The protection already on your devices
Every current operating system ships with security features that are switched on by default. Before spending anything, it is worth knowing exactly what those are, because they set the baseline that a paid product has to improve on.
The baseline, platform by platform
The table below is a summary of the built-in components each platform provides and where to look for them. Interfaces move between releases, so treat the locations as a starting point and confirm against your device's own settings and its maker's support documentation.
| Platform | What is included | Where to check |
|---|---|---|
| Windows 10 and 11 | Microsoft Defender Antivirus with real-time scanning, a firewall, and the SmartScreen reputation check for downloads and sites. Device encryption is available on many machines. | The Windows Security app, under virus and threat protection, and firewall and network protection. |
| macOS | Gatekeeper, which checks that applications are signed and notarised before first launch; XProtect signature checking for known malicious files; a malware removal component; an application firewall; FileVault full-disk encryption. | System Settings, under privacy and security. Most of it has no dashboard and reports nothing unless it acts. |
| Android | Google Play Protect, which checks apps from the Play Store and scans installed apps; per-app permissions; device encryption on current versions. | The Play Store app, under Play Protect, and the security section of Settings. |
| iOS and iPadOS | Strict app sandboxing, App Store review, and code signing. Third-party apps cannot scan the system or other apps, so an "antivirus" app on iOS is really doing web filtering, VPN or breach alerting. | Settings, under privacy and security. There is no scanner to check. |
| Desktop Linux | Varies by distribution: package signing, a permissions model, and a firewall that may or may not be enabled by default. Scanners exist and are often used to check files being passed on to Windows machines. | Your distribution's documentation and its firewall tool. |
Two patterns are worth drawing out of that table. First, the built-in protection on mobile platforms is structural rather than scanner-based: the operating system limits what an app is allowed to do at all. Second, on desktop platforms the built-in tools include a genuine real-time scanner, which is a relatively recent state of affairs and the reason the old advice that a Windows machine is naked without third-party software is no longer accurate as stated.
Check what is actually running before you decide anything
Defaults get changed. A trial that expired may have left real-time protection switched off. Someone may have disabled a feature to make a game install, or a firewall prompt may have been dismissed permanently. Work through each device you own:
- Open the security settings on the device and confirm that real-time or on-access protection is on, not merely that a product is installed.
- Check when the definitions or the app itself last updated. A date measured in months is the thing to fix first.
- Confirm the firewall is enabled for the networks you use, particularly on a laptop that leaves the house.
- Look for more than one security product. Two real-time scanners on the same machine interfere with each other and slow it down; keep one.
- Check whether an expired subscription is still installed and nagging. If it is no longer paid for, it is no longer protecting anything, and it should be removed rather than left in place.
- Note whether the device's disk encryption is on, and whether you have the recovery key somewhere you could actually reach it.
- Include the devices nobody thinks of: the tablet the children use, the old laptop in the spare room, the desktop that only gets switched on at tax time.
The device most often left out
Your modem or router sits between everything in the house and the internet, and its firmware is updated far less often than a phone. Check whether yours updates itself, whether the administration password is still the one printed on the sticker, and whether remote administration is switched on when you have no use for it. The Australian Cyber Security Centre publishes practical guidance for home users on this and related topics at cyber.gov.au.
Where the built-in tools are genuinely thinner
Having said that the baseline is real, it is not equivalent to a full suite, and the differences are worth naming precisely rather than in the abstract.
Cross-platform management. Built-in tools protect the device they are part of and know nothing about your other devices. A paid subscription typically covers a set number of devices across Windows, macOS, Android and iOS from one account, which matters in a household with a mixture of them and one person doing the maintaining.
Consolidated extras. A password manager, a VPN and breach monitoring are not part of the operating system baseline in the way a scanner is. You can assemble them separately, and many people do, but a bundle is one renewal instead of three.
Support you can contact. If something goes wrong with a built-in component, your options are documentation and community forums. A paid subscription usually includes a support channel with someone answering, which is worth more to some readers than any detection statistic.
Ransomware-specific controls. Some suites add protected-folder features that block unrecognised programs from modifying your documents. Equivalents exist in the built-in tools on some platforms but are not always enabled by default.
What to be sceptical about at this stage
Search results for "free antivirus download" are a well-worked target for fraud, and a downloaded installer from an unfamiliar site is exactly the sort of file nobody should be running. If you install anything, take it from the vendor's own domain, typed by hand, or from your platform's official app store.
Be equally sceptical of any page, advertisement or pop-up that claims to know your device is unprotected. It does not know, and the claim is the product being sold.
Deciding whether to add a layer
By this point you should be able to describe, device by device, what is running. That turns an open-ended question into a specific one. In broad terms:
The baseline plus good habits is a defensible position when the household is small, the people using the devices are careful, everything is current, and there is no business data involved. In that case the useful next step is step five, not a purchase.
A paid layer earns its place when several devices need covering under one arrangement, when the person maintaining them wants a single place to see the status of all of them, when a small business's records sit on a home machine, when children share a device, or when somebody in the household has already been caught by a scam and the extra web filtering is a reasonable belt-and-braces measure.
Neither answer is a moral position and nobody here is going to tell you that declining to spend money leaves you exposed. What matters is that the decision is made against a known baseline, which you now have. Step three turns it into a comparison you can run against any vendor, with a method stated up front.