VPN makers selling security suites should show how their numbers are made

VPNs are becoming security suites, and the marketing leans on vendor surveys and block counts with no method shown. Buyers deserve the working, and a plain list of limits.

VPN makers selling security suites should show how their numbers are made
Photo: Startup Stock Photos / stocksnap, CC0

This is an opinion piece. It sets out the view of NerdBible's editors; the facts it relies on are sourced below.

Our position is simple. As VPN companies grow into all-in-one security suites, they should publish how their headline numbers are produced and say plainly what each part of the bundle does not cover. A big number with no method behind it is advertising, not evidence, and buyers deserve to be able to tell the difference.

What changed this week

A VPN used to be sold on one idea: an encrypted tunnel between your device and the internet. That is changing. In its report on a recent New York event, TechRadar describes a celebrity ambassador campaign that raises awareness of digital threats and also boosts marketing as NordVPN moves from a simple VPN to an all-in-one security suite. The same week, TechRadar's deals desk argued that you need far more than a VPN to protect your data online, and promoted a plan that bundles antivirus, password management, dark web alerts and cloud backup with the VPN. Elsewhere, a Cybernews pricing guide describes ExpressVPN's Advanced plan as including a comprehensive security suite.

None of this is wrong in itself. A VPN does not stop you from clicking a bad link or reusing a weak password, so adding tools that do is reasonable. The issue is how these suites are being argued for.

Numbers without a method

The campaign coverage is full of figures. According to TechRadar, NordVPN's antivirus tool scans 12 million unique URLs a day and blocks an average of 130,000 malicious pages, and nearly 5 million malware attempts were blocked in the US in the first months of 2026, as NordVPN says. The company's own research is also quoted: 71 per cent of respondents believe common sense is enough to handle digital threats, 74 per cent could not spot a fake URL, 82 per cent failed to recognise a fake CAPTCHA, and 73 per cent had recently fallen victim to a scam.

We are not saying these figures are inaccurate. We have no basis to say that, and the company is entitled to publish its research. The point is what a reader can do with them. The report does not say how many people were surveyed, how they were chosen, or what counts as a "block". Is a block a confirmed malicious page, or any request that matched a list? Is the daily average taken over a year or a good week? A reader cannot tell, so a reader cannot compare one vendor's number with another's, or with the same vendor's number next year.

A statistic that frightens is also a statistic that sells. When the research is run by the company that sells the cure, readers should at least see the working.

Why "protection" language needs care

Security marketing has been through this before. In a 2010 settlement, the Federal Trade Commission and 35 state attorneys general resolved charges that an identity theft protection company had used false claims. The FTC's complaint, as described in that release, said the service protected only against certain forms of identity theft. The release quotes Illinois Attorney General Lisa Madigan saying "there is unfortunately no foolproof way to avoid ID theft". That case concerned a different product and a different era, and it ended in a settlement. We cite it only because it shows how regulators have treated claims of complete protection: as advertising claims that must match what the product actually does.

Today's bundles use phrases such as dark web alerts, real-time protection and a protection promise, as TechRadar's deal write-up lists them for one plan. Each phrase may be accurate. But each is shorthand, and the buyer needs to know what it means in practice: which threats are covered, which are not, and what the promise actually pays out or fixes.

The strongest case for the other side

The fair counter-argument deserves a full hearing. Bundles solve a real problem. Many people never buy separate antivirus, a password manager and a VPN, and a single subscription that covers all three may leave them safer than the patchwork they had before. A bundle can also cost less than the parts bought separately, which is the pitch in the deal write-up. Marketing, the argument goes, is not a research paper. Brands use surveys and big numbers to get ordinary people to care about security, and caring is the first step to being safe. TechRadar's related coverage even points to an independent test of NordVPN's antivirus, so third-party checks are not absent from this market. And regulators already police false claims, so extra transparency rules are unnecessary.

Much of that is true, and we do not argue for less security marketing. But it does not answer the narrow request here. Asking for a methodology note beside a survey costs a vendor one paragraph. It does not stop the campaign, the ambassador or the bundle. And the regulator's role is a backstop after harm, not a substitute for readers being able to judge a claim at the moment they read it. If independent test results exist, they should sit next to the vendor's own numbers, not in a separate article the buyer may never find.

What we think vendors should do

  • Footnote every survey. State sample size, who was asked, when, and how.
  • Define "blocked". Say what is counted, over what period, and whether the figure is an average.
  • Show third-party results beside your own. Name the tester and the test date.
  • List what each bundled tool does not do. A short plain table beats a row of icons.
  • Show the renewal price next to the intro price. As the Cybernews guide notes for one provider, discounted rates apply only to the first term, and prices rise on renewal.

What buyers can do now

Treat vendor-run surveys as marketing until a method is shown. Before paying for a suite, list what you already use for passwords and device protection, and ask whether you would be paying for duplicates. Check the renewal terms before you check out: the same guide says that for several payment methods the subscription renews automatically. And if a headline number matters to your decision, look for an independent test, not only the vendor's own page.

VPN companies are right that people underestimate online threats. The best way to be believed is to let readers check the numbers.

Looking for the best VPN? See our top picks