feature. A wide platform with a catch: Heimdal is Danish, but its data-region picker also offers the US and the UAE, so EU residency has to be chosen deliberately.
Warsaw, Poland
Founded 2004
Enterprise pricing on request
Best for: Polish organisations wanting a domestic alternative to Kaspersky
Arcabit Sp. z o.o. has been building antivirus software in Warsaw since 2004, and it is the only Polish vendor in this category. Its business range covers Endpoint Security for larger networks, a lighter Small Office Security tier, server protection, and a RoundKick EDR module for detection and response — a full enough spread that Arcabit pitches itself at large corporate and business networks, not only small offices.
The independent check on the detection engine is Virus Bulletin's VB100 award, the same signal ESET, Bitdefender and IKARUS carry. What Arcabit does not publish is pricing or a self-serve trial; both routes go through a contact form, and its presence outside Poland is thin. For a Polish organisation that wants to replace Kaspersky specifically, or simply prefers a domestic vendor with central management for many installations, Arcabit is a plausible and under-documented choice rather than a well-marketed one.
What Arcabit does well
- Building antivirus in Warsaw since 2004
- Virus Bulletin VB100 certified
- RoundKick EDR module for detection and response
- Central management console for large networks
- Polish company and support
Where Arcabit falls short
- No published pricing or self-serve trial
- Thin presence outside Poland
- Smaller company with less independent test coverage than ESET or Bitdefender
Standout feature. The only Polish vendor in this category: a direct domestic alternative for organisations moving off Kaspersky.
London, United Kingdom
Founded 2007
Enterprise pricing on request
Best for: Protecting BYOD, VDI and unmanaged endpoints from keylogging
SentryBay Limited, in London since 2007, solves a different problem than every other tool in this category: its Armored Client does not scan for malware or hunt for behavioural anomalies, it stops keylogging, screen capture and DLL injection on endpoints nobody manages — a contractor's laptop, a BYOD phone, or a VDI or DaaS session where installing a full EDR agent is not possible or not allowed.
Its own positioning is blunt about the difference: while EDR and XDR attempt to detect the threat, Armored Client is built to just stop the data loss.
That makes it a companion to the rest of this list rather than competition for ESET or Bitdefender: a company still needs anti-malware on the machines it controls, and Armored Client covers the sessions and devices it does not.
SentryBay Limited is registered in London and majority-owned by its own UK holding company, so the British jurisdiction question has a clean answer here — it sits outside the EEA under the UK's adequacy decision. Pricing and trial availability are not published; a demo has to be requested.
What SentryBay does well
- Protects unmanaged, BYOD and VDI endpoints that cannot run a full agent
- Blocks keylogging, screen capture and DLL injection specifically
- Lightweight, targeted only at chosen corporate applications
- British company, transparently and independently owned
- Works alongside existing EDR rather than replacing it
Where SentryBay falls short
- Not anti-malware; does not replace ESET, Bitdefender or the others here
- United Kingdom, outside the EEA, dependent on the adequacy decision
- No published pricing or trial
Standout feature. It protects the sessions nobody can put an agent on: SentryBay is the only tool here built for BYOD and VDI rather than managed machines.