"What antivirus do you recommend for my practice?" is one of the questions I get asked most on a client visit, usually between two other tasks or while setting up a new machine. The honest answer usually surprises people: for most of the small Paris businesses I work with, what's already sitting on an up-to-date Windows PC is enough. The real question is almost never which antivirus brand to buy — it's everything people skip around it.

Microsoft Defender is genuinely good enough for most small businesses
I'll say this plainly, even though it doesn't help me commercially: Microsoft Defender, the one already built into Windows 10 and Windows 11, has become a serious antivirus. Ten years ago its reputation was bad, and fairly so; that hasn't been true for years now. Independent labs (AV-Test, AV-Comparatives) routinely rank it alongside paid suites for detecting common malware, with one advantage nobody else has: direct access to Microsoft's own security telemetry across hundreds of millions of machines worldwide.
For a freelancer, a three-person practice or a small agency anywhere from the 16th to the 8th arrondissement, Defender has three decisive qualities: it's already there, it's free, and it's fully integrated with the system — no conflicts with updates, no second engine dragging the machine down, no upsell popup at startup. If your business runs Microsoft 365 Business Premium, Defender for Business is already bundled into the subscription — better to lean on that than pay for a second layer doing much the same job. A short Microsoft 365 support session usually gets that configuration sorted in under an hour.
When a paid antivirus genuinely earns its price
It's rarely about "better virus protection" in the raw sense — the gap between Defender and paid suites has become marginal there. The real case for paying is about management, not detection.
The first trigger is machine count. Past roughly ten devices, managing security one machine at a time stops being realistic: manually checking that each PC is up to date and that nobody accidentally disabled the antivirus. A central console — the kind a paid EDR (Endpoint Detection and Response) tool provides — gives one view across the whole fleet, with alerts surfacing automatically.

The second trigger is ransomware recovery. Some paid suites (Sophos Intercept X, for instance) include a rollback mechanism that keeps local copies of modified files and can restore them automatically if mass encryption is detected mid-attack — something Defender alone doesn't offer in an equivalent way. For an accounting practice storing client files on a shared drive, that single feature can justify the subscription.
The third trigger is an outside requirement: a cyber insurance policy requiring proof of a deployed EDR, a larger client demanding a security review before signing, or an ISO 27001 process underway. It stops being a purely technical choice — it becomes a contractual box to tick, and it's better ticked with a recognised product than with Defender alone.
What actually matters more than the antivirus brand
This is the point I repeat most on-site, and the one people least want to hear because there's nothing to buy for it. Of the last ten infections I've dealt with for business clients in Paris, the installed antivirus wasn't at fault in a single one. The problem almost always came from somewhere else: Windows with no security update in months, an admin password reused across three services, or a backup that had never actually worked.
Automatic updates for Windows, the browser and business software close most of the gaps exploited in practice — even an excellent antivirus always reacts after the flaw exists, never before. Two-factor authentication (MFA) on business email and cloud accounts blocks most account takeover attempts. Backups that are actually tested, not just scheduled, are what separates a business back up in a day after ransomware from one that loses months of files. Least-privilege access — no admin account for daily work — limits the damage if a machine gets compromised anyway. And an ad blocker removes a large share of the fake sites that serve as the initial entry point.
None of these five things cost much, and none depend on which antivirus brand you pick. And yet they decide nearly all of the real-world risk a small business actually carries.
Paid options worth considering, by profile
If you do decide to go paid, the right choice mostly depends on what you already have. On Microsoft 365 Business Premium, Defender for Business is included and deploys without third-party software — the obvious choice nine times out of ten. For ten to fifty machines wanting a simple console without depending on Microsoft, Bitdefender GravityZone Business Security or ESET PROTECT Entry offer a solid balance of central management and price, with a light footprint on performance. For sensitive data or an insurer requiring automatic restoration, Sophos Central Intercept X remains the reference — pricier, but with a genuinely proven rollback feature. Malwarebytes for Business works well as a second layer alongside Defender, for one-off cleanup of unwanted software.
Why free consumer antivirus is a bad idea for a business
Putting a free Avast or AVG on business machines looks like an easy way to save money, but it's a false economy. First, a simple contractual issue: free consumer licences explicitly prohibit commercial use. In the event of an incident, your insurer can refuse to cover a claim if the security software installed wasn't under a valid business licence.
Second, a practical issue: these free tiers offer no management console or central visibility, and several consumer vendors have been caught selling browsing data or bundling unwanted toolbars into their installers. Nothing illegal for an individual, but nothing professionally defensible once business data is involved. A lightweight business antivirus costs relatively little compared with the risk taken.
The reality on macOS
XProtect and Gatekeeper, built into macOS, filter known threats effectively and block unsigned applications from running without explicit approval. For a single Mac used by a freelancer, that baseline is enough in the vast majority of cases — Mac malware exists and is growing, but stays well below Windows numbers. I cover the real risks in my article on how to protect a Mac from viruses in 2026.
The nuance shows up at fleet scale. Once an agency passes five or six business Macs, macOS alone stops giving central visibility: no way to know, without a lightweight EDR, whether one machine has been compromised before the problem spreads. Same logic that applies to Windows, carried over to a mixed fleet.

Avoiding an antivirus that slows the PC down
Slowdown traced to antivirus almost always comes from the same cause: two real-time protections running at once. A third-party antivirus installed without first disabling Defender means two engines constantly scanning each other, doubling the load without doubling the protection. Check what's already running before installing anything.
Beyond that, full scans scheduled mid-workday explain most of the slowdown complaints I get called about. Scheduling the full scan outside working hours and excluding large, already-verified folders from the real-time scan solves most of it without reducing protection. Finally, hardware matters more than software: an SSD with enough RAM absorbs the load of a modern antivirus, while an old mechanical hard drive will make any security suite feel sluggish, even the lightest one.
Paris pricing
A review of existing protection across five to fifteen machines — checking Defender, updates, backups — typically runs €89 to €149 depending on the number of devices. If a paid EDR deployment is the right call, expect roughly €3 to €7 per device per month depending on the vendor, plus €250 to €450 for initial setup across about ten machines. Businesses on an ongoing IT maintenance plan get this review as part of the standard check. For a one-off visit at home or at the office in Paris, an initial assessment is usually possible within 48 hours.
Frequently asked questions
Do I need to pay for antivirus if Windows Defender is already installed?
Not necessarily. For a freelancer or a business under ten machines, an up-to-date Defender, paired with a properly configured firewall and real backups, covers most real-world threats. Paid antivirus earns its keep once you need a central console to watch several machines remotely.
How much does an EDR cost for a small business in Paris?
Expect roughly €3 to €7 per device per month depending on the vendor and protection tier, plus initial deployment time. For around ten machines, a full deployment with console setup runs about €250 to €450, on top of the subscription.
Does a Mac need antivirus in a business setting?
XProtect and Gatekeeper, built into macOS, block the great majority of known threats on a single Mac. Once a fleet of business Macs passes five or six machines, a lightweight EDR adds the central visibility macOS alone doesn't provide, mainly to catch a compromised machine before it spreads across the shared network.
My antivirus is slowing down my PC, what should I do?
First check that only one antivirus engine is actively running: two real-time protections scanning each other is the most common cause of slowdown. Then exclude large, trusted folders from the continuous scan and schedule the full scan outside working hours instead of running it constantly.