What are the key advantages of AVG Internet Security Business Edition?
Central console – AVG Cloud Management Console included, no per device setup.
Exchange protection – Scans mail on your own Exchange Server.
SharePoint scanning – Checks files uploaded to and downloaded from servers.
Ransomware defence – Behavioural tests and sandboxing on Windows endpoints.
Managed firewall – Policy based traffic filtering across all Windows devices.
Important note – No EDR, patch management or Mac coverage.
Business Antivirus – File, web, email and behaviour shields on Windows endpoints.
Exchange Server Protection – Scans mail for spam, phishing links and infected attachments.
SharePoint Server Protection – Scans files uploaded to and downloaded from SharePoint.
Firewall – Filters traffic and blocks unauthorised inbound and outbound connections.
AVG Cloud Management Console – Deploy agents, apply policies and monitor threats centrally.
Important – No EDR, patch management or encryption management is included.
AVG Internet Security Business Edition is Windows-only endpoint protection for small and medium businesses, extended with mail and file server scanning, and managed centrally through the AVG Cloud Management Console. AVG dropped the year from its business product names, so older listings such as AVG Internet Security Business Edition 2016 refer to the same continuously updated line.
One console – Install, update and configure agents without visiting each PC.
Mail server coverage – Strips infected attachments before staff open them in Outlook.
Ransomware analysis – Static tests, behavioural tests and sandboxing on endpoints.
CyberCapture – Unknown files are locked and sent to Threat Labs.
Out of hours scanning – Smart Scanner runs outside your core business hours.
Password Protection – Guards credentials stored in Chrome and Firefox browsers.
The fit depends less on headcount than on what you have to prove to third parties. A company that only needs malware protection on Windows PCs and an Exchange server is well served. A company that has to demonstrate detection and response, or answer supplier audits in detail, will run into the missing components quickly.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | Often | ✓ |
| EDR telemetry and incident forensics | Rarely | Often | ✓ |
| This product fits | ✓ | Partial | ✕ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the revised Information Security Act requires them to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Organisations below the thresholds set in the Cybersecurity Ordinance, broadly fewer than 50 employees and under CHF 10 million turnover or balance sheet total in the critical activity, are exempt. What this product contributes is the detection record: the AVG Cloud Management Console collects threat alerts, detections and quarantine entries from the managed Windows endpoints, Exchange and SharePoint servers, which is the material you use to describe what was found and when. What it does not contribute is everything the rest of a report needs, because there is no EDR telemetry to reconstruct how an attacker moved through the network, no log retention or syslog export into a SIEM, and no incident handling workflow, so a 24-hour report has to be assembled manually from console alerts and other sources. This is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
No product creates NIS 2 compliance, because the directive places duties on the organisation rather than on software: risk analysis and security policies, incident handling and reporting, business continuity and backup, supply chain security, vulnerability handling and disclosure, access control and cryptography, and basic cyber hygiene and staff training, with management held accountable. Measured against that list, this edition covers a narrow but genuine part of cyber hygiene: malware protection on Windows workstations, on Exchange mailboxes and on SharePoint file content, network filtering through the managed firewall, and policies enforced centrally rather than left to each user. The gaps are substantial and should be planned for: no backup, no encryption or key management, no multi-factor authentication, no vulnerability or patch handling, and no incident response tooling. Patch management is a separate AVG product rather than a component of this edition, so vulnerability handling means an additional purchase even inside the AVG range. Treat this edition as one preventive control among many, not as an answer to NIS 2.
AVG business products are made by Avast, part of Gen Digital, and two authority decisions concerning Avast are final and still in force. The Czech Office for Personal Data Protection issued a final and binding decision in April 2024 imposing a fine of CZK 351 million, around EUR 13.9 million, on Avast Software for unlawfully transferring pseudonymised browsing data of roughly 100 million users of its antivirus software and browser extensions to its subsidiary Jumpshot during 2019, a case handled jointly with other EU supervisory authorities under the GDPR one-stop-shop mechanism. In June 2024 the US Federal Trade Commission finalised an order requiring Avast to pay USD 16.5 million, banning it from selling or licensing browsing data for advertising, and requiring a privacy programme subject to independent assessment for 20 years. Avast closed Jumpshot in 2020 and has maintained that its handling of the data was lawful. Independent testing of the protection engine is a separate matter and has continued: AV-Comparatives awarded Avast the Approved Business Security Product award in both runs of its 2025 enterprise main test series, although the SKU submitted for those business tests is the Avast-branded business product built on the shared engine, not the AVG Business Edition itself. In practice this matters most if you sell into the public sector or to large customers whose supplier questionnaires ask about regulatory findings against a vendor within the last five years, because you will have to declare these decisions; the findings concern consumer telemetry from 2019 rather than the business management console, and the decision on whether that is acceptable is yours.
Partly, and it is worth knowing exactly where the answers stop. It lets you answer yes, with evidence from one console, to the questions on centrally managed anti-malware across all workstations, on protection of mail against malicious attachments and phishing links at the Exchange server, on scanning of file content held in SharePoint, on a centrally enforced host firewall policy, and on an audit trail of detections and quarantined objects. It does not answer the questions on endpoint detection and response or continuous monitoring, on multi-factor authentication, on encryption of data at rest and removable media, on vulnerability scanning and patch cycles, on backup and tested restores, on log retention and SIEM forwarding, on mobile device management, or on coverage of macOS and Linux systems. It also does not help with the supplier due diligence questions about regulatory findings against the vendor. Closing those gaps by moving up within the AVG family is not possible in the way it usually is with other vendors: the AVG business range consists of the AntiVirus and Internet Security editions, the File Server and Email Server editions, Patch Management and the console, with no higher tier that adds EDR, encryption, backup or MFA, so the practical route is to add Patch Management for the vulnerability questions and to source detection and response, backup and MFA elsewhere.
The decisive difference is mail: only the Internet Security edition includes Exchange Server Protection, which scans messages on your own Exchange server for spam, suspicious links and infected attachments. The second difference is Password Protection, which secures credentials stored in Chrome and Firefox against theft by malware. Everything else is shared, including the firewall, SharePoint Server Protection, CyberCapture, Smart Scanner, the File Shredder and the AVG Cloud Management Console, and both editions run the same protection engine. If you have no Exchange server on your own hardware, for example because mail runs in Microsoft 365, the mail scanning component has nothing to attach to and the AntiVirus edition is the more sensible choice.
| Component | AntiVirus Business Edition | Internet Security Business Edition |
|---|---|---|
| Exchange Server Protection | ✕ | ✓ |
| Password Protection | ✕ | ✓ |
| SharePoint Server Protection | ✓ | ✓ |
| Firewall | ✓ | ✓ |
| AVG Cloud Management Console | ✓ | ✓ |
| EDR and patch management | ✕ | ✕ |
This is a Windows-only product: AVG lists Windows 10 Pro, Education and Enterprise and Windows 11 for workstations, and Windows Server 2025, 2022, 2019, 2016 and 2012 excluding Server Core for servers, with Exchange Server 2019 to 2010 SP2 and SharePoint Server 2019 to 2010 for the server components. There is no agent for macOS, Linux, Android or iOS, and Windows 11 in S mode and Windows running on ARM processors are excluded, so mixed fleets need a second product. On regional availability, the product is sold across Switzerland and the European Union with localised pages, but AVG states business support as 24/5 in English only, which means no German-language or French-language business support line and no weekend cover, and that is worth weighing if your IT is outsourced or you have no in-house administrator. The limitations that most often trigger a follow-up purchase are the absence of any EDR component anywhere in the AVG business range, patch management being a separately sold AVG product, and the absence of backup and encryption management. Consider also that the AVG Cloud Management Console is a cloud service, so if your policy requires management data to stay on your own infrastructure you need AVG's on-premise console instead.
AVG lists the Cloud Management Console as part of both business editions, so central deployment, policy management and threat monitoring are included rather than sold separately. AVG also documents an on-premise console as an alternative for organisations that prefer to host the management server themselves, and the two consoles cannot be installed on the same machine.
Yes. Exchange Server Protection scans messages and attachments on supported Exchange versions, while SharePoint Server Protection scans content uploaded to and downloaded from SharePoint, and both are managed from the same console as the workstation agents. For file servers that are plain Windows file shares rather than SharePoint, AVG positions its separate File Server Business Edition.
The business edition adds the components a company needs and a household does not: central remote deployment and policy enforcement through a management console, Exchange Server Protection, and SharePoint Server Protection. The consumer product has no management console, so every device would have to be configured and checked individually.
Centrally managed Windows endpoint protection with Exchange and SharePoint server scanning. No EDR, no patch management, no Mac or Linux agent.
AVG Internet Security Business Edition, AVG, Avast, Gen Digital, business antivirus, endpoint protection, exchange server protection, sharepoint protection, firewall, cloud management console
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies