In this guide
Appearance
Appearance
By Scot, 10+ years in IT support and helpdesk ·How these guides are checked
Macs are resistant, not immune. Gatekeeper and XProtect block most malware outright, so attackers target the person instead — phishing, fake installers from search ads, hijacked extensions, and scareware pop-ups all need you to approve something. The real prize is your Microsoft 365 account.
Checked against Microsoft Learn - end of support and retirement, Google Chrome Releases and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.
"Macs don't get viruses" is the most durable belief in personal computing, and it was defensible for a long stretch. This article explains where it came from, gives macOS full credit for the defences it genuinely has, and then sets out what actually reaches Mac users at work today — which turns out to have very little to do with viruses.
In this guide
This myth persisted for two decades because for much of that time it described reality accurately.
Two of those three things have changed. Mac market share in business has grown substantially, particularly in technology, design, and executive teams, which are exactly the accounts an attacker wants. And Windows closed most of the gap: modern Windows is a far harder target than the Windows that earned the comparison.
What has not changed is that the underlying claim was always about likelihood, never about immunity. Those are different statements, and the difference is where people get caught.
Any honest version of this article has to give Apple credit, because the built-in defences are strong and most Mac users have never had to think about them.
"App" can't be opened because Apple cannot check it for malicious software. Nothing runs by accident.That is a genuinely good stack, and it is the reason the answer to "is my Mac safe?" is closer to yes than to no. It is also the reason attackers stopped attacking the operating system.
When the software is hard to break, the person becomes the way in. Nearly everything that lands on a Mac now arrives because someone was persuaded to approve it.
Notice what every item on that list has in common: each one needs a person to click, approve, or type a password. That is not a weakness in macOS. It is what an attacker does when the software gives them nothing.
This is the point the myth costs people most, so it is worth stating on its own.
The valuable thing on your desk is not the laptop. It is your Microsoft 365 or Google account — the mailbox, the files, the ability to send messages that colleagues trust. That account is reached through a browser, over the web, from anywhere. The operating system is not part of the transaction.
A Mac gives you a more resistant computer. It gives you no additional protection at all on the attack that is actually being used against your organisation this week.
None of this requires security software you have to think about. It requires six habits.
Note: If you are the only Mac user on a Windows team, several of the instructions IT sends out will not match your screen. What to Do When You're Assigned a Mac at a Windows Company covers translating them.
Finding an endpoint agent installed on a company Mac surprises people who have read this far and concluded macOS handles it. Three reasons, none of them distrust of Apple.
The agent normally needs Full Disk Access and a system extension approved once, in System Settings > Privacy & Security. Those prompts are expected on a managed Mac. If one gets stuck or reappears every time you log in, send IT this: "The endpoint agent on my Mac keeps asking for approval and does not stay approved. Please send me the exact profile name and the panel to approve it in, or push the approval through device management."
WARNING
Two actions do more damage on a Mac than everything else combined: typing your Mac password into a prompt you did not trigger, and right-clicking Open to defeat a Gatekeeper block on software that arrived from a search ad, a pop-up, or a link. Current Mac malware depends on a person performing one of those two steps, because macOS will not perform either on its own. Declining both is most of your protection.
| Situation | What is really going on | What to do |
|---|---|---|
| A full-screen page says your Mac is infected | Scareware web page, not a macOS message | Press Command + W to close the tab. If the page blocks that, press Option + Command + Escape, select the browser, and click Force Quit. Reopen without restoring tabs. Never call the number. |
Apple cannot check it for malicious software | Gatekeeper blocked an app that is not notarized | Expected for software from outside the App Store. Override it only for software you deliberately sought from the vendor's own site. For a work tool, tell IT: "Please approve this app for managed Macs — it is blocked by Gatekeeper as unnotarized." |
| Your browser homepage and search engine changed on their own | Malicious extension or configuration profile | Remove unknown items from System Settings > General > Device Management, then review your browser extensions and remove anything you did not install deliberately. |
| A password prompt appeared with nothing running | Something is requesting administrator rights in the background | Click Cancel. Then check System Settings > General > Login Items & Extensions for an item that added itself, and remove it. |
| IT installed security software and the Mac feels slower | Endpoint agent performing its first full scan | Initial scans are heavy and settle within a day. If it is still slow afterwards, tell IT: "The endpoint agent is holding high CPU on my Mac after the initial scan — please check the exclusion policy for my device." |
| You think you already entered your password into something fake | Credentials possibly captured | Change your work password immediately from a different device, then check your recent sign-in activity and report it. Treat browser-saved passwords for other sites as exposed too. |
IT Tip Tuesday
Get a short, actionable IT tip in your inbox every week.
Nothing loads from beehiiv until you click. Once it does, the form sets beehiiv's own cookies and loads beehiiv's own analytics.