We aren't just scanning for binary code inside an executable anymore. The bad code could be hidden in a password-protected Zip file or encrypted in SMIME [Secure MIME]. These are things we can't even scan.

We are considering doing virus scanning on all incoming e-mail.

It is expensive, it creates a bottleneck at the mail server, and it isn't clear that such a scan will be all that effective.

It takes time to download the new fixes to each desktop.