Windows already comes with antivirus built in. Every business owner has asked the same question at some point: why pay for anything else? The honest answer starts with the labs that actually test antivirus software, with no ties to any vendor.

In April 2026, AV-TEST — one of the industry's most respected independent institutes — tested the business version of the antivirus that ships with Windows, now called Microsoft Defender, and gave it a perfect score: 18 out of 18 points, full marks in protection, performance and usability. Two months later, in June 2026, the version that comes free on every ordinary computer — the consumer edition, at no extra cost — scored the same on protection: 6 out of 6. The only gap between the two showed up in performance.

That changes the question worth asking. If the built-in protection detects just as well as any paid antivirus, the money a company would spend switching products wouldn't fix the problem it actually has. And this is where most of the debate on the topic goes wrong: it compares detection rates, when detection rates stopped being where the real difference lives.

The built-in antivirus detects well — with one caveat

AV-Comparatives, another independent lab that has tested antivirus software since 1999, published an analysis dedicated to this exact question: whether the antivirus that ships with Windows is enough. The conclusion isn't "it doesn't protect." It's more specific: part of Microsoft Defender's detection power depends on being connected to Microsoft's cloud. Without that connection, the measured detection rate dropped to 89.2%, against 98.6% for other products evaluated in the same offline scenario — a design choice, not a flaw, but one that matters for any laptop that spends much of its day outside the company network.

The same analysis notes that vulnerabilities were found in Microsoft Defender itself in May 2026 — true of any antivirus, none is immune to that — and recommends treating protection as layers that add up, not as a single product that solves everything on its own. Neither caveat is a reason to switch antivirus software. Both are reasons to ask who, inside the company, makes sure the computer's protection stays connected, updated and running — because none of that happens by itself.

Neither lab recommends dropping the antivirus that ships with Windows. Both, in fact, rank it among the best-reviewed products on the market. The problem for a company with 15, 40 or 100 computers was never the product's detection score — it was making sure that score holds for every single computer, all the time, and that someone notices when one of them falls out of line.

Why the usual approach doesn't hold up

Why the usual approach doesn't hold up

The usual approach, in a company that never contracted anything beyond what already comes installed, looks like this: every computer arrives from the store with Microsoft Defender active, someone assumes "it's already protected," and nobody looks at it again until the day a file won't open anymore.

There's no single dashboard showing all 15, 40 or 100 computers on one screen. Nobody checks, every month, whether protection is still active on each machine — because a user can disable it by accident, a driver can conflict with it, an update can stall halfway through. Nobody reads what the antivirus already blocked on its own: most of the time, a malicious file gets stopped and the notification flashes on the employee's screen for two seconds, then gets dismissed without anyone understanding what just happened.

CERT.br, the center that handles security incidents in Brazil, released a ransomware resilience guide in 2025 aimed specifically at small and medium-sized businesses. The document organizes an attack response around four pillars — prevention, detection, response and recovery — and the core point holds across all of them: a company is only truly protected when someone monitors the environment and knows how to act when something shows up. Having the antivirus installed only covers the first of those four pillars. The other three depend on people paying attention, not on software running by itself.

That's the most common blind spot: the company has the right tool and no process around it. An antivirus scoring 6 out of 6, silently disabled without anyone noticing, protects exactly nothing.

What has to be in place

Managed antivirus protection comes down to verifiable mechanisms, not promises.

Confirmation that protection is active on every computer in the company. Not the assumption that "it's already installed," but a periodic check, machine by machine, including the laptops that spend most of their time outside the office.

Protection updates verified, not just assumed. Someone confirms the antivirus definitions are current on every machine, because an update that silently stalls is common, and nobody at a small company tends to notice on their own.

Alerts that reach a person, not just the employee's screen. When the antivirus blocks or quarantines something, the notice needs to reach someone who can tell whether that's routine or the start of a bigger problem.

An inventory of who's protected and who isn't. A living list of which computers have active protection, which version, and which ones fell behind after a hardware swap or a reinstall.

Checking protection outside the company network. A laptop spending the week working from home or visiting a client depends on the cloud connection to detect as well as a computer inside the office does; someone needs to know when that connection drops.

An agreed response for whatever shows up after business hours. A block at two in the morning can't wait until Monday for someone to look at it; there needs to be a defined path for who receives the alert and what to do with it.

This is how Skills IT works: it checks whether antivirus protection is active on every one of a client's computers, tracks whether definitions are up to date, and puts someone between the alert the antivirus already raised and the decision about what to do with it.

The payoff for whoever decides

The payoff for whoever decides

The payoff of having someone look after this doesn't show up in a detection score — it shows up day to day. The owner stops being the person who finds out, through word of mouth, that "the front-desk computer is slow because of a virus." The person handling IT stops opening one antivirus screen at a time just to check whether everything's fine.

The financial gain is indirect but real: an infected computer stops generating revenue while it's down, and the rework of reinstalling the system, recovering files and resetting access eats into hours that could go toward serving a customer. When the alert reaches someone the same day, instead of being discovered a week later, the damage is smaller — and so is the time the computer spends out of commission.

It also changes the conversation leadership has about security. Instead of asking "are we protected?" — a question nobody can answer with a guess — the question becomes "how many computers are unprotected right now?", which has an objective answer once someone is actually watching for it every day.

Questions to bring to the next IT meeting

Does anyone know, right now, how many of the company's computers have antivirus disabled? If answering that means checking computer by computer, there's no visibility — there's a guess.

What happens when the antivirus blocks something at two in the morning? If the answer is "it sits there until someone looks on Monday," the alert isn't doing anyone any good.

Do laptops that leave the office get the same checks as the desktops that stay? That's exactly the part that depends on a cloud connection to work fully.

When was the last time someone confirmed, instead of assumed, that protection was up to date on every machine? If the answer is "not sure," the company is trusting luck, not a process.