Really? We really don't do that anymore. We have a strong XDR (Extended Detection and Response), basically Antivirus + behavioural analysis + SIEM integration. A managed password manager, and even detection for such behaviour of stored passwords in plain text or office files (through Microsoft Purview DLP). XDR is an evolution of EDR (Endpoint Detection and Response) with a bit more in terms of data sources added (and a lot of marketing "Our <..>DR is better than yours because we have a cooler letter" :P
Basically an XDR looks not only at malware but also at potentially malicious actions. This is a much more complete view because not every malicious action is triggered by malware. It can also be simply a user (and AI automation/control will be a new thing there). Big names in this are Crowdstrike (yes that one that killed half the enterprises), SentinelOne, Microsoft Defender for Endpoint (not to be confused with the normal consumer defender). An XDR will notice when a PC is doing a port scan, when a process is trying to gain root rights, when significant numbers of files are suddenly rewritten. It will immediately kill the process and/or trigger a ticket to the SOC (Security Operations Center). Who can take global actions on all endpoints to immediately kill the malware everywhere. It's pretty cool, you can trace back the entire process history, what launched what, what was were the system call parameters etc.
Big companies really have this stuff figured out. Unfortunately exfiltration is harder to detect if the malicious actor is doing it through a cloud service that the company also subscribes to.
If a company doesn't know what XDR is they are probably < 100 employees.