Antivirus can spot and block many harmful files and known threats. It still belongs on business computers.
It cannot protect every part of the business. A criminal may steal a password through a fake login page, take over an email account or convince a staff member to change bank details without installing a virus.
Small businesses need protection around people, accounts, devices and recovery, not only files.
Attacks do not always use a virus
Fake emails and login pages
A phishing email may look like a message from Microsoft, a bank, courier, supplier or colleague. It asks the reader to open a file, follow a link or sign in.
If someone enters a password on a fake page, there may be no harmful file for antivirus to block. The criminal can use the real username and password from another device.
Stolen or reused passwords
A password exposed through another website can put business email or cloud services at risk when staff reuse it.
Antivirus on an office computer cannot stop someone elsewhere signing in with valid details. Multi-factor authentication, unique passwords and sign-in monitoring help with that risk.
Business email takeover
A criminal who gains access to a mailbox may monitor real conversations and wait for an invoice or payment request. They can then send a message from the genuine account or change bank details in an existing exchange.
Because the message comes from a real mailbox, it can be difficult for staff and filters to recognise. A separate payment verification process is essential.
Unsafe cloud access
Email, accounting, file sharing, bookings and customer systems are often reached through a web browser. Their security depends on account settings, access and staff behaviour as well as the protection installed on a computer.
Build protection in layers
Each control has a different job. If a dangerous email reaches a staff member, training may help them report it. If they enter a password, multi-factor authentication may stop the sign-in. If an account is accessed, monitoring may detect an unusual change. If data is deleted or damaged, a tested backup may support recovery.
No layer works perfectly. Together they reduce the chance that one mistake stops the business.
What to put in place
A practical small business setup should include:
- Supported device protection on business computers.
- Multi-factor authentication for email, accounting and other important systems.
- Unique passwords stored in a business password manager.
- Email filtering for dangerous links, attachments and known scams.
- Current security updates for computers, phones and apps.
- Tested backups that cover the systems the business needs to recover.
- Clear access rules for staff, contractors and former employees.
- Short training based on scams staff may see at work.
- Monitoring and a clear way to report a problem.
- A payment verification process that does not rely on email alone.
The exact products depend on the way your business works. The controls need an owner and regular maintenance after they are installed.
Start with the likely business impact
A compromised inbox can lead to changed invoices and exposed customer messages. A damaged laptop can stop work. An untested backup can turn a small mistake into a long recovery.
Ask what the business would do if someone clicked a fake link, lost a phone or could not open important files. The answers show which controls and recovery steps need attention.
Antivirus is a useful start. It is not the whole security plan.
Antivirus is only one part of the review. Book a business security controls consultation to examine the email, account and recovery controls it cannot cover, then prioritise the gaps that could stop work.