What Is the Difference Between a Virus and Malware?
Malware is the umbrella term for any malicious software — viruses, ransomware, trojans, spyware and worms. A virus is one specific type that spreads by attaching to legitimate files.
Quick answer
Malware is the umbrella term for any malicious software — viruses, ransomware, trojans, spyware and worms. A virus is one specific type that spreads by attaching to legitimate files. Most modern UK business attacks are ransomware and info-stealers, not classic viruses, so you need behavioural endpoint detection, not legacy antivirus. That is exactly what AMVIA runs — security-first.
Key Points
What you need to know.
The Short Answer
A concise overview of what you need to know.
For UK Businesses
How this applies specifically in the UK context.
Cost Considerations
What to expect in terms of investment and ongoing costs.
Next Steps
What you should do with this information.
Quick Comparison
| Feature | Option A | Option B |
|---|
People use "virus" and "malware" interchangeably, but they are not the same thing, and the difference matters when you are buying protection. Get the terms wrong and you buy the wrong defence. This guide explains both clearly, shows the threats UK businesses actually face in 2026, and sets out what real protection looks like. It is part of our wider managed cybersecurity guidance for UK SMEs.
What is malware?
Malware — short for "malicious software" — is any program written to damage, disrupt, steal from, or gain unauthorised access to a device or network. It is the parent category. Viruses, ransomware, trojans, spyware, worms, adware and rootkits are all sub-types of malware, each with a different method and goal.
The UK's National Cyber Security Centre treats malware as a broad family of threats rather than a single thing, because the way each type behaves — and the way you stop it — varies enormously. When a vendor sells you "anti-malware", they should be defending against the whole family, not just one member of it.
What is a virus, and how is it different?
A virus is a specific type of malware that replicates by attaching itself to a legitimate file or program. When that file runs, the virus runs too, then copies itself into other files. The key trait is that a virus needs a host file and usually some user action — opening an attachment, running a download — to spread.
So every virus is malware, but not every piece of malware is a virus. A worm, by contrast, spreads on its own across a network with no host file and no user action. A trojan hides inside something that looks legitimate. Treating "virus" as the whole problem is like calling every illness "the flu" — it leads you to the wrong treatment.
What are the main types of malware UK businesses face?
Classic file-infecting viruses are now a small slice of the threat landscape. The malware that actually hurts UK businesses today is built to make money — by encrypting your files, stealing your credentials, or quietly siphoning data. Approximately 19,000 UK businesses were hit by ransomware alone in 2025 (Sophos), and very few of those strains behave like a traditional virus.
Here is how the common types differ:
| Malware type | How it spreads | Primary risk to your business |
|---|---|---|
| Virus | Attaches to a file; runs when the file is opened | File corruption, system disruption |
| Worm | Self-replicates across networks; no user action needed | Rapid network-wide infection |
| Trojan | Disguised as legitimate software the user installs | Backdoor access, payload delivery |
| Ransomware | Phishing, stolen credentials, unpatched software | Encrypted files, ransom demand, downtime |
| Spyware / info-stealer | Silent install via phishing or bundled software | Stolen credentials, keystrokes, data theft |
Two patterns stand out. First, ransomware is now the dominant business threat, and it overwhelmingly arrives via phishing or stolen logins rather than a self-spreading file. Second, info-stealers run silently. 22% of breaches involved compromised credentials (Verizon DBIR 2025), many of them harvested by malware that sat undetected for weeks. If you want a deeper breakdown of the costliest type, read our explainer on what ransomware is and how it works.
Why is "antivirus" now an outdated term?
Traditional antivirus was built to spot known viruses by matching them against a database of signatures. That model struggles against modern threats — ransomware, fileless attacks, and info-stealers frequently have no known signature, or change with every infection. Signature matching simply does not see them.
This is why the industry shifted to endpoint detection and response (EDR), which watches for malicious *behaviour* — a process encrypting files en masse, a script reaching out to a command server — rather than a known fingerprint. 85% of businesses that experienced a breach identified phishing as the attack vector, according to the UK Cyber Security Breaches Survey 2025 (DSIT), and phishing-delivered malware routinely bypasses signature-based tools. Calling modern protection "antivirus" undersells what a business actually needs. We unpack the practical gap in our managed detection and response overview.
How do you actually protect a business from modern malware?
Effective protection is layered: stop the delivery (mostly phishing), detect malicious behaviour on the endpoint, and have someone watching around the clock to respond before a foothold becomes a full breach. No single product does all three, which is why managed services exist.
AMVIA's approach is deliberately one accountable stack:
- Behavioural endpoint protection with endpoint detection and response, using Microsoft Defender for Endpoint rather than signature-only antivirus.
- Email and network filtering via the Barracuda suite, because most malware still arrives by email — backed by dedicated phishing protection.
- 24/7 monitoring and response from our in-house SOC, so behavioural alerts are investigated and contained day or night — see 24/7 security monitoring.
One provider, security-first, with Microsoft-certified engineers. That single line of accountability matters: when something is flagged at 2am, you want one team that owns detection, response, and your Microsoft environment — not three vendors pointing at each other.
Frequently Asked Questions
Technically it's malware but rarely a true virus — ransomware seldom self-replicates by infecting files; it arrives via phishing, stolen credentials or exploited systems, then encrypts. The distinction matters because defences aimed at 'viruses' miss how modern attacks actually get in.
No — signature-based antivirus catches known files, while modern attacks increasingly use no recognisable malware at all: stolen logins, legitimate admin tools, fileless techniques. That's why the current standard is EDR (behaviour-based detection), ideally watched by someone.
Ransomware for impact, infostealers for quiet credential theft, and the phishing that delivers both — 85% of UK breaches involve phishing (DSIT 2025). The category names matter less than the entry route, which is overwhelmingly email and identity.
Signs include odd account activity, unexpected mail rules, machines suddenly slow or noisy at strange hours — but modern malware is deliberately quiet. The reliable answer is detection tooling and monitoring rather than symptoms; by the time it's visible, it's late.
Related Questions
What Is Ransomware?
Ransomware is the most damaging form of malware targeting UK businesses today.
Endpoint Security Service
EDR-based endpoint protection that detects ransomware and modern malware beyond legacy antivirus.
MDR vs EDR
Compare endpoint detection tools with fully managed detection and response.
Cybersecurity Guide for UK SMEs
A practical guide to understanding and defending against modern cyber threats.
Protect your business → Get Cybersecurity Assessment