What are the core benefits of Norton Small Business?
Account managed – One owner invites users, no policy console.
Device Security – Real-time antivirus and firewall for Windows, Mac.
Platform coverage – Windows, Mac, Android and iOS endpoints, no servers.
Cloud Backup – 500 GB with Premium, Windows and owner only.
Included tools – Password manager, VPN and Windows software updater.
Important note – No central reporting or EDR for audits.
Download: Norton by Symantec Small Business
Device Security – Real-time antivirus plus firewall on Windows and Mac.
Cloud Backup – Windows only, account owner only, 500 GB with Premium.
Password Manager – Encrypted vault per employee for credentials and cards.
Norton VPN – Encrypted connection on untrusted Wi-Fi, Premium plans only.
Software Updater – Keeps Windows applications patched against known exploitable gaps.
Important – No central policy console; owner invites users and manages installs.
Norton Small Business is a subscription endpoint suite for Windows, Mac, Android and iOS, built on the Norton 360 consumer stack and sold by Gen Digital. It is managed from a single Norton account in which one account owner invites employees and manages installs; the retail name Norton by Symantec Small Business is legacy branding, because the Symantec brand passed to Broadcom in November 2019 while the small business line stayed with the consumer arm and was relaunched in 2023.
No console overhead – Nothing to install, configure or maintain centrally.
One subscription, four platforms – Covers Windows, Mac, Android and iOS from one account.
Employee settings locked – Users cannot disable firewall or antivirus settings themselves.
Ransomware fallback – Cloud Backup restores Windows files after encryption or theft.
Patch gap closing – Software Updater keeps third-party Windows applications current.
Proven detection engine – Built on the Norton 360 consumer protection stack.
The product is built for owner-operated companies without IT staff, typically under ten employees. The decisive limit is not the number of devices but the absence of central policy enforcement and reporting: once a company has to prove to an auditor or a customer that a rule is applied on every device, an account with an invitation list is no longer sufficient.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Central policy enforcement and evidence reporting | Optional | ✓ | ✓ |
| This product fits | ✓ | ✕ | ✕ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, and it is triggered by sector rather than by headcount. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the incident must first be detected, then described well enough to file. Norton Small Business supports the detection half only: Device Security blocks and logs malware on the individual endpoint, and the account owner sees device status in the Norton account. It does not support the reporting half, because there is no central log retention, no syslog or SIEM export, no attack timeline and no root-cause view that could be attached to a report. An affected operator therefore still needs a separate mechanism to collect and preserve incident evidence. This is not legal advice; whether your company falls under the reporting obligation should be clarified with your legal department or a specialised lawyer.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management rather than the presence of a specific tool. NIS 2 requires categories of measure including risk analysis and security policies, incident handling, business continuity and backup management, supply chain security, cyber hygiene, access control, and the use of cryptography and multi-factor authentication. Norton Small Business contributes to two of these: cyber hygiene, through endpoint malware protection and third-party patching on Windows, and business continuity, through Cloud Backup on Windows PCs. It contributes nothing to incident handling workflow, supply chain security, access control and asset management, or the policy documentation that has to accompany them. Multi-factor authentication for company systems is also outside its scope, since the Password Manager stores credentials but does not act as an identity provider.
Partly, and it is worth knowing in advance which lines you can tick and which you cannot. It answers: endpoint anti-malware deployed on all company Windows, Mac, Android and iOS devices; host firewall on Windows and Mac; encrypted credential storage for employees; third-party application patching on Windows; and backup of business-critical files, with 500 GB of cloud storage on the Premium plan. It does not answer: centrally enforced and documented security policy, because settings are configured per device; centralised logging and log retention; endpoint detection and response or managed monitoring; disk encryption management; mobile device management and remote wipe; server and mailbox protection; multi-factor authentication or single sign-on; and audit-ready reporting, since the Norton account shows current device status rather than a historical record you can export as evidence. To close those gaps, note that Norton's small business family has no higher edition with a management console, so upgrading within the family does not help here. A company that regularly receives these questionnaires is usually better served by moving the endpoint layer to a business platform that includes a console and exportable reporting, and keeping Norton only where consumer-grade coverage on personal or unmanaged devices is genuinely enough.
The decisive difference is not the antivirus engine, which is identical, but the additional services layered on top: Norton VPN and Driver Updater are Premium-only, and Premium is the plan that carries the 500 GB cloud storage entitlement. Premium also adds Business Tech Support and the monitoring services, but several of those are geographically restricted and are worth checking against your own location before you weigh them. Neither edition includes a central management console, endpoint detection and response, or server protection, so the choice between them does not change the management model. If you only need protection on employee devices, the base edition already covers it; the case for Premium rests on the backup quota, the VPN and the support entitlement.
| Component | Norton Small Business | Norton Small Business Premium |
|---|---|---|
| Device Security and firewall | ✓ | ✓ |
| Password Manager and Secure Browser | ✓ | ✓ |
| Cloud Backup, Windows and owner only | Included | 500 GB |
| Norton VPN | ✕ | ✓ |
| Driver Updater | ✕ | ✓ |
| Business Tech Support, five sessions | ✕ | US and UK only |
| Financial and Social Media Monitoring | ✕ | US and UK only |
| Central management console | ✕ | ✕ |
The most important one is regional: according to Norton's own support documentation, Norton Small Business is offered only in the United States, the United Kingdom, Australia, New Zealand, Canada, Japan and some Latin American countries. Switzerland and the European Union are not on that list, so entitlements, support language and feature availability may differ from what the manufacturer's pages describe, and Financial Monitoring, Social Media Monitoring and Business Tech Support are limited to the US and UK in any case. On platform coverage, there is no protection for Windows Server, Linux, mail servers or hypervisors, so a company running a file server or an on-premises Exchange server needs a second product for it. Within the client platforms the coverage is also uneven: Cloud Backup runs on Windows PCs only and is reserved for the account owner, the firewall is not available on Android, and SafeCam is unsupported on macOS. The gaps that most often trigger a follow-up purchase are disk encryption management, mobile device management, and any form of centralised reporting for audits or customer questionnaires.
No, and they are not even sold by the same company. Broadcom acquired Symantec's enterprise security business including the Symantec brand in November 2019, so Symantec Endpoint Protection is a Broadcom product, while Norton Small Business belongs to Gen Digital. If a tender or supplier list names Symantec Endpoint Protection specifically, Norton Small Business does not satisfy it.
No. The account structure has exactly two roles, account owner and user, and it assumes a single business managing its own devices. There is no tenant separation, no consolidated view across customers and no API for scripted remediation, so managed service providers need a product built for the partner channel instead.
The account owner manages installs from the Norton account and can remove a device to free the entitlement for someone else. Note that the departing employee's Password Manager vault is personal to them, so credentials for shared company accounts should be rotated separately rather than assumed to be recoverable through the Norton account.