Malware

In short
Malware is the umbrella term for software that damages a device or takes data from it — viruses, trojans, spyware and [ransomware](/glossary/ransomware) among them. It rarely arrives through a technical hole. Far more often it arrives through a person who opens or installs something.
The way in is rarely technical
Most cases start with a mail, an attachment, or a sign-in page that looks genuine. The attack is not aimed at the technology but at one person's attention on a busy day.
That is why phishing is not a separate topic sitting next to malware. It is its most common delivery route.
Why antivirus alone is not enough
Because it recognises what is already known. Malware that is new, or tailored to one target, is unknown at exactly the moment it arrives.
What carries beyond that are the measures that work even against something unrecognised: current software, restricted rights, multi-factor at sign-in, and a separate backup that is not permanently reachable.
How an infection shows itself
Usually later than you would like. The visible signs are sign-ins from unexpected countries, forwarding rules appearing in a mailbox, unexplained system load, or files that no longer open.
The most important reflex is the inconvenient one: disconnect the device from the network, do not reboot it, and get someone in. A reboot can destroy the traces the investigation needs.
How we handle it
We put the measures that work independently of the malware type in place first, and detection second. The order is deliberate: detection without basic hygiene reports incidents that need not have happened.
Implementation: IT security.
Related terms
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you — even when it did not come from us.