I totally Agree with Samker,
MC AV with MC Firewall, as long as it's set up properly "Access Protection" then you should find that even if something does attack the system it cant write itself anywhere or is allowed to run. i.e dont allow things to run from the TEMP directory!!
If you have a program that needs a temp space to write too then set one up dedicated to that program I used to have to do this all the time, I even locked the Temp Directory down to the program's .EXE in the early days and this allowed me to catch a couple of inderviduals looking to try and tunell through the network by running Putty type tools e.t.c from that Temp directory.
This was all befor we locked down Peripherals e.t.c so now I dont have to worry so much. : ) But like Samker said is someone trying to circumvent your security measure's e.t.c you really need to probe this more.
Take Samker's advice lock your system down properly and you should be fine, For a little extra protection get you company to pay for the SPYWARE module thats available for MC VirusScan, I have used it on both 8.5 and 8.7 with moderate success.
Long and Short of it, Nothing is 100%, Take a continual pro-active approach to your networks security by testing out other products in a "Test" Enviroment Inc things like Malware bytes - Im sure you can get a corp version???
Regards
HD