---
title: Why Antivirus Software May Not Be Enough to Protect Critical Business Data
description: With the increasingly sophisticated cyber threats affecting businesses, antivirus software is becoming less and less effective. According to a 2017 Ponemon study, 77% of successful malware-based attacks used fileless techniques that could not be detected by traditional antivirus software. In this article, we will discuss some of these new-age cybersecurity threats while providing advice on how to defend against them.
---

[Skip to content](https://blog.oitc.ca/blog/why-antivirus-software-may-not-be-enough-to-protect-critical-business-data#main-content)

![Outsource IT Computing](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=1408&height=302&name=OITC%20Logo-1.png)Homepage

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

Blog

# Why Antivirus Software May Not Be Enough to Protect Critical Business Data

![Nathan Zych](https://7528315.fs1.hubspotusercontent-na1.net/hub/7528315/hubfs/raw_assets/public/mV0_d-cms-elevate-theme_hubspot/elevate/images/avatar-placeholder.jpg?width=48&height=48&name=avatar-placeholder.jpg)

 Nathan Zych

July 17, 2020

## **Why Antivirus Software May Not Be Enough to Protect Critical Business Data**

With the increasingly sophisticated cyber threats affecting businesses, antivirus software is becoming less and less effective. According to a 2017 Ponemon [study](https://www.businesswire.com/news/home/20171115005988/en/Ponemon-Institute-Study-Reveals-Organizations-Lose-5), 77% of successful malware-based attacks used fileless techniques that could not be detected by traditional antivirus software. Some of these modern threats can easily evade antivirus software, and in many cases are personalized for a particular organization.

Antivirus technology protects against malware by scanning files and comparing them against a database of known malware. If a file matches either a known malware signature or it does something that the heuristic engine considers suspicious, the antivirus software will quarantine the file for later inspection.

While antivirus software can work well against malicious files downloaded from the Internet, it is not completely effective against the wide variety of threats that target businesses today. Additionally, many cybersecurity threats involve tricking a human into doing something which compromises security, commonly referred to as social engineering. In most cases, antivirus software cannot prevent these kinds of threat.

In this article, we will discuss some of these new-age cybersecurity threats while providing advice on how to defend against them.

### **Email Threats**

Email is the most used channel for [cyber-attacks](https://www.oitc.ca/blog/the-most-dangerous-email-threats-and-how-to-stop-them/). Everything from phishing attacks to blackmail is carried out over email. In fact, [90%](https://www.csoonline.com/article/3153707/top-cybersecurity-facts-figures-and-statistics.html) of malware is delivered via email.

As one of the most effective cyberthreats, [email phishing attacks](https://www.oitc.ca/simulated-phishing-tests/) are hard to stop with traditional antivirus software. These messages trick users into entering credentials on illegitimate pages disguised to look like a vendor’s actual website. The best defense for this is the use of email gateways which employ techniques such as AI classification and URL rewriting to prevent phishing messages from ending up in inboxes.

With spear phishing, email gateways are less effective, since historical data is more useful in determining whether a message is malicious. API-based email defense which detects, and blocks targeted malicious messages based on historical data, is the best choice in this case.

Another common email-based attack is [business email compromise](https://www.oitc.ca/blog/how-to-protect-your-organization-from-business-email-compromise-attacks/), where an attacker impersonates a coworker or boss. These attacks cost organizations [$1.77 billion](https://www.zdnet.com/article/fbi-bec-scams-accounted-for-half-of-the-cyber-crime-losses-in-2019/) last year alone, according to the FBI. Similar to spear phishing, API-based email defense which uses historical trends is the best way to protect users from these dangerous threats.

### **Fileless Malware**

Fileless malware has increased in popularity over the last few years, with documented cases of attacks on enterprises around the world, according to a [2017](https://securelist.com/fileless-attacks-against-enterprise-networks/77403/) Kaspersky report. Most successful malware attacks today use fileless techniques. When malware injects its code into existing processes on the computer or runs using an interpreter like PowerShell, this is what is referred to as fileless malware. Conventional antivirus software which scans files on a computer’s hard drive will not be able to guard against this threat since there is no file to be deleted.

Endpoint detection and response (EDR) solutions are well-suited for detecting fileless malware and similar cyberattacks. By constantly monitoring the behavior of endpoint devices like laptops and mobile devices, EDR solutions correlate security events to potential threats much more effectively than traditional antivirus solutions.

### **Never-Before-Seen Malware**

Occasionally, antivirus software will fail to stop even relatively unsophisticated malware-based cyberattacks. This is especially true if the malware signature has not yet entered the antivirus vendor’s threat database. While most antivirus software utilizes heuristic technology to detect never-before-seen malware threats, this technology is approximate and many times inaccurate. Therefore, if an attacker uses a new type of malware, antivirus products will have a hard time detecting the threat.

As with fileless malware, EDR solutions are the best choice. An EDR solution has the capability to detect unusual behavior across an entire fleet of endpoint devices with much better accuracy than antivirus, owing to its richer data sources and more advanced threat intelligence.

### **Antivirus Itself Can Be Compromised**

Even though antivirus software is not completely effective at stopping newer cybersecurity threats, some companies use it as an additional layer of security. While this is sometimes a good idea, antivirus software can increase the attack surface of a device, potentially providing a foothold for attackers to further compromise business security.

Respected Google security researcher Tavis Ormandy [discovered](https://www.securityweek.com/vulnerability-prompts-avast-disable-emulator-used-antivirus) that Avast contained vulnerabilities that could be used by attackers to gain access to secure computers. He reported that when old versions of the Avast antivirus product scanned specially-crafted files, the software could be tricked into running attacker-selected code. Not only did the antivirus software fail to stop a malware attack, it actually facilitated one.

While these kinds of vulnerabilities are rare and would likely only affect high-profile enterprises and governments, they are worth considering for organizations of all kinds. Even security software can be used to compromise an endpoint device if the software contains vulnerabilities.

### **Mitigate Threats with EDR**

Cybersecurity attacks come in all shapes and sizes. Email threats, fileless malware, and brand new malware, are all attacks that antivirus software cannot stop. In some cases, the antivirus software itself is a major security liability. Endpoint detection and response (EDR) solutions are the best way to protect against many of these new cybersecurity threats.

With years of experience helping our clients protect their businesses against an evolving threat landscape, Outsource IT can strengthen your organization’s cybersecurity beyond antivirus software. Contact your Outsource IT account manager to learn more about our [business IT security](https://www.oitc.ca/services/business-it-security/) services.

[![Worry Free Business Cybersecurity](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/ancp-B.png?width=900&name=ancp-B.png)](https://www.oitc.ca/contact/)

[Click here to contact Outsource IT](https://www.oitc.ca/contact/)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.oitc.ca%2Fblog%2Fwhy-antivirus-software-may-not-be-enough-to-protect-critical-business-data><https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.oitc.ca%2Fblog%2Fwhy-antivirus-software-may-not-be-enough-to-protect-critical-business-data><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.oitc.ca%2Fblog%2Fwhy-antivirus-software-may-not-be-enough-to-protect-critical-business-data><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fblog.oitc.ca%2Fblog%2Fwhy-antivirus-software-may-not-be-enough-to-protect-critical-business-data>[mailto:https%3A%2F%2Fblog.oitc.ca%2Fblog%2Fwhy-antivirus-software-may-not-be-enough-to-protect-critical-business-data](mailto:https%3A%2F%2Fblog.oitc.ca%2Fblog%2Fwhy-antivirus-software-may-not-be-enough-to-protect-critical-business-data)

## Keep reading

### [Managed IT vs In-House IT: Why It’s Not Always an Either-Or Decision](https://blog.oitc.ca/managed-it-vs-in-house-it-why-its-not-always-an-either-or-decision)

### [Blog 10 Signs You’ve Outgrown Your Current IT Provider](https://blog.oitc.ca/10-signs-youve-outgrown-your-current-it-provider)

[![OITC Logo-1](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=300&height=64&name=OITC%20Logo-1.png "OITC Logo-1")](https://oitc.ca)

<https://www.linkedin.com/organization/1598823/><https://www.facebook.com/outsourceitcomputing/><https://x.com/oitc_ca>

---

[Privacy Policy](https://oitc.ca/privacy-policy/) · © 2025. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nathan Zych",
    "url" : "https://blog.oitc.ca/author/nathan-zych"
  },
  "dateModified" : "2025-07-10T22:20:09.105Z",
  "datePublished" : "2020-07-17T19:19:37.000Z",
  "headline" : "Why Antivirus Software May Not Be Enough to Protect Critical Business Data",
  "mainEntityOfPage" : {
    "@id" : "https://blog.oitc.ca/blog/why-antivirus-software-may-not-be-enough-to-protect-critical-business-data",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.oitc.ca/hubfs/OITC%20Logo-1.png"
    }
  }
}
```