I worked in such companies, where you need to sign that you assume all legal consequences of a virus being introduced into the company network via your computer.
But big companies have internal security teams which basically handle all of this behind the scenes (until you get road blocked weeks/months when they come out of the woodwork to make your new product secure - a very necessary annoyance)
No, most people would rather install an IT certified anti-virus on their systems and keep the customer, than lose the business opportunity.
Didn't think so