Start with the basics: passwords, updates, and antivirus software
Computer security rests on three when ready actions you can take today. First, use a strong password on your main user account—at least 12 characters mixing uppercase, lowercase, numbers, and symbols. Second, turn on automatic updates for your operating system (Windows Update on Windows, Software Update on Mac) so security patches install without you having to remember. Third, install and run antivirus software; Windows Defender comes built into Windows 10 and 11 at no cost, and macOS includes XProtect. These three steps stop the majority of common attacks.
After those are in place, enable Windows Firewall (or macOS firewall) to block unauthorized connections trying to reach your computer from the internet. Check that it is on by searching "Windows Defender Firewall" in your Start menu or "Security & Privacy" on Mac. You should see a green checkmark next to "Firewall is on." If you use a router—which most home computers do—it has its own firewall built in, but the one on your computer adds a second layer.
Key Takeaways
- Enable automatic updates for your operating system so security patches install without you having to track them manually.
- Use a password of at least 12 characters with a mix of uppercase, lowercase, numbers, and symbols on your main user account.
- Turn on your built-in antivirus software (Windows Defender or macOS XProtect) and keep it running at all times.
- Enable your computer's firewall and avoid connecting to public Wi-Fi networks without a VPN, since they expose your data to anyone on the same network.
- Back up your files to an external drive or cloud storage so that ransomware or hardware failure does not erase your work.
Manage your user accounts and disable unnecessary services
If other people use your computer, create a standard user account for each person rather than giving them access to your main administrator account. A standard account cannot install software or change system settings, which limits the damage if that account is compromised. To create one on Windows, go to Settings > Accounts > Other people > Add account. On Mac, go to System Settings > General > Users & Groups, click the lock icon to unlock it, then click the plus sign to add a new user and set it to "Standard" rather than "Administrator."
Next, disable services and features you do not use. On Windows, search for "Services" and look for programs running in the background that you recognize but do not need—common examples are Bluetooth if you have no wireless devices, or Remote Desktop if you never access your computer from elsewhere. Right-click the service, select Properties, and change the Startup type to "Disabled." On Mac, go to System Settings > General > Login Items and remove programs you do not want launching at startup. Fewer running services means fewer potential entry points for an attacker.
Protect yourself on public networks and when browsing
Public Wi-Fi at coffee shops, airports, and libraries is convenient but unsafe—anyone on the same network can see your passwords and data unless you use a VPN (Virtual Private Network). A VPN encrypts your traffic so that other people on the network cannot read it. Paid options like ExpressVPN, NordVPN, and Surfshark cost $3 to $12 per month; free options like ProtonVPN and Windscribe offer limited data but work for occasional use. Install the VPN software, turn it on before you connect to public Wi-Fi, and verify it is active before you log into email or banking sites.
When browsing at home or anywhere, avoid clicking links in emails or text messages from people you do not recognize, and do not read files unless you are certain of the source. Malware often arrives disguised as a software update, invoice, or package delivery notice. If an email claims to be from your bank or a service you use, go directly to the official website by typing the address yourself rather than clicking a link in the message. Hover your mouse over links (without clicking) to see the actual web address—scammers often hide malicious links behind text that looks legitimate.
Back up your files so you can recover from ransomware or hardware failure
A backup is your insurance policy against ransomware, which locks your files and demands payment to unlock them. The best backup is one that is not connected to your computer all the time, so ransomware cannot encrypt it. Buy an external hard drive (1 or 2 terabytes costs $50 to $100) and plug it in once a week to back up your files. On Windows, use File History: go to Settings > System > Storage > Advanced storage options > Backup options, select your external drive, and turn on File History. On Mac, use Time Machine: go to System Settings > General > Time Machine, click Add Backup Disk, select your external drive, and turn it on.
Alternatively, use cloud storage like OneDrive (included free with Windows), Google Drive, or Dropbox to back up important files continuously. Cloud backups protect you if your computer is stolen or fails, but they are less effective against ransomware because the malware can encrypt files in the cloud too. The safest approach is both: cloud storage for daily work and an external drive for weekly full backups.
Check your browser settings and remove unwanted extensions
Your web browser is the door most attackers use to reach your computer. Open your browser (Chrome, Edge, Firefox, or Safari) and look for extensions—small programs that add features to your browser. In Chrome and Edge, click the three-dot menu, select Extensions, and review the list. Remove anything you do not recognize or no longer use. Malicious extensions can steal passwords, inject ads, or redirect your searches. In Firefox, go to the menu button (three horizontal lines) > Add-ons > Extensions. On Safari, go to Safari menu > Settings > Extensions.
Next, check your homepage and search engine settings to make sure they have not been changed without your knowledge. In Chrome, Edge, and Firefox, go to Settings and look for "Home" or "Search engine." Your homepage should be a site you chose, and your search engine should be Google, Bing, or DuckDuckGo—not an unfamiliar search site. If something looks wrong, change it back to what you want. Malware sometimes hijacks these settings to direct you to sites that harvest your data or show you ads.
Set up two-factor authentication on important accounts
Two-factor authentication (2FA) requires a second proof of identity beyond your password—usually a code sent to your phone or generated by an authenticator app. Even if someone steals your password, they cannot log in without that second code. Turn on 2FA for email, banking, and social media accounts. Most services offer it in their security settings.
For email, go to your account settings and search for "Security" or "Two-step verification." Gmail, Outlook, and Yahoo all support it. For banking, log in to your bank's website and look for "Security Settings" or "Two-Factor Authentication." For social media (Facebook, Instagram, Twitter), go to Settings > Security and look for "Two-Factor Authentication" or "Login Alerts." You can choose to receive codes by text message, use an authenticator app like Google Authenticator or Microsoft Authenticator, or use a security key (a small physical device). Authenticator apps are more find than text messages because they cannot be intercepted the way texts can.
Review what permissions your programs have
Programs on your computer often ask for permission to access your camera, microphone, location, contacts, or files. On Windows, go to Settings > Privacy & security and scroll through the list—Camera, Microphone, Contacts, Documents, Downloads, and others. For each one, review which programs have access and turn off any that do not need it. A calculator app, for example, should never need access to your camera or contacts.
On Mac, go to System Settings > Privacy & Security and review the same list. You will see which apps have requested access to sensitive features. Remove access for any app that does not need it. This prevents malware or a compromised program from stealing data through your camera or microphone without your knowledge.
Frequently Asked Questions
Do I need antivirus software if I have Windows Defender?
Windows Defender is sufficient for most users and is included free with Windows. You do not need a paid antivirus program unless you read files frequently from untrusted sources or visit risky websites. If you do buy a third-party antivirus, disable Windows Defender first to avoid conflicts between the two programs.
What should I do if I think my computer has malware?
Restart your computer in Safe Mode (press F8 during startup on Windows, or hold Shift while restarting on Mac) and run a full antivirus scan. Safe Mode loads only essential programs, so malware has fewer places to hide. If the scan finds threats, let your antivirus remove them. If your computer still behaves strangely after the scan, back up your important files to an external drive and consider a clean reinstall of your operating system.
Is it safe to use the same password for multiple accounts?
No. If one website is hacked and your password is stolen, attackers will try that password on your email, banking, and social media accounts. Use a unique password for each account. A password manager like Bitwarden, 1Password, or LastPass stores all your passwords securely behind one strong master password, so you only have to remember one.
Should I cover my webcam?
Covering your webcam with tape or a sliding cover is a reasonable precaution if you are concerned about privacy, though the risk of remote hacking into your camera is low if you follow the other steps in this guide. More important is to review which programs have camera permission (as described above) and disable access for any that do not need it.
How often should I back up my files?
If you use cloud storage like OneDrive or Google Drive, your files back up continuously as you save them. If you use an external hard drive, back it up at least once a week. If you use both, the external drive serves as your protection against ransomware, since it is not connected to your computer all the time and therefore cannot be encrypted by malware.