Security basics: what to do before you buy anything
This page contains no partner links and nothing to buy. It is here because a site funded by security-software commission should be able to tell you, without hedging, which free measures matter more than the purchase — and in what order to do them.
1. Install updates, promptly
The single highest-value habit, and the least interesting. Most successful attacks on home machines exploit a flaw that had already been fixed; the gap between a patch being released and being installed is the window. Turn on automatic updates for the operating system, and remember that the browser and its extensions, the PDF reader and anything else with network access need the same treatment. A device that no longer receives security updates from its maker — an old phone, an unsupported Windows version — should be treated as permanently exposed, not as fine because it still starts.
2. Turn on two-factor authentication, starting with e-mail
Do e-mail first. Not banking, not social media — e-mail, because it is the password-reset route to everything else you own. Whoever controls your inbox controls your other accounts, whatever their own passwords are. Then banking, then anything with a payment method stored in it.
Not all second factors are equal. An app that generates codes, or a hardware key, is materially better than SMS, because SMS codes can be intercepted by transferring your number to another SIM. SMS is still far better than nothing, so if the app is the obstacle, use SMS today and improve it later.
3. Keep one backup that ransomware cannot reach
This is the control that actually recovers your files. Security software reduces the chance of being hit; a backup is what you have if it happens anyway. The requirement is that the backup is not a folder your computer can silently overwrite — so an external drive you unplug, or a service that keeps versions and lets you roll back to a date before the encryption.
And restore one file from it, once, deliberately. An untested backup is a belief, not a backup. Most people discover their backup was not running at the moment they need it.
4. Use a different password on every site
The threat here is not someone guessing your password; it is one company being breached and the attacker trying the same address and password everywhere else. Unique passwords contain the damage to one account.
Current NIST guidance has moved away from forced complexity rules and mandatory rotation, both of which pushed people towards predictable patterns, and towards length and uniqueness. In practice nobody achieves uniqueness by memory, which is why a password manager is worth having — a bundled one, a standalone one, or the one built into your browser. Any of them beats reuse.
5. Audit your browser extensions
An extension can usually read and alter every page you open, including your bank. Extensions also change hands: a useful tool acquired by someone else can become an injector of advertising or worse in a single update, with no visible sign. Open the extensions page, remove anything you do not actively use, and be sceptical of anything that asks to read data on all websites without needing to.
6. Treat urgency itself as the warning sign
Fraud needs you not to check. That is why the message says twenty-four hours, why the caller says your account is being emptied right now, and why the page says the offer ends tonight. The defence is procedural rather than technical: verify through a route you chose yourself. Close the message, open the app or type the address you already know, and see whether the problem exists. A genuine provider is never harmed by you calling them back on a number from their own website.
Where paid software fits
After the six above, not instead of them. Every supported version of Windows already includes Microsoft Defender Antivirus, a firewall and SmartScreen filtering at no cost, and Defender is tested publicly alongside the paid products. A paid suite can still be a reasonable purchase — cross-platform cover for a household, a bundled VPN and password vault, one subscription instead of four — but it is a convenience decision, not the difference between protected and unprotected. Anyone who tells you otherwise is selling. Our main guide goes through that decision in detail, and it does carry partner links.
If you think you have already been hit
- Disconnect from the network — unplug the cable, turn off Wi-Fi. If files are being encrypted, this limits what is reached.
- Do not pay immediately, and do not wipe immediately. Both remove options.
- Change the important passwords from a different, clean device, e-mail first. If an infostealer was present, those credentials have already left the machine.
- Restore from backup rather than trusting a cleaned machine with anything valuable. For a serious compromise, a rebuild is the only reliable answer.
- Tell your bank if payment details were on the device or typed into a suspicious page.
Public guidance on ransomware response is published free by CISA at cisa.gov/stopransomware, and the European picture is covered in ENISA’s annual Threat Landscape reports at enisa.europa.eu.