The Era When Computer Viruses Were Everywhere
When I first started using computers, we were still living through the eras of DOS, Windows 95, Windows 98, Windows Millennium, Windows 2000, and eventually Windows XP.
At that time, almost every computer user experienced a virus infection. Computers would suddenly slow down, files would disappear, browsers would be hijacked, and sometimes the entire operating system had to be reinstalled.
The one I remember most clearly was the ILOVEYOU virus, which appeared in 2000. Disguised as an email carrying the subject line “ILOVEYOU,” it persuaded recipients to open an attachment before spreading rapidly through their contact lists.
Technically, it was a computer worm rather than a conventional virus. Within a very short time, it affected millions of computers worldwide and made the world realise something important: the more widely a technology is adopted, the greater the potential damage caused by even a small weakness in its foundation. Source: EBSCO, “ILOVEYOU Virus Attacks Computers.”
How Much Has Microsoft Spent Protecting Windows?
As Windows became one of the world’s most widely used operating systems for individuals and businesses, it naturally became one of the most valuable targets for attackers.
Microsoft does not only have to protect its operating system. It must also consider different computer brands, enterprise systems, legacy software, hardware drivers, third-party applications, and decades of compatibility requirements.
We have all encountered Windows security updates and software patches. Sometimes, just as we are preparing to shut down the computer, Windows begins installing an update and asks us to wait. From a user’s perspective, this can be frustrating. From a security perspective, however, it represents a battle that never truly ends.
Microsoft previously announced a US$20 billion investment over five years to advance cybersecurity. Its published materials also indicated that the company was investing more than US$1 billion annually in security, data protection, and risk management. These figures demonstrate how expensive it is to protect a large, open ecosystem that must continue supporting countless legacy systems. Source: Microsoft’s Cybersecurity Investment; Microsoft Cyber Defense Operations Center.
This does not necessarily mean that Windows was built on a weaker foundation. Windows faces more attacks partly because of its enormous user base, complex operating environments, and obligation to support a vast range of enterprise systems and third-party hardware and software. For cybercriminals, attacking a platform with a larger market share can offer a much greater return.
Why Do Many Mac Users Not Install Antivirus Software?
Many years later, I started using a MacBook. I noticed that many Mac users did not install separate antivirus software, yet their computers continued operating normally. Like many people, I wondered whether Macs simply could not get viruses.
Strictly speaking, that is incorrect.
macOS can still be affected by malware, ransomware, phishing, and system vulnerabilities. The difference is that Apple has integrated many protective mechanisms directly into the operating system, so users may not even notice that these protections are running.
macOS includes technologies such as XProtect, Gatekeeper, and App Notarization. Gatekeeper checks whether software comes from an identified developer, has been notarised by Apple, and has not been altered. XProtect is Apple’s built-in anti-malware technology, designed to detect, block, and remove known threats.
Apple organises its malware defence into three layers: preventing malicious software from launching, blocking it from running, and remediating it if it has already been executed. Source: Apple, “Protecting Against Malware in macOS”; Apple, “Gatekeeper and Runtime Protection.”
Apple has therefore not avoided spending money on security. A more accurate explanation is that Apple has placed much of that investment into its underlying architecture, hardware-software integration, application review process, permission controls, and automatic updates.
The fact that users do not install antivirus software themselves does not mean that there is no major security investment behind the system.
Apple also maintains greater control over its hardware and software ecosystem. It can determine which devices run macOS, how applications access system resources, and which security policies are enabled by default. This controlled environment reduces some complexity.
However, Apple’s approach cannot simply be copied and applied to Windows because the two platforms serve different markets and carry different compatibility responsibilities.
Will AI Cause Computer Viruses to Decline?
As we enter the AI era, I initially had a thought: if AI can automatically detect unusual activity, analyse malicious code, predict attack patterns, and allow firewalls to respond automatically, will traditional computer viruses gradually decline?
Part of this observation is correct.
AI can help security teams identify threats more quickly, detect phishing messages, close detection gaps, and respond at machine speed. Microsoft is already developing AI security systems designed to turn threat signals into real-time protection. Source: Microsoft, “Rethinking Security for the Age of AI.”
However, we cannot conclude that viruses will disappear simply because AI has arrived. Defenders can use AI, but attackers can use it too.
Cybercriminals can use AI to search for vulnerabilities, generate malicious code, create more convincing scam messages, and attack many more targets simultaneously. Microsoft’s security research also warns that AI adoption benefits both defenders and threat actors. Source: Microsoft Digital Defense Report 2025.
What may decline is the visible experience we once described as “my computer has caught a virus.” What may increase instead are less visible threats: identity theft, data theft, ransomware, supply-chain attacks, manipulated AI agents, and scams designed to exploit human behaviour.
Viruses may not disappear. They may simply evolve into different forms.
Was Microsoft’s Past Security Investment Wasted?
If AI can eventually automate a large part of cybersecurity work, does that mean the money, manpower, and time Microsoft invested in the past have all gone to waste?
My answer is no.
Those investments created the vulnerability databases, threat intelligence, authentication systems, security standards, update infrastructure, and defensive experience that we rely on today.
Without that foundation, AI would not have enough reliable information or established rules to distinguish normal behaviour from a genuine threat. AI is not a security expert that suddenly appeared from nowhere. Its capabilities are built upon decades of knowledge accumulated by people and organisations.
What may become obsolete is not the previous investment in security, but some of the repetitive ways security work was performed.
Security professionals may no longer need to inspect every alert manually. However, they will still be needed to design policies, supervise AI, make high-risk decisions, and ensure that the automated security systems themselves are not compromised.
Microsoft’s recent direction is also not limited to using AI to patch vulnerabilities. It has renewed its emphasis on Secure by Design, Secure by Default, and Secure Operations—placing security at the centre of design, default configurations, and everyday operations.
This tells us that even with powerful AI, everything eventually comes back to the quality of the foundation. Source: Microsoft Secure Future Initiative.
What the AI Era Has Truly Taught Me
This article is not written to criticise Microsoft or to prove that Apple is necessarily better.
It is simply a reflection from someone who lived through the eras of DOS, Windows 95, Windows 98, Windows Millennium, Windows 2000, and Windows XP—and who is now observing how computer viruses, security updates, and cyber defence are evolving in the AI era.
Different operating systems carry different historical responsibilities, user bases, levels of ecosystem openness, and security risks. We cannot judge the quality of a technology simply by asking which platform appears to suffer fewer virus infections.
However, this history has given me one important insight:
The foundation is the most important part of any good system.
If the architecture is unclear, permissions are poorly designed, data is disorganised, and responsibilities are not properly assigned, even the most advanced technology will spend its life repairing gaps.
Every time the world changes, the organisation will need more technical people, more knowledge, and more money just to keep compensating for a foundation that was never properly established.
Today, this principle does not apply only to operating systems. It applies to every organisation preparing to implement AI.
AI can help us move faster. But if our foundation and direction are wrong, it will also help us create problems at a much greater speed.
In the AI era, true competitiveness will not be determined by how many tools we own, how many technical people we employ, or how much security software we install. It will depend on whether we have designed the right architecture, governance, permissions, and accountability from the very beginning.
Technology will continue to change. Threats will continue to evolve.
But a strong foundation will never become obsolete.
























