CIS IG1 Control 10.1: Table Stakes, but Only If It Can Catch What’s Actually Out There

Deploy and Maintain Anti-Malware Software

 

Anti-malware is the one security control almost every business already believes it has. So the question worth asking isn’t whether you have it. It’s whether what you have can catch what actually shows up today, and whether it’s running on everything, not just the obvious computers. A lot of organizations are protected on paper and quietly exposed in practice.

Control 10.1 is deliberately foundational. It doesn’t ask for anything exotic. It asks that real, current anti-malware protection is deployed and managed across your whole environment, which sounds simple until you go looking for the gaps.

 

What this control actually says (in plain English)

 

Here’s the translation: every computer and server needs current anti-malware protection, installed and managed centrally rather than left to each machine to handle on its own.

Now the official version. Control 10.1 says you should deploy and maintain anti-malware software on all enterprise assets.

The word all is doing quiet work there. The failures with this control are almost never “we had no anti-malware.” They’re “we had it, but not on that.”

 

Why business leaders should care

 

Two gaps show up again and again. The first is coverage. Anti-malware tends to land reliably on staff laptops and desktops, then thin out from there. Servers, which often hold the most valuable data, get missed because someone assumed they were handled. Macs get missed because of a lingering belief that they don’t need protection. Every uncovered machine is a soft spot in an otherwise reasonable defense.

The second gap is age. “Anti-malware” isn’t one thing. Older, signature-only tools recognize threats they’ve seen before and struggle badly with anything new, while modern protection watches for malicious behavior and catches attacks that don’t match any known fingerprint. A business running decade-old-style protection can genuinely believe it’s covered while missing exactly the kind of threat most likely to actually hit it. Having anti-malware and having anti-malware that can catch what’s out there now are not the same claim.

 

What “good” looks like

 

This is achievable without turning your business into a security operation. Here’s the practical path.

  • Deploy to everything, using your inventory to check. Put anti-malware on every endpoint and every server, and reconcile against your asset inventory so nothing is quietly left out. This is exactly why we started the series with Establish and Maintain a Detailed Enterprise Asset Inventory: you can only protect the machines you know you have.
  • Cover the platforms people forget. Make sure servers and Macs are protected to the same standard as Windows laptops, not treated as exceptions.
  • Choose modern, behavior-aware protection. Favor tools that detect malicious behavior, not just known signatures, so you’re defended against threats no one has catalogued yet.
  • Manage it from one place. Use a central console so you can see coverage, spot machines that have fallen out of protection, and respond quickly. Protection you can’t see the status of isn’t protection you can rely on.

 

The audit and defensibility angle

 

This is one of the first controls anyone evaluating your security will check, and it’s easy to get partial credit for while failing the substance. Being able to show full coverage across every asset, on current and centrally managed protection, is a clear signal of a well-run environment. The organizations that struggle here are almost always the ones that couldn’t say with confidence what they owned in the first place, which is why coverage and inventory rise and fall together.

Anti-malware is table stakes, but table stakes only count if they’re actually on the table everywhere and current enough to matter. Deploy real protection to every machine you own, keep it modern, and manage it where you can see it. Do that and you’ve closed one of the most basic gaps attackers count on finding, the one everyone assumes is handled and no one checks.

Heath Gieson

Heath Gieson

Let's Connect. Make Better Technology Decisions with Forthright.

Understand your current environment and get a clear path forward. Let's connect.

who we support

Built for organizations that prioritize security, uptime, and compliance.

Z

Teams that want executive-level technology guidance and strategy for growth

Z

Operations that cannot afford disruption from unreliable or reactive IT

Z

Organizations ready to modernize operations with AI, automation, and data-driven insights

Z

Organizations handling sensitive data that need to stay secure and compliant without slowing down operations

Z

Organizations seeking outsourced IT support that strengthens their internal team or provides complete coverage when no internal team is in place

Forthright is the technology partner you should be working with

2024_CRN_MSP_500
Certified minority business
comptia-cybersecurity-trustmark