What Apple already protects you against
macOS ships with several layers: Gatekeeper checks the signature of applications before they run, notarisation screens developer software for known malware, XProtect blocks recognised threats and System Integrity Protection prevents changes to core system files. FileVault encrypts the disk and the firewall blocks unsolicited inbound connections.
Confirm each of these is on. FileVault and the firewall in particular are not always enabled on a machine that has been migrated from an older Mac.
- FileVault disk encryption enabled
- Firewall on, stealth mode optional
- Automatic updates for macOS and Safari
- Lockdown Mode if you are a high-risk user
The threats that actually land
Adware and browser hijackers arrive bundled with free converters, cracked applications and fake Flash-style updaters, then inject advertising and change search settings. Information stealers aimed at macOS have grown quickly and target saved browser passwords, session cookies and cryptocurrency wallets, usually arriving through a convincing installer downloaded from a search advertisement.
Fake support calls and phishing pages complete the picture. None of these depend on a software vulnerability; they depend on a person approving an installation or typing a password.
Do you need antivirus on a Mac?
For a careful user who installs only from the App Store or known vendors, Apple's built-in protections plus good habits are a defensible baseline. A third-party product is worth it if you share the machine, download software frequently, want stronger web and phishing filtering, or handle work data where detection and reporting are expected.
Bitdefender and Norton both perform well on macOS, and Intego is a long-standing Mac specialist. Avoid so-called cleaner utilities advertised in pop-ups, which are frequently the problem rather than the solution.
Cleaning up a Mac that is behaving oddly
Start in the browser: remove unfamiliar extensions, reset the homepage and search engine, and revoke notification permissions you did not grant. Then check System Settings for configuration profiles you did not install, and review login items and background items, which is where persistence usually hides.
Move suspicious applications to the bin and empty it, restart, then scan with a reputable tool. If saved passwords were in the browser, change them from a different device and sign out of all sessions, because credential theft is the likeliest real damage.
- Remove unknown extensions and reset browser settings
- Delete unrecognised configuration profiles
- Review login and background items
- Change browser-saved passwords from a clean device
Hardening beyond the defaults
Use a standard account for daily work and keep an administrator account separate, so an installer prompt is an unusual event rather than routine. Store passwords in a manager rather than the browser, and enable a hardware key or passkey on your Apple Account, which is the key to your backups, photos and device location.
Finally, back up with Time Machine to a drive you disconnect, or to an encrypted cloud backup. Ransomware on macOS is uncommon but a failed disk is not.
