I'd usually explicitly disable Office macros, as those tend to be the biggest source of "fun" with Office documents.
Enable those macros only as and when and if you need them, and be skeptical about macros in documents from untrusted sources.
As for security, a Mac running macOS has built-in anti-malware including a built-in malware scanner and removal tool, as well as the signed system volume, gatekeeper and notarization, the app store, and other related mechanisms.
While not completely immune to malware (nothing useful is), installing malware usually requires the user to perform explicit overrides. Coupon apps and cracked apps and adware tend to be the common annoyances.
And some of the better known add-on anti-malware has been caught (and fined for) selling personally-identified browser history and web-purchasing history data.