You have been told, repeatedly and from every direction, that your computer is defenceless without protection. The pop-up on the news site says so. The browser extension that promises to keep you safe says so. The comparison article ranking above this one says so, then lists its top three picks with discount codes attached. Meanwhile, the machine in front of you almost certainly shipped with security software already installed, already running, updating itself quietly in the background — and nobody selling anything has much reason to mention that.

This site sells no software. We do not make antivirus products, we are not paid to recommend them, we earn no commission if you buy one, and there is not a single product link in this article. Weigh that against the other pages you have read on this question. Almost every one was published by a company that sells antivirus software, or by an affiliate site earning money when you click through and subscribe. Those pages are not necessarily dishonest. But they all reach the same conclusion, and they all have a reason to.

Here is the short version. For most people using a modern, updated Windows computer, the protection built into the operating system is already sufficient, and a paid product adds little. And more importantly: the thing most likely to hurt you is not a virus at all.

What does antivirus software actually do?

Strip away the marketing and antivirus software does two main things.

The first is signature matching. Every known piece of malicious software has identifiable characteristics — a distinctive pattern in its code, a particular file fingerprint. The antivirus keeps a database of these signatures and compares files on your machine against it. This works extremely well for threats already catalogued, and not at all for anything genuinely new, because a signature can only be written after someone has found and analysed the thing.

The second is behavioural detection, sometimes dressed up as heuristics or machine learning. Rather than asking “have I seen this exact file before?”, it asks “is this program doing something programs shouldn’t?” An application that starts encrypting your photo library at speed gets flagged on its behaviour rather than its identity. This catches more novel threats than signatures do, but it is a judgement call, and judgement calls go both ways: false alarms on legitimate software, and evasion by malicious software that moves slowly and looks ordinary.

So neither approach reliably catches something genuinely new. This is not a flaw in any particular product; it is the nature of the problem. Anyone claiming otherwise is selling.

Is the protection built into Windows good enough?

For most people, yes.

Windows has included capable, always-on antivirus for many years now. It is enabled by default on a new machine. It updates its definitions automatically through the ordinary update system. It performs both signature-based and behavioural scanning, it includes ransomware protections, it filters known-malicious downloads and websites at the browser level, and it participates in the same industry testing that third-party products do — where it has for years placed comfortably among them rather than trailing behind.

Let me be careful not to overclaim. It is not magic. It will not stop everything. It does not have every feature that a paid suite advertises. If you turn it off, or if you install a third-party product, Windows steps aside and the built-in protection stops being your defence. And there are specific situations — covered further down — where something more is genuinely warranted.

But the ordinary case is this: a person with an updated Windows machine, browsing normally, is already protected to roughly the standard a consumer paid product would provide. Enormous numbers of people are paying an annual subscription for something they already have and did not know they had. That is the single most useful fact in this article.

Worth checking rather than assuming: open your security settings and confirm the built-in protection is on and current. It sometimes gets switched off by a preinstalled trial that later expired — leaving an inactive paid product and a disabled free one. That is a bad state to be in, and a common one.

What about Macs and Linux machines?

The old line was that Macs do not get viruses. That was never quite true, and it is less true now. What is accurate is that Macs are targeted less, for reasons that are mostly commercial rather than magical: the installed base is smaller, so the return on writing something that only works on macOS is lower. Where a platform’s share grows, attention follows.

macOS does have real structural defences — applications are checked against Apple’s records before they run, unsigned software is blocked by default, and the system restricts what programs can reach without explicit permission. These help substantially. But the biggest risk on a Mac is usually not a technical compromise at all. It is the user installing something they were persuaded to install. A fake update prompt, a “your Mac is infected, download this cleaner” page, a pirated application with something extra inside. The security model is bypassed entirely when the owner clicks through the warnings themselves, because from the system’s point of view, that is a person exercising legitimate authority over their own machine.

Linux is similar but more so: less targeted on the desktop, with a culture in which most software arrives from vetted repositories rather than random downloads. For a desktop Linux user installing from those repositories, antivirus is rarely the useful next step.

Do phones need antivirus apps?

Largely, no — and this is the part most articles skip.

Phone operating systems are built around sandboxing: each app runs in its own sealed compartment and cannot read other apps’ data or inspect the wider system unless explicitly permitted. This is excellent for security. It also means a mobile “antivirus” app is trapped in the same box as everything else: it cannot scan your other apps or inspect system memory, because the platform is deliberately designed to prevent any app doing that.

So what do they do? Usually check installed app names against a list, scan links you hand them, and bundle peripheral features — a VPN, a junk cleaner, a breach alert. Some of that has value. None of it is antivirus in any meaningful sense. On iOS especially, where sideloading is restricted and app review filters heavily, the category is close to pure theatre.

What actually matters on a phone:

  • App permissions. A torch app requesting your contacts and location is the real threat model. Review what your apps can access, and revoke what does not make sense.
  • Where apps come from. Sideloading — installing from outside the official store — is where genuine Android malware lives, almost without exception.
  • Links and messages. The overwhelming majority of phone-based harm arrives as a message asking you to log in somewhere, pay something, or approve a code.
  • Keeping the phone updated, and knowing when it stops receiving updates.

What actually goes wrong for ordinary people?

This is the section that matters most, and it is why the standard advice has drifted out of date.

The classic threat model — a virus in an infected file, spreading from machine to machine — was the dominant risk in an era of shared floppy disks and software downloaded from anywhere. It still exists, but it is no longer where most harm to ordinary people comes from. What harms people now is overwhelmingly deception, not infection. And antivirus software addresses very little of it, for a simple structural reason: the user is being persuaded rather than compromised. Every action taken is technically legitimate. There is nothing for a scanner to detect.

Consider what this looks like in practice:

  • Phishing and credential theft. A convincing email or message leads to a convincing login page, and the password is typed in voluntarily. No malicious file exists. The password now belongs to someone else. Browser and email filters catch a lot of this; antivirus scanning does not, because there is nothing to scan.
  • Fake support calls. Someone phones claiming to be from a technology company, a bank, or an internet provider, and talks the person into installing remote-access software — legitimate remote-access software, the same kind an IT department uses. The antivirus does not object, because the software is not malicious and the user approved it.
  • Account takeover. A password reused across sites is exposed in one breach and then used to open every other account it unlocks. This happens entirely on other people’s servers. Your computer’s condition is irrelevant.
  • Malicious browser extensions. Extensions run inside the browser with broad access to what you see and type. Some start out benign, gain a user base, then get sold or updated into something that harvests data. Antivirus generally does not police what runs inside your browser.
  • Scam payment requests. A fake invoice, a redirected bank transfer, a marketplace buyer with a story, an investment that pays out until it doesn’t. Every one of these is a person making a voluntary payment. There is no software involved to detect.

Look at that list and ask honestly how much of it any antivirus product could have stopped. The answer is: a slice of the first item, and almost nothing else.

This is not an argument that security does not matter. It matters enormously. It is an argument that the money and attention are going to the wrong place. If you are worried about staying safe online, the highest-value thing you can do is understand how scams actually work now — because the old tells, the typos and the crude formatting, have largely stopped being reliable signals.

What do paid antivirus suites actually add?

Being fair to the category: some of what paid products offer is real. It is worth separating that from the padding.

Genuinely useful, in the right circumstances:

  • Centralised management across many devices. If you are responsible for a household or a small business with a dozen machines, being able to see and control all of them from one place has real value.
  • Parental controls and content filtering. Built-in options exist but third-party ones are often more capable.
  • Stronger anti-phishing and link filtering. Some products do add meaningful protection at the browser layer, above what is already there.
  • Support you can telephone. Undervalued. For someone who is not confident with computers, a human to call when something looks wrong is worth paying for on its own.

Mostly padding:

  • “System optimisers”, registry cleaners and junk removers. Negligible benefit on modern hardware, and occasionally the cause of problems.
  • Bundled VPNs. Often limited, and typically included to inflate the feature list rather than because you need one. Whether you need a VPN at all is a separate question, and the honest answer is narrower than the advertising suggests — see whether you need a VPN.
  • Bundled password managers. Fine as far as they go, but tying your passwords to an antivirus subscription creates an awkward dependency. The category is worth understanding on its own terms; we looked at whether password managers are safe separately.
  • “Identity protection” and dark-web monitoring. Usually amounts to telling you that an address of yours appeared in a breach — which free services also do, and which you can rarely act on beyond changing a password you should change anyway.

The reason suites are packaged this way is straightforward. Core antivirus is now a commodity the operating system gives away, and selling a subscription requires a longer feature list than the free option.

If a product is free, how does the company make money?

This is a fair question to ask of any free product from a large company, and not a conspiratorial one. Software costs money to build; companies employing hundreds of people have revenue coming from somewhere.

For free antivirus, the usual answers are: upselling to a paid tier, bundling other companies’ software into the installer, advertising within the product, and — historically, and this is documented rather than speculative — collecting and monetising user browsing data. Security software is unusually well positioned to do this, because it legitimately needs deep visibility into what you do and where you go in order to function. That same access makes an attractive data product.

There have been real regulatory and journalistic findings in this industry on exactly this point. No companies are named here, because the principle outlasts the specifics: be more sceptical of free security software than of free software in general, precisely because of what it is permitted to see.

The built-in Windows protection sits outside this dynamic in a useful way. It exists because the operating system’s reputation suffers when machines get compromised. The commercial motive is aligned with yours.

Can installing security software make things worse?

Yes, sometimes, and this deserves stating plainly because it is rarely acknowledged.

Performance. Real-time scanning inspects files as they are opened, written and executed, and that costs something. On a fast machine it is often unnoticeable; on an older one it can be very noticeable indeed, particularly during scans.

Conflicts. Two security products on one machine is a classic cause of instability — each treating the other’s activity as suspicious. Products also interfere with legitimate software, block updates, break network configurations and quarantine files that were perfectly fine.

The product is itself software. This is the point people miss. Antivirus runs with the deepest possible privileges — it has to, in order to inspect everything — which makes it an unusually valuable target, and security software has had serious vulnerabilities found in it, including flaws where the protective component became the way in. Adding another privileged program enlarges the surface an attacker can aim at. It may still be worth it, but it is a trade, not a free gain.

Who genuinely should run something extra?

Plenty of people, and this is where the article stops being a case against the category.

  • Anyone whose work makes them a target — journalists, activists, people handling substantial financial transactions, anyone with access to systems that would be valuable to compromise. Different threat model entirely, and worth layered defences.
  • Shared and family machines, especially those used by children or by relatives who are not confident with computers. Extra guardrails on a machine used by many people are sensible, and the management and filtering features earn their place.
  • Anyone who has been caught out more than once. If you or someone you help has already installed something they shouldn’t have, or been talked into something on the phone, additional friction has demonstrated value.
  • Unsupported or old systems. More on this below.
  • Businesses with regulatory or contractual obligations. If your insurer, client contract or industry regulator requires an endpoint security product, the debate is over. Buy the product. Compliance is a legitimate reason.

What actually protects you, in priority order?

Being direct: every item on this list matters more than which antivirus you choose. If you did all of these and ran nothing but the built-in protection, you would be safer than someone who bought a premium suite and did none of them.

  1. Keep the operating system and browser updated. Not exciting, comfortably the highest-value action. Most successful attacks exploit flaws that were fixed months ago on machines that never applied the fix. Turn on automatic updates and let them run.
  2. Use a unique password for every account, kept in a password manager. Password reuse turns one breach anywhere into a compromise everywhere. This single change eliminates an entire category of harm.
  3. Turn on two-factor authentication for accounts that matter — email first, because email is the key that resets everything else, then banking, then anything holding payment details. An app-based code or a hardware key beats an SMS, though SMS is far better than nothing.
  4. Keep backups, and keep one of them disconnected. This is the honest answer to ransomware. Detection can fail; a recent backup means the attack is an inconvenience rather than a catastrophe. It also protects against the far more common disasters — drive failure, theft, spilt coffee.
  5. Be sceptical of anything that arrives asking you to act. Unexpected links, urgent messages, phone calls claiming to be from your bank. Hang up and call back on a number you looked up yourself. Urgency is the common thread in nearly every successful scam, because it is what stops people checking.
  6. Install software only from legitimate sources — official app stores, the developer’s actual website reached by typing the address, your distribution’s repositories. Not from a search advert, not from a download portal, not from a pop-up telling you your player is out of date.

What should you do if you think you are already infected?

Calmly, and without buying anything.

  1. Disconnect from the internet if you suspect something active — unplug the cable or turn off the Wi-Fi. This limits both data leaving and instructions arriving.
  2. Run a full scan with the protection you already have. Windows’ built-in tool includes an offline scan option that runs before the system fully starts, which catches things that hide during normal operation.
  3. Change important passwords from a different, trusted device. Changing them on a compromised machine simply hands over the new ones. Start with email.
  4. Check for unfamiliar programs, browser extensions and startup items, and remove what you do not recognise and cannot account for.
  5. Review account activity — email forwarding rules and unauthorised recovery addresses are favourite hiding places. Check bank and card statements.
  6. If it is serious, reinstall the operating system. Unglamorous, and the only method that offers genuine certainty. With backups in place it is a slow afternoon rather than a disaster.
  7. If money is involved, contact your bank immediately and report it to your national fraud reporting body. Speed matters here more than anywhere else.

Be wary of anything that finds you during this process. Search results for cleanup tools and “support” numbers are a well-known hunting ground for the same people who caused the problem. And treat any page or pop-up that tells you that you are infected as a scam by default — a web page cannot scan your computer, so it cannot know.

What about a computer that no longer gets updates?

This is the genuinely serious risk that almost nobody discusses, and it is the one case where the calm tone in this article should sharpen.

When an operating system reaches end of support, it stops receiving security fixes. Flaws found after that date are never patched — and they are found, and they are published, and they remain exploitable forever. The machine does not fail suddenly. It quietly becomes more vulnerable every month, permanently.

Antivirus software helps here more than it helps on a supported system, because there is a real gap for it to partially fill. But it cannot patch a hole in the operating system itself. It is a mitigation, not a fix. If you are running an unsupported system:

  • Upgrade if the hardware allows it. This is the actual answer.
  • If it does not, a lightweight Linux distribution will often revive old hardware for ordinary browsing, and will keep receiving updates.
  • If the machine must stay as it is for a specific piece of software, take it off the internet entirely, or restrict it to a network segment that cannot reach anything important.
  • If it must remain online, then yes — run additional protection, and stop using it for banking, email or anything you would mind losing.

The same applies to phones that have stopped receiving updates, and to routers, which are frequently years past support and rarely thought about at all.

So what is the honest answer?

If you are on a modern Windows machine that receives updates, the built-in protection is running, and you are not in one of the higher-risk groups above, you do not need to buy antivirus software. You already have adequate protection. Spend nothing, and spend the attention instead on updates, unique passwords, two-factor authentication, backups, and a healthy scepticism about anything urgent that arrives unbidden.

Antivirus is not a scam. It is a legitimate technology that does a real job — and one that is heavily oversold to consumers who already have what they need, while the threats that actually reach them have moved somewhere it cannot follow.

The National Cyber Security Centre and CISA both publish security guidance with no product attached, which makes them a fair check on anything said here.

The NCSC keeps a plain home-user checklist at Cyber Aware.

Frequently asked questions

Will Windows turn its built-in protection back on if my paid subscription expires?

Generally yes — Windows steps aside when a third-party product registers itself and resumes when that product goes inactive. But do not assume it. Open your security settings and confirm real-time protection is on and definitions current. An expired trial that never deregistered leaves a machine unprotected while appearing covered.

Can I run two antivirus programs for extra safety?

Don’t. Two real-time scanners typically conflict, each flagging the other’s deep system access as suspicious, producing instability, slowdown, and sometimes protection that fails on both sides. One active product at a time. On-demand scanners designed for a second opinion are the exception, and they say so.

Does antivirus stop ransomware?

Partially. Products include behavioural rules to spot mass file encryption, and these do catch some attacks. But detection is reactive and a genuinely new variant may get through. The reliable defence is a recent backup kept disconnected from the machine — with that in place, ransomware becomes a restore rather than a ransom. Backups beat detection here, and it is not close.

Do I need antivirus if I only browse and use email?

That is the profile for which the built-in protection is most clearly sufficient. But note that browsing and email is also precisely where the deception-based threats live. Your risk is not low because your usage is light; it has simply moved to a category antivirus does not address. Focus on recognising manipulation, not on scanning files.

Is free antivirus safe to use?

The protection is often technically comparable to paid tiers. The questions worth asking are about the business model: what data does it collect, what does it bundle into its installer, how aggressive are its upgrade prompts. The free protection built into your operating system avoids most of these concerns, because it is funded by the platform’s own interest in your machine not being compromised.

My computer is slow — is it infected?

Usually not. A full drive, an ageing storage device, too many startup programs, heavy browser tabs or a pending update are all far likelier. Rule out the mundane first, and be sceptical of anything advertising itself as a cleaner to fix it — that category has a long history of manufacturing the problem it offers to solve.