Reference
Choosing security software without the hype
A checklist for evaluating any consumer security product — including the one this site advertises — and the marketing techniques that should make you close the tab.
No commercial links on this page
This page is reference material and carries no partner links. The site as a whole is advertising-funded — see the editorial policy for how that is kept separate from what is written.
Start with the question nobody selling you something will ask
Do you need to buy anything? Windows ships with Microsoft Defender enabled; macOS has XProtect and Gatekeeper. Both are free and both are meaningfully effective. A paid suite is a reasonable purchase when you want the adjacent controls — configurable firewall, ransomware folder rules, sandbox, webcam permissions, one console, one support contact — not because you have been told you are naked without it. If a sales page implies your computer is currently unprotected, it is lying to you about the default state of your operating system.
The eight-point checklist
- Read the tier table, not the headline. Vendors sell three or four tiers and move features between them. The feature you want may be one tier up. This is the most common cause of buyer regret in this market.
- Check the per-platform list. A licence covering iOS does not mean the iOS app does what the Windows app does. Apple’s sandboxing forbids it, for every vendor.
- Find the renewal price before you buy. The advertised price is nearly always a first term. Assume auto-renewal is on and that the renewal rate is higher.
- Read the current independent test round. AV-TEST and AV-Comparatives publish openly. Look at protection and false positives, prefer real-world tests over static scans, and weigh consistency across several rounds over one good month.
- Read the vendor’s privacy policy. Reputation-based detection works by telemetry. That is legitimate and necessary; what varies between vendors is what else they do with it. Several well-known vendors have faced regulatory action on this point.
- Check the system impact figures. Both labs measure it. A suite that makes an older laptop unpleasant to use will be uninstalled within a month, which protects nobody.
- Know the refund terms. The vendor’s money-back promise and your statutory EU withdrawal right are different things with different conditions — see our notes on refunds.
- Count what you already have. If you already pay for a VPN and use a password manager, a bundle that includes both is a different value proposition from one that does not.
Red flags on a review page
We hold ourselves to this list too; if we breach it, tell us.
- A precise score with no methodology. “9.7/10” means nothing without saying what was measured and how.
- Countdown timers and “only 3 licences left”. Software does not run out. Artificial urgency is a sales technique and, in the EU, aggressive versions of it are a regulated unfair commercial practice.
- Testimonials you cannot verify. Named strangers with stock photographs saying the product changed their life.
- Guaranteed outcomes. “100% protection”, “complete security”, “you will never be infected”. Nobody can promise this, and the testing labs’ own results show why.
- A comparison table where the advertised product wins every row. Real products have weaknesses.
- A price with no date. Prices move constantly; an undated price is a stale price.
- No disclosure of how the page is funded. If a page is full of buy buttons and does not say whether it is paid, assume it is and read accordingly.
- Fake “your PC is infected” scan animations. A web page cannot scan your computer. Any page that pretends to is not merely advertising — it is deceptive.
The free measures worth more than any subscription
In rough order of value per euro spent, which for all of these is zero:
- A backup that is disconnected from the computer. An external disk you unplug, or a versioned cloud copy. This is the only thing that defeats ransomware after the fact.
- Automatic operating-system and browser updates, left on.
- Unique passwords from a password manager. Your browser has one built in and it is free. Reuse is what turns somebody else’s breach into your problem.
- Two-factor authentication on e-mail first, then banking, then everything else. Your e-mail account is the reset route for all the others.
- Not installing cracked software. It is the single highest-yield malware route in consumer computing.
- Changing the router’s default administrative password and keeping its firmware updated.
Where paid software genuinely adds something
Having said all of the above: the folder-permission model used by ransomware shields, a firewall with a usable interface, an application sandbox and consolidated management across a household’s devices are real capabilities that the free defaults do not provide. If you want those, buying a suite is a sensible decision made for a sound reason. That is a very different argument from fear.
Sources
- AV-TEST Institute and AV-Comparatives — published testing methodologies and current result rounds.
- Directive 2005/29/EC on unfair commercial practices, on misleading and aggressive practices including false urgency. eur-lex.europa.eu
- Directive 2011/83/EU on consumer rights, Articles 9 and 16. eur-lex.europa.eu
- ENISA Threat Landscape, annual editions. enisa.europa.eu
General guidance, not legal or security advice for any particular situation. Reviewed 21 September 2026 by Lisa Thomas.