What antivirus was built to do
Traditional antivirus works by recognising known bad files. A vendor sees a piece of malware, writes a signature for it, and every protected machine learns to block that file. It is effective against the flood of commodity malware that still circulates, and no business should run without it. But its model assumes two things: that the attacker brings a file, and that someone has seen that file before.
In 2026, both assumptions fail more often than they hold.
The attacks that leave no file behind
CrowdStrike's 2026 Global Threat Report found that 82% of detections in 2025 were malware-free — up from 51% in 2020.[1] Instead of dropping malicious software, adversaries log in with valid credentials, then use the tools already on the machine: PowerShell, Windows Management Instrumentation, remote desktop, scheduled tasks and legitimate remote-access software. Security teams call this "living off the land". To a signature scanner it looks like an administrator doing admin work, because technically that is what it is.
They are also fast. The average eCrime "breakout time" — the gap between initial access and lateral movement onto another system — dropped to 29 minutes in 2025, a 65% increase in speed from the previous year. The fastest observed breakout took 27 seconds.[1][2] A control that only evaluates files at the moment they are written to disk has no opportunity to intervene in an intrusion that never writes one.
Credentials are the new malware
If attackers are not using malware, what are they using? Mostly, your passwords. Verizon's 2025 Data Breach Investigations Report lists credential abuse as the leading initial attack vector at 22% of breaches, with exploitation of vulnerabilities close behind at 20% — and vulnerability exploitation grew 34% year on year.[3] In cloud environments, CrowdStrike attributes 35% of incidents to valid-account abuse.[1]
The South African picture matches. Sophos' State of Ransomware in South Africa 2026 found compromised credentials were the most common technical root cause of ransomware (27% of incidents), ahead of exploited vulnerabilities (25%) and malicious email (22%). Strikingly, 85% of victims said their ransomware incident was the same event as their most significant identity attack.[4] Ransomware, in other words, is usually the last step of an identity breach — and antivirus is looking for the wrong thing at the wrong time.
Where attackers actually get in
Sophos also asked South African organisations where the intrusion started. User devices were the entry point in 43% of incidents and exposed applications or systems in 38%; firewalls accounted for 13%.[4] Verizon adds a third door: breaches involving a third party — a supplier, contractor or software vendor — doubled to 30% of the total.[3]
The common thread is that each of these is a behaviour problem rather than a file problem: a laptop signing in from an unusual place at 02:00, a web application being probed for a vulnerability published last week, a supplier's account suddenly downloading gigabytes of files. Catching it means watching what happens, not just what arrives.
What "enough" looks like in 2026
None of this means uninstalling antivirus. It means recognising that antivirus is one layer, and building the others around it:
- Behavioural endpoint detection and response (EDR). Modern endpoint platforms still block known malware, but they also watch for suspicious behaviour — credential dumping, unusual PowerShell, mass file encryption — and can isolate a device automatically. For most small businesses the practical form is a managed service (MDR), because an alert at 02:00 is only useful if someone acts on it.
- Phishing-resistant multi-factor authentication on email, VPN, remote access and every administrator account. The CISA-led #StopRansomware Guide puts this at the top of its prevention list.[5] A stolen password with MFA in front of it is a failed login, not a breach.
- Patching that prioritises internet-facing systems and known-exploited vulnerabilities, closing the second-largest door.[5]
- Email authentication. Implementing DMARC, built on SPF and DKIM, makes it far harder for criminals to send email that appears to come from your domain — the mechanism behind most business email compromise.[5]
- Least privilege and segmentation, so that a compromised account or device cannot reach everything.[5]
- Offline, tested backups, because no prevention layer is perfect.
The hardest part for an SME is not the tools but the capacity to run them. In South Africa, 47% of ransomware victims cited a lack of adequate protection and 43% a lack of cybersecurity capacity or expertise as contributing factors.[4] That is the honest reason "antivirus alone" persists: it is the one control that runs itself. The answer is not more products to babysit; it is a defence someone is actually watching.
References
- CrowdStrike, 2026 Global Threat Report: Evasive Adversary Wields AI (key findings), February 2026. crowdstrike.com
- CrowdStrike, 2026 CrowdStrike Global Threat Report press release, 24 February 2026. crowdstrike.com
- Verizon, 2025 Data Breach Investigations Report, 23 April 2025. verizon.com
- IT-Online, Defences improve, but ransomware still threatens SA businesses, 18 September 2026 — reporting Sophos, The State of Ransomware in South Africa 2026. it-online.co.za
- CISA, MS-ISAC, NSA and FBI, #StopRansomware Guide, updated 2023. cisa.gov

