Although I don't have any experience with ESET Endpoints Products, I use ESET IS on my Gaming PC and in default settings, it won't be enough to stop my cousins from getting infected. I can train the HIPS and FW for 1 month using Learning Mode and then switch them to Interactive like I did on my Gaming PC but I'm sure that during the 1 month training time, the PC will get infected.In light of your daily complex tasks, you may need to consider the followings:
(1) Try ESET endpoint antivirus---much less noisy than SEP and KIS. That means fewer popup, user interactions.
(2) to completely LOCK UP system---you may consider Voodoo Shield.
(3) to take the steps that Umbra has suggested in # 11.