Small Business Security 2026: What Consumer Antivirus Misses
By NorwegianSpark Editorial · Published August 29, 2026 · 7 min read — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Almost everything else on this site is written for one person protecting their own devices, and that advice does not stop being true when you start a company. What changes is that two new categories of risk appear, and neither is something an antivirus engine was ever built to see. The first is that data can now walk out through people who are supposed to have it. The second is that you have to decide whether someone you have never met in person is who they say they are, before you hand them the keys. This guide is about that narrow gap — and about not over-buying to fill it.
Start by not throwing away what already works
The most common mistake when a business starts taking security seriously is to assume the consumer layer is now beneath it. It is not. The realistic incidents that take a small company offline are the same ones that hit households: ransomware arriving through a download, a phishing page harvesting a reused password, a laptop stolen from a car. The controls that answer those have not changed.
- Antivirus on every device, including the ones nobody thinks of. Our best antivirus guide covers the engines, and whether Macs need it answers the argument that always comes up.
- A password manager, used by everyone, not just by you. See best password managers — and the password rules NIST says to stop enforcing, because forced 90-day rotation makes staff behaviour worse, not better.
- Backups you have actually restored from. An untested backup is a belief, not a control. Our backup software review covers the tooling; the discipline is yours.
- Multi-factor authentication on email above all else. Email is the reset path for everything else you own.
If those four are not all in place, stop reading here and fix them. Nothing below is worth buying before they are done.
The first genuinely new problem: data leaving with your own people
Insider risk is uncomfortable to plan for, because planning for it means accepting that the people you hired are part of your threat model. In practice it is rarely dramatic. It is a salesperson exporting the client list in their notice period, a contractor keeping a copy of the project folder, someone emailing a spreadsheet to a personal address so they can finish it at home. No malware is involved, no perimeter is crossed, and in most small companies nobody would ever know it happened.
Antivirus is structurally blind to all of it. Its job is to judge whether code is malicious; here the code is Windows Explorer and the actor has a valid login. The tooling that addresses this works on a different axis — recording what happened to which file, and making displayed information traceable back to whoever displayed it.
Coworkshop Solutions — file activity and screen watermarking
Coworkshop Solutions sells two products aimed squarely at this layer. Curtain LogTrace monitors file activity, so that copying, moving, renaming and removal leave a record rather than happening silently. Curtain MonGuard applies screen watermarking, so that a document displayed on a monitor carries a mark identifying the session it was shown in.
Be clear about what the second one does. Watermarking does not physically prevent a person from photographing their own screen, and any vendor implying otherwise should be treated with suspicion. What it changes is that a leaked screenshot is no longer anonymous, which deters the casual case and preserves evidence in the deliberate one. That is a real control, but it is a behavioural and forensic one, not a barrier.
This is organisational software and it is priced and deployed as such. It is the wrong purchase for a household, and it is the wrong first purchase for a company that has not yet finished the list above. It earns its place when you hold data whose loss would genuinely damage you — client records, designs, source code — and when more than a couple of people can reach it.
The second: verifying the person before they become an insider
Remote hiring quietly removed a check nobody had ever thought of as a security control: someone turned up, in a building, and was seen. Without it, the interview and the first day of work are two separate events involving two faces on two screens, and nothing in a standard hiring process confirms they belong to the same person.
The failure modes range from mundane to serious. A candidate has a more capable friend sit the technical interview. A recruitment intermediary substitutes one worker for another after placement. At the far end, an identity is fabricated outright in order to obtain employment and the access that comes with it. What makes this a security problem rather than an HR one is what happens next: onboarding issues credentials, device access and, very often, a path to customer data. Every control discussed on this site assumes accounts belong to the people they were issued to.
Secure Interview — identity checks at the interview stage
Secure Interview, from Sourcer, Inc., addresses candidate-identity verification and recorded-interview integrity — confirming that the person in the interview is the person they claim to be, and that the interview itself was not gamed. It sits earlier in the chain than anything else here, which is the point: it is considerably cheaper to decline a candidate than to revoke access, rotate credentials and audit what was reached in the meantime.
Three different jobs, compared
| Feature | Coworkshop | Secure Interview | Consumer antivirus |
|---|---|---|---|
| Problem it addresses | Data leaving via your own staff | The candidate is not who they claim | Malicious code reaching a device |
| Who the threat is | Insiders and departing staff | Applicants and their proxies | External attackers |
| Stops malware | No | No | Yes (its core function) |
| Useful to a household | No — organisational | No — organisational | Yes |
| Where it sits | File activity and screen display | The hiring process, before access exists | The endpoint |
| Get the deal | See Coworkshop | See Secure Interview | Covered in our consumer guides |
These are not competitors and choosing between them is the wrong question. Antivirus answers external code, Coworkshop answers what insiders do with data they can already reach, and Secure Interview answers whether that insider should have been given access at all. A company that buys the second two while neglecting the first has arranged its spending backwards.
Mistakes worth avoiding
- Buying organisational tooling before the basics are finished. Insider-risk software on machines without tested backups is an expensive way to document your own ransomware incident.
- Treating monitoring as a substitute for access control. The cheapest insider-risk reduction available is not buying anything — it is that fewer people can reach the sensitive folder in the first place.
- Deploying surveillance quietly. Recording file activity and watermarking screens carries legal and employment obligations that vary by jurisdiction, and staff discovering it by accident does more damage than the leak you were worried about. Tell people, and take advice for your own jurisdiction.
- Assuming a background check covers identity. A background check verifies a history against a name. It does not establish that the person on the call is the one attached to that name.
Frequently Asked Questions
Is business antivirus different from the consumer version?
What is insider risk, and is it really a threat for a small company?
What does screen watermarking actually stop?
Why would a company need to verify a candidate's identity?
Should a small business buy all of this at once?
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.