Ten or fifteen years ago the answer was simple: a Windows PC without third-party antivirus was a PC waiting to be infected. That is no longer true. Every mainstream operating system now ships with malware protection switched on, and the independent test labs that once embarrassed the built-in tools now rank them alongside paid products. So the honest question is not "do I need antivirus?" but "is the protection I already have enough for the way I use my devices?" This guide explains what the built-in tools actually do, what the independent evidence says, where the real gaps are, and how to decide without being sold to.
What antivirus actually does today
The word "antivirus" is a relic. Modern security software does far more than compare files against a list of known viruses, and it has to, because attackers can generate new variants of a malicious file faster than any list can be updated. A current product typically combines several layers:
- Signature and reputation checks: known-bad files, and files nobody has seen before, are flagged or sent to the vendor's cloud for a verdict.
- Behaviour monitoring: a program that starts encrypting hundreds of documents, injecting code into other processes or disabling security settings is stopped based on what it does, not what it looks like.
- Web and download filtering: known malicious and phishing sites are blocked before anything reaches the disk.
- Remediation: anything that slips through is quarantined or removed, and changes it made are rolled back where possible.
The UK National Cyber Security Centre (NCSC) describes antivirus as one part of a wider system: it "works in conjunction with network defences, device configuration and App Store scanning to try and block malware before it can cause harm." That framing matters. Antivirus is a safety net, not the whole of your security.
What is already built into your devices
Windows
Windows 10 and 11 include Microsoft Defender Antivirus, managed through the Windows Security app, with real-time protection, cloud-delivered protection, and app and browser controls that warn about unknown or malicious downloads and sites. Microsoft's documentation also describes an important detail many people miss: when you install a third-party antivirus product on a home Windows PC, Defender switches itself off automatically, and it can switch itself back on if that product expires or is uninstalled. You are never meant to run two real-time scanners at once.
One genuinely useful Defender feature is controlled folder access, which stops untrusted apps from changing files in protected folders such as Documents and Pictures. Microsoft recommends turning it on to "protect your important local folders from unauthorized programs like ransomware or other malware". It is not switched on by default, and it can occasionally block a legitimate program that you then have to allow manually.
macOS
Apple's platform security guide describes three layers: preventing malware from launching (the App Store, or Gatekeeper combined with notarisation for apps downloaded from the web), blocking known malware with XProtect, and remediating malware that has already run. XProtect's signatures are updated separately from macOS itself, and Apple says Macs check for those updates daily by default. When Apple discovers a malicious app it can also revoke the developer's certificate, which stops that app opening on Macs everywhere.
Android, iPhone and Chromebook
On Android, Google Play Protect scans apps in the Play Store before you install them, checks the device for harmful apps from other sources, and can deactivate or remove harmful apps. Google states it is on by default. iPhones and iPads rely on similar app store controls. This is why the NCSC's device guidance says third-party antivirus is largely unnecessary on iOS, Chrome OS and Android in its default configuration: the platform design removes most of what antivirus used to protect against.
What the independent test labs show
Two of the best-known independent labs, AV-TEST in Germany and AV-Comparatives in Austria, test consumer security products against live threats every few months and publish the results on their own sites. NerdBible does not run its own malware tests, so we rely on theirs.
The pattern in recent rounds is clear. In AV-TEST's home-user tests on Windows, which score protection, performance and usability out of 6, Microsoft Defender has recently earned full marks for protection and the lab's "Top Product" label. In one recent four-month AV-Comparatives Real-World Protection Test, which exposed each product to 400 live malicious URLs, Defender blocked 396 of them (99.0%) and received the lab's highest award, while protection rates across the products tested ranged from 92.0% to 99.8%. Defender also recorded no false alarms in that round.
Two cautions keep this honest. First, results move from round to round, so treat any single test as a snapshot and look at the labs' current reports rather than a vendor's old badge. Second, the gap between the best products is now a percentage point or two. That still matters at scale, but for an individual it means the choice between Defender and a good paid suite is rarely about raw detection anymore.
Where built-in protection stops
If detection is roughly even, why do paid suites still exist? Because the threats that actually hurt most people today are not always malicious files.
- Phishing and scams: a convincing fake bank page or a phone call from a "support technician" involves no malware at all. Built-in filters block many known phishing sites, but no filter catches every new one, and none can stop you handing a password to a convincing caller. Some paid suites add extra phishing and scam filtering on top.
- Account takeover: reused passwords stolen in a data breach let criminals log in as you. Antivirus cannot fix that; a password manager and two-step verification can.
- Unsupported software: an operating system or browser that no longer gets security updates leaves holes no scanner fully covers.
- Settings you never turned on: controlled folder access, automatic backups and device encryption only help if they are enabled.
Paid suites mainly compete on convenience features bundled around the scanner: password managers, VPNs, identity or breach monitoring, parental controls, and one dashboard covering Windows, Mac and phones. Some of these are genuinely useful, some duplicate free tools you already have, and the NCSC is blunt that "we don't recommend using more than one AV product on any device", because the products may conflict.
Common myths
"Free built-in antivirus is basic"
Not on current evidence. The independent lab results above put Defender in the same band as well-known paid products for detection.
"Macs and iPhones cannot get malware"
They can, which is why Apple builds XProtect into macOS and revokes malicious developers' certificates. The difference is that the operating system already does most of the work, so a third-party product adds less.
"Two antivirus programs are safer than one"
The opposite. Two real-time scanners fight over the same files, slow the machine and can cause instability. Windows avoids this by turning Defender off when another product registers itself.
"A pop-up says I am infected, so I need to buy something"
Fake virus warnings in the browser are a classic scam. Genuine detections appear in your security app, not as a web page with a phone number.
How to decide: a practical checklist
- Open your built-in security app and confirm it is on. On Windows, go to Windows Security, then Virus & threat protection, and check which provider is listed. On Android, open the Play Store, tap your profile and check Play Protect.
- Turn on automatic updates for the operating system, browser and apps. Most successful attacks use flaws that already have fixes.
- Switch on controlled folder access (Windows) and set up an automatic backup to an external drive or a cloud service with file version history.
- Use a password manager and two-step verification on email, banking and anything that can reset other accounts.
- Then ask whether a suite adds something you would actually use. Consider one if you want cross-browser phishing filtering, if several less technical people share devices, if you want a single dashboard and parental controls across a family's Windows PCs, Macs and phones, or if you prefer to buy one bundle instead of setting up separate free tools.
- If you buy, check the current lab results on AV-TEST and AV-Comparatives, read the renewal price, not just the first-year price, and uninstall any old security product first.
When you probably do not need a paid suite
If you use one up-to-date Windows PC with Defender on, a Mac or iPhone on current software, or an Android phone that only installs apps from the Play Store, and you already use a password manager, two-step verification and backups, a paid suite is unlikely to make a meaningful difference to your safety. The NCSC's own conclusion for Windows and macOS is that the built-in products "will meet the needs of many organisations", and the same logic applies at home.
The bottom line
You still need malware protection, but you probably already have it. Built-in tools on Windows, macOS and Android now perform close to the best paid products in independent testing. The bigger risks are phishing, reused passwords, missed updates and no backups, and fixing those matters more than which scanner you run. Buy a paid suite for the extras you will genuinely use, not out of fear. If you do decide on one, our antivirus comparison explains how we rank them.