Analyst at a monitor at night
Insights··6 min read

Why Antivirus Alone Isn't Enough in 2026

Antivirus still matters. But the attacks that hurt businesses most in 2026 do not look like viruses, and a scanner built to spot bad files cannot see a criminal logging in with a valid password.

What antivirus was built to do

Traditional antivirus works by recognising known bad files. A vendor sees a piece of malware, writes a signature for it, and every protected machine learns to block that file. It is effective against the flood of commodity malware that still circulates, and no business should run without it. But its model assumes two things: that the attacker brings a file, and that someone has seen that file before.

In 2026, both assumptions fail more often than they hold.

The attacks that leave no file behind

CrowdStrike's 2026 Global Threat Report found that 82% of detections in 2025 were malware-free — up from 51% in 2020.[1] Instead of dropping malicious software, adversaries log in with valid credentials, then use the tools already on the machine: PowerShell, Windows Management Instrumentation, remote desktop, scheduled tasks and legitimate remote-access software. Security teams call this "living off the land". To a signature scanner it looks like an administrator doing admin work, because technically that is what it is.

They are also fast. The average eCrime "breakout time" — the gap between initial access and lateral movement onto another system — dropped to 29 minutes in 2025, a 65% increase in speed from the previous year. The fastest observed breakout took 27 seconds.[1][2] A control that only evaluates files at the moment they are written to disk has no opportunity to intervene in an intrusion that never writes one.

82%Share of detections in 2025 that were malware-free — attackers used valid credentials and legitimate tools rather than malicious files (CrowdStrike, 2026).[1]

Credentials are the new malware

If attackers are not using malware, what are they using? Mostly, your passwords. Verizon's 2025 Data Breach Investigations Report lists credential abuse as the leading initial attack vector at 22% of breaches, with exploitation of vulnerabilities close behind at 20% — and vulnerability exploitation grew 34% year on year.[3] In cloud environments, CrowdStrike attributes 35% of incidents to valid-account abuse.[1]

The South African picture matches. Sophos' State of Ransomware in South Africa 2026 found compromised credentials were the most common technical root cause of ransomware (27% of incidents), ahead of exploited vulnerabilities (25%) and malicious email (22%). Strikingly, 85% of victims said their ransomware incident was the same event as their most significant identity attack.[4] Ransomware, in other words, is usually the last step of an identity breach — and antivirus is looking for the wrong thing at the wrong time.

Where attackers actually get in

Sophos also asked South African organisations where the intrusion started. User devices were the entry point in 43% of incidents and exposed applications or systems in 38%; firewalls accounted for 13%.[4] Verizon adds a third door: breaches involving a third party — a supplier, contractor or software vendor — doubled to 30% of the total.[3]

The common thread is that each of these is a behaviour problem rather than a file problem: a laptop signing in from an unusual place at 02:00, a web application being probed for a vulnerability published last week, a supplier's account suddenly downloading gigabytes of files. Catching it means watching what happens, not just what arrives.

What "enough" looks like in 2026

None of this means uninstalling antivirus. It means recognising that antivirus is one layer, and building the others around it:

The hardest part for an SME is not the tools but the capacity to run them. In South Africa, 47% of ransomware victims cited a lack of adequate protection and 43% a lack of cybersecurity capacity or expertise as contributing factors.[4] That is the honest reason "antivirus alone" persists: it is the one control that runs itself. The answer is not more products to babysit; it is a defence someone is actually watching.

References

  1. CrowdStrike, 2026 Global Threat Report: Evasive Adversary Wields AI (key findings), February 2026. crowdstrike.com
  2. CrowdStrike, 2026 CrowdStrike Global Threat Report press release, 24 February 2026. crowdstrike.com
  3. Verizon, 2025 Data Breach Investigations Report, 23 April 2025. verizon.com
  4. IT-Online, Defences improve, but ransomware still threatens SA businesses, 18 September 2026 — reporting Sophos, The State of Ransomware in South Africa 2026. it-online.co.za
  5. CISA, MS-ISAC, NSA and FBI, #StopRansomware Guide, updated 2023. cisa.gov

Get your free
Cyber Security Review.

In 30 minutes, we'll assess your current security posture and show you exactly where you're exposed — at no cost, no pressure.