How to maximize internet security?

Hi All,

 

I'm building a new Win7 64-bit graphics workstation. I'm thinking of installing Windows Virtual PC and doing most of my e-mail and internet browsing in Windows XP Mode. Except for updates I would mostly keep the Win7 installation disconnected from the internet. I know I would need to install NIS twice.

 

If I did this and contracted malware in the virtualized XP mode side (NIS's defenses get penetrated), would it/could it (malware) also infect the Win7 installation?