Skip to content
Technology Munch

Privacy  / Analysis

Antivirus Now: What Still Matters

The built-in protection on modern systems is genuinely good. What third-party products add, what they cost you, and where the actual risk moved.

The advice to install antivirus software dates from an era when operating systems shipped without protection. That changed, and the honest current answer is narrower than the industry's marketing.

What the built-in protection now covers

Windows includes a full security suite: real-time scanning, cloud-assisted detection, ransomware protection for designated folders, firewall, browser protection. In independent testing it performs comparably to paid products.

macOS includes signature-based malware scanning, verification of signed applications, and system integrity protections that prevent large classes of compromise.

Both platforms verify software signatures and warn about unsigned applications.

Phones are substantially more locked down. Mobile antivirus apps have very limited ability to do anything, because the platform prevents them from inspecting other apps. Most mobile security apps are largely a bundle of unrelated features.

What third-party products add

Sometimes marginally better detection rates in laboratory testing. The differences are small and they move between vendors and test cycles.

Cross-platform management for families or small organisations, which is a real convenience.

Bundled extras: password manager, VPN, dark web monitoring, parental controls. These vary in quality and are frequently weaker than dedicated products in each category.

A support line, which some people value.

What they cost

Performance. Third-party real-time scanning consistently costs more system resources than built-in protection.

Conflicts. More than one real-time scanner is a genuine problem and a common cause of slowness and instability.

Aggressive commercial behaviour. Renewal pricing, upsell prompts, scan results framed to alarm, browser extensions installed without clear consent. This category has an unusually poor record.

Their own vulnerabilities. Security software runs with deep system access and has been a source of serious flaws.

Subscription cost for something the system already does.

Where the actual risk moved

Traditional malware infecting a machine through a downloaded file is a shrinking share of how people are harmed.

Phishing and credential theft. The dominant attack against individuals. No antivirus product stops you typing your password into a convincing fake page.

Account compromise through reused passwords from a breach elsewhere.

Malicious browser extensions, which run inside the browser with permission to read everything.

Social engineering — the phone call, the urgent message, the fake support number.

Supply chain compromise of legitimate software.

Unpatched software, particularly the browser.

None of these is addressed by antivirus. They are addressed by unique passwords, a phishing-resistant second factor, careful extension management and prompt updates.

What actually protects you

In order of effect:

Unique passwords, managed properly. Converts one breach into a local problem.

A phishing-resistant second factor — a passkey or hardware key — on your email account. Email resets everything else.

Automatic updates enabled everywhere.

Scepticism about unsolicited contact, and never authenticating from a link.

Reviewing browser extensions occasionally.

Backups that are not permanently connected, which is the real defence against ransomware.

Built-in protection left enabled.

That list costs nothing and addresses far more than any security suite.

A reasonable position

For most people on a current, updated system: the built-in protection is sufficient. Spend the subscription money on a password manager instead, which addresses a risk that is actually present.

Consider a third-party product when: you manage machines for family members who will click things, you need central management, or you are on an older system no longer fully supported.

If you do install one, install exactly one, and decline the bundled browser extensions and the VPN unless you specifically evaluated them.

Do not install mobile antivirus. The platform prevents it from doing much, and the permissions requested are frequently disproportionate to the function.

Removing one you no longer want

Uninstalling security software is unusually awkward, and doing it badly leaves a machine in a worse state than before.

Uninstall through the system's normal process first.

Then run the vendor's own removal tool. Most publish one, because their software installs drivers and services that a standard uninstall leaves behind. Search for the product name and "removal tool" on the vendor's own site.

Restart, then confirm the built-in protection turned itself back on. Windows disables its own protection while a third-party product is present and should re-enable it automatically. Check rather than assume, because a machine with neither is the worst outcome.

Check the browser for extensions the suite installed, which frequently survive uninstallation.

Check for a subscription still billing. Removing the software does not cancel the payment, and automatic renewal in this category is aggressive.

Then leave the built-in protection alone. It needs no configuration.