Do remember though that even the sort of industrial strength AV that the IT people at the company I worked for cannot prevent a user from clicking on a link in phishing scam:
https://www.ncsc.gov.uk/collection/phishing-scams
and thus shooting themselves in the foot.
Consequently,
all employees where I worked, from the CEO at the top to the newest recruit , including
all of the IT people actually running the IT systems, had to complete several IT security training courses annually, i.e
every year. These courses were different every year so you couldn't just rehash last year's answers. If you failed the course you had to retake it, and the questions changed. If you forgot to do the course before the annual deadline you were locked out of the IT systems until you sat the course (and your line manager was notified!)
To put it another way, a chain is only as strong as it's weakest link and in IT security a human being is invariably the weakest link.
Ken