
Between quishing campaigns that hide malicious QR codes in emails and ransomware targeting both individuals and small organizations, the attack surface of a workstation continues to expand. Protecting your computer against viruses and cyberattacks today requires measuring the gap between what the operating system provides natively and what recent threats actually demand.
Windows Defender vs. Commercial Antivirus: Performance Table
For a long time, installing a third-party antivirus was an almost automatic reflex. Recent results from independent laboratories call this habit into question.
| Criterion | Windows Defender (February 2026) | Commercial Antivirus (average) |
|---|---|---|
| AV-TEST Protection Score | Maximum Score | Maximum Score for Leaders |
| Threat Blocking (Sept. 2025) | 100% of tested threats | Equivalent rate for top vendors |
| Annual Cost | Integrated with Windows | Paid subscription |
| Additional Features (VPN, password manager) | Absent or limited | Often included |
| Impact on System Performance | Moderate | Variable by vendor |
The conclusion is clear: Windows Defender now matches the protection level of commercial antivirus in standardized tests. The gap lies elsewhere, in peripheral functions (integrated VPN, password vault, extended browsing protection). For typical office use, the native layer of Windows is sufficient to cover the detection base. Additional resources are regularly published on viruslab.fr to compare detection engines based on the type of threat encountered.
However, if you handle sensitive data or work from a professional workstation subject to insurance requirements, a third-party antivirus may still be relevant, not for raw detection, but for the ancillary tools it includes.

Quishing and ASCII Art: Attack Vectors That Classic Filters Do Not Block
Anti-spam and antivirus filters analyze attachments, hyperlinks, and the text of emails. Attackers are aware of this and adapt their methods.
Since 2024, campaigns of quishing (phishing via QR code) have been multiplying. The principle: integrate a QR code into the body of an email to redirect the victim to a fraudulent site. Since the QR code is an image, text filters detect nothing suspicious.
Security vendors report a more sophisticated variant: QR codes reconstructed in ASCII art, character by character, in the body of the message. This technique bypasses both image filters and text filters because the pattern is neither a clickable link nor a classic image.
- Never scan a QR code received by email without verifying the sender and the context of the message, even if the email seems to come from a known provider.
- Hover over or decode the QR code with a URL preview tool before opening the link in your browser.
- Disable automatic link opening in your mobile messaging app, as this is the main entry point for these attacks.
This type of vector illustrates an underlying trend: threats bypass software protections through user behavior. No antivirus, even the most effective, can block a QR code that you voluntarily decide to scan.
Cyber Insurance and Hardening the Workstation: What Insurers Require
A rarely addressed angle in consumer protection guides concerns the requirements of insurers. Since 2025, cyber insurance brokers increasingly condition the acceptance or maintenance of coverage on concrete technical evidence.
Among the measures requested, multifactor authentication activated on all privileged accounts, a documented backup policy (frequency, medium, restoration testing), and formalized incident response procedures are systematically included.
For a professional individual or a micro-enterprise, this means that protecting your computer is no longer just a technical issue, but a contractual condition. A workstation without two-factor authentication or verifiable backups may lead to a denial of compensation in the event of an incident.
Minimum Technical Measures to Document
- Active multifactor authentication on email, cloud storage, and administrative access to the operating system.
- Automated backups on a disconnected medium or an encrypted cloud service, with a restoration test at least once per quarter.
- Operating system and software updates applied shortly after publication, especially critical security patches.
- Event logs activated to trace connections and unusual access attempts.

Resources Cybermalveillance.gouv.fr: An Updated Awareness Foundation
The Cybermalveillance.gouv.fr initiative has strengthened the availability of thematic content for the general public and small organizations since 2024. Guides, practical sheets, and videos cover the main threats (ransomware, phishing, data theft) with regular updates.
These resources do not replace a protection tool, but they fill a frequent blind spot: the user’s ability to identify an attempted attack before the software intervenes. An effective antivirus combined with a user who clicks on every attachment without verification remains a vulnerable point.
Protecting a computer relies on three distinct layers: software detection, system configuration, and user behavior. The weakness of one negates the strength of the other two.
Recent data on Windows Defender shows that the software layer is no longer the weak link for the majority of uses. It is the vectors that bypass the software, like quishing, and the organizational gaps that insurers are beginning to financially penalize.