With fake SSL certificates signed by "real" CAs, cross-site scripting and other advances in phishing attacks, just educating users may not be as effective as it used to be. Malware is quickly becoming advanced enough that even trained technical users may be fooled. Many attacks don't require user interaction. AV products may be slow to respond and signature matching won't catch everything, but if it catches half of what shows up on corporate networks it can still save a lot of time and money.