What Security Software Do You Recommend? (2026 Q3 update)

Basic protection in four steps.

My updated guide cuts through the hype with four no-nonsense steps to keep your PC safe. Learn what works, what to avoid, and how to stay secure without overspending or overcomplicating.
The Best of Ask Leo!
A Corgi sitting in front of a PC displaying Windows Security. The Corgi looks at the camera and gives a "thumbs up".
(Image: Google Flow)

Question: What security software should I use? What anti-virus is best? How about a firewall? And what about spyware? Should I use one of the all-in-one packages that claim to do everything? Is there anything else I need?

I get these questions constantly. There’s a fair amount of churn and drama in the security industry; things change over time.

It’s time once again for my periodic update. Not a lot has changed in the last year, but there are some new things to consider.

TL;DR:

My security software recommendations

  1. Windows’ built-in Windows Security remains my recommended security solution for most systems.
  2. Your router can serve as your primary firewall at home or work.
  3. Leave the Windows Firewall enabled unless it causes problems.
  4. Let Windows Update keep your computer as up-to-date as possible.

That’s it. Good basic protection in four steps.

Basic security software: Windows Security

Windows Security — previously known as Windows Defender — comes pre-installed with Windows, and Microsoft seems to improve it with every release.

Windows Security does a fine job of detecting malware without adversely affecting system performance or nagging you for renewals, upgrades, or upsells. It just does its job quietly in the background: exactly what you want from your anti-malware tool.

Ask Leo! is Ad-Free!
Help keep it going by becoming a Patron.

The ratings game

Every so often, Windows Security comes under fire for rating lower in tests than other security packages. I get push-back — often angry push-back — that it remains my primary recommendation.

There are several reasons I stick to that position.

  • No anti-malware tool will stop all malware. Malware can slip through even the highest-rated packages.
  • The “highest-rated” security software changes depending on the date, the test, and who’s doing the testing. There is no single clear, consistent winner.
  • Regardless of how the data is presented, the differences among detection rates across most current anti-malware tools are relatively small compared to other factors.

There are also practical reasons I continue to prefer Windows Security.

  • It’s free.
  • It’s already installed; there’s nothing you need to do.
  • It rarely affects system performance.
  • It automatically keeps itself up to date using Windows Update.
  • It has no hidden agenda; it won’t pester you with renewals, upgrades, or upsells to tools you don’t need.

It’s not perfect, but no security tool is.

My recommendation stands. Windows Security remains a solid, free security package with minimal system impact. It should be appropriate for almost everyone.

Alternative security software and additions

I also recognize that Windows Security might not be right for everyone. No single product is.

This is where I run into difficulty making specific recommendations. The landscape keeps changing. More than one once-free tool has promoted its paid product so heavily that the free version virtually disappeared. People download and install programs thinking they are free, only to discover it’s a “free trial” or “free download”, meaning if you want to keep it past a certain length of time, you’re required to purchase it.

Some programs have become as much self-promotion tools as they are security tools, bombarding you with sales pitches and upgrade offers to the point of impeding your computer use.

Things keep changing, so in terms of the tools I mention below, caveat emptor: “Let the buyer beware.” I can’t honestly predict that these tools will remain recommendation-worthy.

A short list of top recommendations from around the internet includes:

  • Avast
  • BitDefender
  • ESET
  • Malwarebytes
  • Webroot

Note that these aren’t necessarily free.

There are plenty of others as well. I’ve selected these because they have shown up fairly consistently in the ratings game over the years. Don’t take offense if I’ve overlooked your favorite.

Caveats to all

I need to reiterate some important points.

  1. Beware of the word free. In most cases, a free trial is just that: a trial of a full-featured product that eventually requires payment. In some cases, the “free trial” becomes a truly free version after the trial ends. In other cases, they are separate downloads. And in other cases, there is no truly free version at all. Be sure you know what you are getting.
  2. Regardless of what you download, you are likely to face upgrade and upsell offers or even an ongoing subscription. Unless or until you know you want this, decline.
  3. Speaking of declining: when installing any of these, always choose custom installation, never the default. The default may include unrelated software you don’t need or want.
  4. Windows Defender, the anti-malware component of Windows Security, will turn itself off if you install a third-party tool. It should turn back on if you uninstall.1

What else besides security software?

Besides having security software, I recommend three other essential actions to stay safe: enable a firewall, back up, and stay up to date.

A firewall

For home and business use, I recommend using a NAT router as a firewall. You almost certainly already have one. They don’t have to be expensive and are one of the simplest approaches to keeping your computer safe from network-based threats. If you trust all the computers on your local side of the router, there’s no need for an additional software firewall besides the one already present in Windows.

Back up

I strongly recommend that you back up regularly.

In fact, I can’t stress this enough. Up-to-date backups completely avoid 99% of the disasters I hear about.

Macrium Reflect and EaseUS Todo are the backup tools I currently use and recommend.

Stay up to date

Keep your computer, Windows, and all the applications you run as up to date as possible.

This happens automatically as long as you don’t take steps to disable it. Needless to say, I strongly recommend you not disable those functions. Let Windows Update keep your system up to date.

Many of the security issues we hear about are because individuals (and, sadly, corporations) have not kept their operating systems or applications current with the latest available patches.

And finally, Internet Safety: 7 Steps to Keeping Your Computer Safe on the Internet has even more tips for keeping your computer safe.

A note about Windows 10

And you may be able to sign up for the ESU — Extended Security Updates — program for additional peace of mind into 2027.

If you’re using a third-party security package, check with that provider’s plans, but in general, most will continue to work on Windows 10 for a long time after Microsoft’s official end-of-support date.

Do this

I regularly cover topics like this to help keep you safe and secure.

Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers and tips in your inbox every week.

Podcast audio

Play

Footnotes & References

1: This is because you should not have multiple security packages performing real-time scans at the same time.

37 comments on “What Security Software Do You Recommend? (2026 Q3 update)”

    • I don’t have a recommendation, since Mac’s aren’t my strength (though I do use them). In general, though, my understanding is that it’s the same: you don’t need additional security tools.

      Reply
  1. “Good basic protection in four steps.” Actually, in a way, it’s more like “Good basic protection in no steps.” All of these are active in Windows by default except for the NAT router, which most people have to control the local network.

    Reply
    • The one thing I’ve done with my NAT router is to ensure that it ignores all incoming TCP/UDP requests. This effectively makes my home network invisible on the Internet, because when my ports get scanned, they make no response to the scan.

      Ernie

      Reply
    • Because I have limited time, and can’t stay on top of all possible security solutions. That being said PCMatic has a reasonable reputation these days (wasn’t always so). I tend to shy away from their approach to malware screening (only allowing known good things through), if they’re still doing that. I know some appreciate the approach.

      Reply
      • “You tend to shy away from their approach to malware screening”?

        But if multitudinous users like it, why shouldn’t you at least try it for awhile?

        I hadn’t heard of it before, but I’ve seen it get some very high praise for its “whitelist-only” approach. I’m definitely interested; If you were to give it a trial, I would give very serious weight to your opinion!

        Reply
        • My problem is not with its approach. My problem is with the fallout among “normal” users.

          People are interested in getting their stuff done, not security. If an allow-list approach blocks something the average user is, in my opinion, more likely to say “oh, it’s just that security software crying wolf and getting in my way again”, and bypassing the block. All is well and good until the security software was right.

          Allow-list has a much bigger role in corporate, where the stakes are generally higher, and users can be more directly convinced to follow the rules (though even then….).

          Reply
  2. On Windows, I use Microsoft Security for malware protection. I have my NAT router configured to ignore incoming connection requests from the Internet. I do NOT CLOSE or BLOCK any of my ports, because they will then report their state when they receive an incoming connection request. The best security setting for a home router that doesn’t serve any Internet requests is IGNORE on all ports. My router allows me to configure all my Internet facing ports with one setting, so I chose IGNORE all incoming connection requests. GRC’s “Shields UP!” reports that my Internet connection is effectively invisible. This means that when crackers (black-hat hackers) attempt to scan my ports, their equipment ‘sees’ nothing.

    In GNU/Linux, I keep my system up to date regularly, and run a monthly rook-kit check, just in case.

    On the Internet, I employ what I identify as Cognitive Security. I NEVER click ANY hyperlink without checking the URL it will take me to, either on websites or in email messages. If the URL doesn’t correspond with the hyperlink’s label, I DON’T click! If I have any doubt whatsoever about the link, I DON’T CLICK! As an example, if the label reads “Best Buy”, the URL must begin with “https://bestbuy.com/”. There can be a path following the first part that will direct my browser to a specific page on the site, but there shouldn’t usually be anything before the first part. For me, if there is, or I can’t decipher what the URL is, that’s a BIG RED FLAG, so I DON’T CLICK!

    Ernie

    Reply
  3. How come you’ve never mentioned ad-blocking as a security step? Not only does it make surfing the web a faster and more enjoyable and decluttered experience, but uBlock origin (widely recognised as the best ad-blocker) also often blocks websites that impersonate others or have been reported as badware. With ads also being used to trick users into downloading malware or entering personal data on a sketchy website when it comes to helping someone unfamiliar with the internet and the dangers that lie in trusting everything you see on your screen, ad-blocking can condidently prevent 90% of the most vicious attacks – the ones that prey on the weakest link in the chain – the user.

    Reply
    • Ad-blocking is more of a privacy concern than a security one. Most browsers available today come with security features built into the browser. For example, Microsoft’s Edge browser works with Windows Defender SmartScreen to guard against PUPs and malware. Firefox has similar settings.
      I use Firefox as my default browser and have the Privacy Badger and uBlock Origin extensions installed. But I rely on Windows Security to protect my computers.

      Reply
  4. I find that Windows Update is not always automatic. On many occasions I have manually run Windows Update and have found Updates that have not automatically downloaded.
    One PC I have seen lacked over 50 updates and since it had missed critical updates, it could no longer be updated and was almost unusable.

    Reply
    • Running it manually just causes it to install things now that it would have installed later. Not everything goes out immediately to everyone, and the check is one way to force things to arrive sooner.

      Reply
      • But most of the uninstalled Updates are for the antivirus software and it seems like they should be installed IMMEDIATELY.
        I’ve found as many as 4 new updates when checking 4 times per day.

        Reply
  5. I am told the importance of backing up Windows all the time.
    But I also understand the hard drive contains all information and needs
    a military style clean to erase all data, so which is true?
    Ihave used a PC for 30 years, and never backed up and never lost anything!
    Thanks.

    Reply
    • Two different things.
      The fact is things can go wrong – hard drives fail, sectors go bad, software overwrites the wrong thing, malware shows up — none of those are things that can be recovered by some magical “military style” access to the hard drive. A backup protects you.

      Reply
  6. Leo I made a big mistake when I bought this computer. It was a Windows 10 but has been upgraded to Windows 11. When I bought my computor my daughter was sick but I could tell she wanted to be part of everything and I made a foolish mistake I let her sign on as Administrator . I had no Idea that anything would go wrong. My daughter got more ill and had to go into I C U in the hospital. She wound up at Harberview in Seattle where she passed away in 2021. Now I can’t update or have the games or music i had before. And I can’t get my computer rid of her as the Administrator. Is there any hope for me to get rid of my mistake?

    Reply
    • In order for anything that follows to work, you must have administrative access to the computer. the following presumes that you have your own account on the computer, and that it is an administrative account.

      If all the above applies to you, the solution is quite simple.

      Open the Settings app

      Select ‘Accounts’ in the left column

      In the right column, scroll down to the ‘Other users’ item and click the right arrow at the right end of it.

      In the new listing you’ll see your daughter’s account, expand it by clicking the down-arrow at the right end of the item.

      After you expand your daughter’s account listing, you will see an option labeled ‘Account and data’. At the right end you will see a ‘Remove’ button. When you click it, her account and all her data will be removed from your computer.

      If you don’t have an account on the computer, or your account doesn’t have administrative access, you can log in to your daughter account using her log-in information, then in the settings app, navigate to Settings – Accounts – Other users, and add an account for yourself (after creating the account change its account type to Administrative), or if you have an account, but you don’t have administrative access, expand your account and change the account type to administrative.

      After making those changes, you can log out of your daughter’s account, log into your own account and then remove your daughter’s account as denoted at the top of this post.

      To anyone who reads this, if I’ve missed any necessary details, please append any additions or corrections

      Ernie

      Reply
    • If it’s a local account and not tied to a Microsoft account You should be able to reset it with the
      Offline NT Password and Registry Editor

      If it’s a Microsoft account login, you can reset it if you can recover her MS account (outlook.com, hotmail, etc.) password. You’ll then be able to log in with that.
      If you’ve lost access to your Outlook.com or Hotmail.com account, this is where to start.
      How to Recover an Outlook.com Account Without the Recovery Phone or Email (Maybe)

      Reply
  7. I agreed, Leo is my preferred technology information source with is no bullshit approach. It’s still for technical savvy people, grandma or tech adverse people stay uninformed and uninterested.

    Reply
  8. I got a yearly One Drive subscription five years ago. I cannot access it because my ISP now asks me to get a code at another email address – which wants me to get a code from my email address that is associated with my One Drive account. I got around in circles with both service providers. I’ve posted this problem on MS Community twice in the last 3 years – and again have gone around in circles – leading nowhere. It’s been supposedly ‘escalated’ umpteen times – and no one at Microsoft seems to know how to deal with this. Meanwhile, I’ve been paying for it – with no access to it!

    Reply
  9. Leo , I suggest other good second back up on demand scanner that has quick scan, normal 5 mins malware and a custom scan that will scan every file on your system . The good parts of this scanner it has two engines and does not install into your system . Just create a folder on your desktop and tell the install to go there . If you want to delete it , just delete that folder , no remains on your system. I suggest EMSIsoft Emergenct Kit . Please please remember this is for personal use per license .

    Reply
  10. Your words about Windows Security are reassuring to me. Ove noted lately that there have been almost daily updates to it through Windows Update.

    I’ve purchased EaseUS ToDo Backup, and I have a question. Is it harmful to my PC to leave it on 24/7 so automatic Windows updates can install and stop backups can complete?

    Reply
  11. I had been using Avast free for years, but recently I could not get rid of their pop-ups, I uninstalled it, since Leo says that Window Security is fine. (I am running Windows 10 Home 22H2 Build 19045.7058)

    My frustration with Windows security is that it doesn’t tell you much without digging.
    For example, I have Current Threats, all rated Low: PUA:Win32/AskToolbar, PUA:Win32/AskToolbar, and PUABundler:Win32/CandyOpen.

    To find out more about these, each one requires clinking on it (which shows options “Block threat”, Quarantine, Remove, and “Allow on device”), click “See details”, allow administrator privilege, which then shows a pop-up indicating “Potentially Unwanted Software” for installers I had downloaded for Nero Burning software, outlook_express, and winamp respectively.

    Reply
    • I’m not sure what more you might want to know. They’re unwanted, and should be quarantined or removed. A quick search on any of them gets you more information, but again, I’m missing how that would be helpful.

      Reply
  12. I 100% agree on Backups, and particularly air gapped backups and rotation of at least two External Drive backups. In addition I recommend ongoing automated online backups (with encryption).

    While I agree on Windows Security comments as it truly is free, so much better than it used to be and keeping OS and software updated at all times, my opinion on anti-malware is this. It is NOT sufficient to truly protect you. And, as was mentioned, no security software is 100% and that is true, but having a cybersecurity solution goes far beyond just Anti-malware. Threatlocker is the #1 solution in the space (my opinion) as it is Zero Trust and just blocks all software, scripts from running without going through an approval process.

    Huntress and also Threatdown (a Malwarebytes Managed EDR) are also good additions paired with Windows Security and a good backup strategy are better than just Anti-Malware alone. I “think” your target audience is primarily home users and your suggestions are fine for “most” home users. That said, if you run a small business from home, or have more sensitive personal information, or your more worried about your PC being hacked that getting malware on your PC, adding a good cybersecurity solution in addition can at least minimize and in most cases even prevent or limit what a hacker could do. And as I’m sure Leo knows, security also extends beyond just the PC of course. Routers (most home routers are garbage but better than not having one) and properly secured online accounts and particularly email accounts are crucial to a better security posture and you have great articles on all these already, so those reading here should look at those. While Hardware Keys or an IDP passwordless solution are best for email and other online accounts, some email and online accounts don’t support this type of configuration. So Proton Authenticator for 2FA is my go to for those accounts.

    Additionally, one very affordable solution that might be a great add on for home users is https://www.syshardener.com/ from https://www.novirusthanks.com/ and a decent resource for home/SOHO users. Not “as good” as Threatlocker but certainly adds some additional hardening of the Microsoft Windows OS.

    Just my two cents.
    I’m an Ethical Hacker, Cybersecurity Professional and a Digital Forensics Examiner so I have seen just about everything in my nearly 40 years at this. 🙂 Stay safe out there everyone.

    Reply
  13. 1. I use Microsoft Security here because, as Leo says, it comes with Windows, installed and ready to go, it ranks with the best, and it doesn’t negatively impact Windows performance.

    2. My router acts as my hardware firewall, and I test it periodically on GRC’s Shields Up! website (https://www.grc.com/x/ne.dll?bh0bkyd2) to make sure it still ignores incoming connection requests, aka stealth mode.

    3. I keep Windows firewall active, and using its default configuration because I trust everyone who enters my home, so it meets my needs.

    4. I let Windows Update keep Windows as up to date as possible, but I take Leo’s recommendation a step further. I use UniGetUI to install, update, and remove the software I use on my computer. It sits in the system tray, monitoring the WinGet repository for new updates. When a new update for an installed program becomes available, it alerts me so I can open the its main window to install the update. I recently installed the current Python release interactively so it would install into my user’s space – it’s that flexible.

    While I cover all four of Leo’s ‘steps’, I believe there is a fifth that’s at least as important as the previous four, Cognitive Security which consists of a seriously skeptical attitude combined with a healthy mistrust of everyone and everything that comes from the Internet. Always inspect the URL a hyperlink will take you to before you click to check that it correlates with the label that’s displayed. If not, or if you can’t make sense of it … DO NOT CLICK! Never forget that email comes from the Internet, so it should be regarded with the same skepticism as anything else from there.

    Ernie

    Reply
  14. Hello and thank you for this latest newsletter. I am always much the wiser for them.
    Surprisingly, there is no mention of Norton security suites, but perhaps not without good reason?
    If you’d explain why, it might be time I changed.
    Many thanks in anticipation of your reply.

    Reply
    • In the article, Leo said, “There are plenty of others as well. I’ve selected these because they have shown up fairly consistently in the ratings game over the years. Don’t take offense if I’ve overlooked your favorite.”
      So don’t take offense. 😉

      My experiences with Norton Security has been horrific slowdowns. I once had a one year free license that came with a new computer. I uninstalled it after a couple of days. I’ve heard it’s immproved, but Windows Security does the job well and for free. Why pay when the free program does the job just as well.

      Reply

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.