Even for smaller companies, when doing financial audit (required by law in many places) - consultant firms do highly encourage use of “endpoint protection across organization”. So in case of some IT screwup and financial losses, the auditors can say- “Well, they had Industry standard antivirus, so this shouldn’t have happened. Our financial risk assesment was still correct.”
ISO 27001 specifically mentions it
Any regulated industry where money or lives are at stake. An example is finance where regulations specifically state that you must have antivirus installed, even on servers.
what class software as antivirus for the legislator?
Doesn't Defender qualify as satisfying the regulatory burden?
PCI-DSS pretty much requires a malware protection solution. In practice - an antivirus.
Why Not Windows Defender? It’s really quite competent and it’s pretty lightweight.
That is just fine for PCI-DSS. Not a problem at all.