Start with updates and firmware
Enable automatic updates and check that optional driver and firmware updates are installed. Most successful attacks on home machines use known vulnerabilities that were patched months earlier.
Confirm Secure Boot and device encryption are on. Encryption matters because it protects your files if the laptop is stolen, which is a far more common loss than a targeted intrusion.
Configure Microsoft Defender properly
Defender performs well in independent laboratory tests, but several protections are off or partially configured by default. Turn on real-time protection, cloud-delivered protection, automatic sample submission and tamper protection, and enable reputation-based protection including the block for potentially unwanted apps.
Add SmartScreen for Microsoft Edge or an equivalent protection in your browser, because most infections begin with a download or a fake page rather than an exploit.
Turn on ransomware protection
Controlled folder access is Defender's ransomware defence and it is disabled by default. Enable it, then allow the applications you trust when prompted, which takes a few days of small adjustments.
Combine it with real backups. Ransomware protection reduces damage; a backup you have tested is what actually restores your files.
- Enable controlled folder access
- Keep one backup offline or versioned in the cloud
- Test restoring a single file every few months
- Never store the only copy of important files on the same drive
Accounts, privileges and sign-in
Use a standard account for daily work and keep a separate administrator account for installations. This single change blocks a large share of silent installs and unwanted changes.
Protect the Microsoft account itself with a strong unique password and a passkey or authenticator app, since it can be used to reset the device and access synced data.
Browser and application hygiene
Remove unused extensions, review notification permissions and uninstall software you no longer open. Pirated software and activation tools remain the single most common source of home infections in our experience, and no antivirus fully compensates for installing them.
Install applications from official sites or the Microsoft Store, and be sceptical of search advertisements for popular free software, which are frequently used to distribute installers bundled with malware.
Do you need a paid antivirus?
Defender plus careful habits is a reasonable baseline for a confident user. A paid suite mainly adds stronger web and phishing filtering, ransomware rollback, cross-platform coverage for phones and tablets, human support and bundled extras such as a VPN or password manager.
If several family members share devices, or if somebody in the household frequently installs software, a paid suite usually pays for itself in reduced clean-up time. Our comparison of the leading options explains the trade-offs in detail.
Network and remote-access settings
Set new networks to private only at home and public everywhere else, which tightens discovery and sharing rules automatically. Turn off Remote Desktop unless you genuinely use it, because exposed remote access remains one of the most common routes into small-business machines.
Review the firewall rules occasionally and remove entries created by software you no longer use. Every permanent exception is a door left open for something you have forgotten about.
Backups that actually work
Keep at least two copies of anything you cannot recreate, with one of them offline or in versioned cloud storage that ransomware cannot overwrite. File History or a third-party tool is fine; the format matters far less than testing it.
Restore a single file every few months. An untested backup is a plan, not a protection, and the moment you discover it never ran is always the worst possible moment.
Privacy and telemetry settings
Work through the privacy section once: turn off advertising identifiers, limit diagnostic data, review which applications can use the camera, microphone and location, and disable activity history if you do not use timeline features.
None of this stops malware, but it reduces the amount of data collected about you routinely, and it often removes advertising content from the interface at the same time.
Choosing between the Windows security suites
If you decide a paid product is worthwhile, the choice usually comes down to what you want beyond detection. TotalAV is the simplest to live with and pairs protection with clean-up tools. Bitdefender is the strongest technically, with layered ransomware defence and excellent independent results at a low performance cost. Norton bundles the widest set of extras, including an unlimited VPN and Windows cloud backup.
Kaspersky remains an outstanding engine where it is available, ESET suits users who want control and silence, and Avast or AVG make sense for households upgrading from a free tier they already trust. Our full antivirus comparison sets out the trade-offs product by product.
Signs that something is already wrong
Watch for unexplained slowdowns that persist after a restart, browser searches redirected to unfamiliar engines, new extensions or startup entries you did not add, security tools that will not update, and notification permissions granted to sites you do not recognise.
If several of these appear together, disconnect from the network, run a full scan followed by an offline scan, and change your important passwords from a different device before doing anything else on the affected machine.
