The most effective defenses are the ones you use every day

Protecting your home computer comes down to four habits: using strong passwords, keeping software updated, recognizing suspicious emails and links, and backing up your files. You do not need expensive security software or technical knowledge—most threats succeed because people skip these basics, not because the attacks are sophisticated. A computer that gets updates, runs antivirus software, and has a user who thinks before clicking is far safer than an expensive machine left unpatched.

The threats are real but manageable. Malware can steal your passwords and banking information. Ransomware locks your files until you pay. Phishing emails trick you into handing over credentials. But each of these has a straightforward defense, and layering them together makes you a much harder target than the average home user.

Key Takeaways

  • Create passwords that are at least 12 characters long and use a password manager to store them, so you do not reuse the same password across sites.
  • Turn on automatic updates for Windows, macOS, or Linux, and for every browser and major process you use regularly.
  • Check the sender's email address carefully before clicking links or downloading attachments, and hover over links to see where they actually point.
  • Back up important files to an external drive or cloud storage at least monthly, and keep the backup disconnected from your computer when not in use.
  • Run antivirus software that comes with your operating system (Windows Defender, macOS built-in protection) or a reputable third-party option, and scan your computer weekly.

Create passwords that attackers cannot guess

A strong password is your first line of defense against someone accessing your email, bank account, or social media. The password needs to be long—at least 12 characters—and mix uppercase letters, lowercase letters, numbers, and symbols. "MyDog2024!" is stronger than "password123" because it is longer and uses mixed character types. Avoid words from the dictionary, your name, your birthday, or anything someone could learn from your social media.

The problem is that you cannot remember 50 different strong passwords. That is where a password manager comes in. It is a program that stores all your passwords in an encrypted vault, protected by one master password. You only have to remember one strong password, and the manager fills in the rest. Popular options include Bitwarden (free), 1Password, and LastPass. When you create a new account anywhere, the password manager generates a random strong password and saves it for you.

Never reuse the same password across multiple sites. If one website is hacked and your password is stolen, attackers will try that same password on your email, bank, and social media. A password manager makes it straightforward to use a different password everywhere because you do not have to remember any of them.

Keep your operating system and software updated

Software updates patch security holes that attackers use to break in. When Microsoft, Apple, or a software company releases an update, it usually includes fixes for vulnerabilities they discovered or that researchers reported. If you do not install the update, you are leaving the door open. Attackers often write code to exploit known vulnerabilities within days of a patch being released, so the window to update is narrow.

Turn on automatic updates so you do not have to remember. On Windows 10 or 11, go to Settings > Update & Security > Windows Update and select "Automatic." On macOS, go to System Settings > General > Software Update and turn on "Automatic Updates." For your browser—Chrome, Firefox, Edge, or Safari—updates usually install automatically when you restart. For other programs you use regularly (Zoom, Adobe Reader, Java), check their settings for an automatic update option, or manually check for updates once a month.

Do not ignore update notifications. When your computer tells you an update is available, install it within a week. If an update requires a restart, restart your computer that evening or weekend so the patch takes effect.

Recognize phishing emails and malicious links

Phishing is an email that looks like it came from your bank, PayPal, Amazon, or another trusted company, but actually came from an attacker. The email asks you to "confirm your account," "verify your password," or "update your payment method." It includes a link that looks real but actually points to a fake website designed to steal your credentials.

Check the sender's email address before you click anything. If the email claims to be from Amazon, the sender should be something like "account-update@amazon.com." If it is "amazon-security@mailservice.net" or "support@amazonhelp.org," it is fake. Hover your mouse over any link (do not click) to see the actual URL in the bottom left corner of your screen. If the link says it goes to amazon.com but the URL shows something else, it is a phishing link.

Banks and major companies will never ask you to confirm your password or payment information by email. If you receive an email asking you to do this, delete it. If you are unsure, go directly to the company's website by typing the address into your browser yourself—do not click the link in the email—and log in to check your account.

Watch for spelling mistakes and awkward phrasing. Phishing emails are often written by people for whom English is not a first language, or they are generated by AI. "Dear Valued Customer" instead of your name, or "Please to update your account information," are red flags.

Back up your files so you can recover from ransomware

Ransomware is malware that encrypts your files and demands payment to unlock them. The only way to recover without paying is to restore from a backup made before the infection. A backup is a copy of your important files stored somewhere separate from your computer.

Use an external hard drive or cloud storage. Plug an external drive into your computer once a month and copy your Documents, Photos, and Desktop folders to it. Windows includes a built-in backup tool called File History; go to Settings > System > Storage > Advanced Storage Options > Backup Options and select your external drive. macOS includes Time Machine; go to System Settings > General > Time Machine and select your external drive.

Alternatively, use cloud storage like Google Drive, OneDrive, or Dropbox. These services automatically sync your files to the cloud, so you always have a recent copy. The advantage is that you do not have to remember to plug in a drive. The disadvantage is that if ransomware encrypts your files, it may also encrypt the cloud copies if they are synced in real time. To be safe, keep your external backup drive disconnected from your computer except when you are actively backing up. That way, ransomware cannot reach it.

Run antivirus software and scan regularly

Antivirus software detects and removes malware. Windows comes with Windows Defender built in, and it is effective for most home users. macOS has built-in protection as well. If you want a third-party option, Bitdefender, Norton, and Kaspersky are reputable choices. Avoid free antivirus software from unknown companies; some of it is malware itself.

Enable real-time scanning so the software checks files as you read them. Then run a full scan of your computer once a week. On Windows, open Windows Defender, go to Virus & Threat Protection, and click "Scan Options." Select "Full Scan" and click "Scan Now." This takes 30 minutes to an hour depending on how much is on your computer. Let it run while you do something else.

If the scan finds something, let the antivirus remove it. If it asks whether to quarantine or delete, choose delete. If you are unsure whether something is malware, search the file name online before deleting it.

find your Wi-Fi network and use a firewall

Your home Wi-Fi network is the entry point for attackers on the same network. Change the default password on your router as soon as you set it up. The default password is usually printed on the router itself or in the manual, and attackers know these passwords. Log into your router's admin panel (usually at 192.168.1.1 or 192.168.0.1 in your browser), find the Wi-Fi settings, and change the password to something strong.

Use WPA3 encryption if your router supports it, or WPA2 if it does not. This scrambles the data traveling between your devices and the router so someone cannot intercept your passwords or banking information. The encryption setting is in your router's Wi-Fi settings.

Windows and macOS both have built-in firewalls that block incoming connections from the internet unless you explicitly allow them. Leave these turned on. On Windows, go to Settings > Privacy & Security > Windows Security > Firewall & Network Protection and make sure it is on. On macOS, go to System Settings > General > Security & Privacy > Firewall and turn it on.

Frequently Asked Questions

Do I really need antivirus software if I have Windows Defender?

Windows Defender is sufficient for most home users and is built into Windows at no extra cost. A third-party antivirus is useful if you read files frequently from untrusted sources or want additional features like a VPN or password manager. Do not run two antivirus programs at the same time; they will slow your computer and conflict with each other.

What should I do if I think my computer has malware?

Run a full antivirus scan when ready and let it remove anything it finds. If the scan does not solve the problem, restart your computer in Safe Mode (hold Shift while restarting on Windows, or restart and hold Command-S on macOS) and scan again. Safe Mode loads only essential programs, so malware has less chance to hide. If the problem persists, take your computer to a repair shop or contact the manufacturer's support line.

Is it safe to use public Wi-Fi on my laptop?

Public Wi-Fi is not encrypted, so someone on the same network can see your passwords and banking information. Avoid logging into email, banking, or shopping sites on public Wi-Fi. If you must, use a VPN (Virtual Private Network) like Proton VPN or Mullvad, which encrypts all your traffic. Many VPNs are free or low-cost.

How often should I change my passwords?

You do not need to change passwords regularly if they are strong and unique. Change a password only if you suspect it has been compromised, if a website you use was hacked, or if you used it on a public computer. If you reuse a password somewhere and that site is breached, change the password when ready on all sites where you used it.

What is a VPN and do I need one?

A VPN encrypts your internet traffic and routes it through a server in another location, hiding your real IP address and location. It is useful on public Wi-Fi or if you want privacy from your internet provider. For home use on your own Wi-Fi, a VPN is optional. If you travel or use public Wi-Fi regularly, a reputable VPN is worth the small monthly cost.