Antivirus is not enough. And not the problem either.
· 4 min read
Ask a small business whether their IT security is under control, and the answer is often: “Yes, we have antivirus.” It is a good answer, as far as it goes. The problem is that it does not go very far, and that it often overshadows the things that matter more.
What antivirus actually does
An antivirus program monitors files and programs and intervenes when something known to be harmful tries to run. That is an important function, and it is already built into Windows: Microsoft Defender ships for free and handles the job well for most people.
But notice what the function presupposes: that the attack consists of a harmful file landing on the computer and being run. That is one kind of attack. It is just rarely the kind that hits small businesses.
How the break-ins actually happen
Looking at what actually goes wrong at small businesses, the way in rarely goes through a virus file that fools the antivirus. It goes through things no antivirus looks at:
- A remote access left open to the internet, with a password that could be guessed.
- An employee called or emailed by a “supporter” who let them in personally.
- A password reused from a service that was leaked three years ago.
- A computer not updated in eight months, with publicly known holes.
- A firewall switched off during troubleshooting that never came back on.
None of the five is a “virus”. The antivirus program can be as good as it likes; it is never asked to deal with them. It is like having a guard dog at the front door while the back door stands ajar.
The false security is the real problem
The most dangerous thing about “we have antivirus” is not that it is wrong. It is that it feels like a complete answer. The box is ticked, security is “handled”, and then nobody looks at the back doors.
Attackers exploit that feeling. They do not need to beat an up-to-date antivirus; they go around it and use the doors that already stand open. It demands less of them and is harder for you to detect, precisely because there is no harmful file to catch.
What an honest answer requires
For “we have it under control” to be true, it needs to cover a bit more than antivirus. Not much more; it is still about basics Windows can handle by itself:
Protection switched on, for the whole computer, not just parts of it. Updates running automatically. Backup running and tested once in a while. Remote access closed unless actively used. And passwords that are long, unique and preferably backed by two-factor login where available.
Antivirus belongs on the list, but it is one item out of six, not the whole list.
Our role in this
Argos, our upcoming product, is not an antivirus, and we say so clearly everywhere we can. Argos is the inspection: the tool that watches whether the basics, including your antivirus, are actually switched on and running. Because that is usually where things go wrong. Not in the advanced, but in the basics nobody noticed were off.