null
Account ×
GENUINE MICROSOFT LICENCES DIGITAL DELIVERY

Our Blog

Cyber Security for Windows 10 & 11: Essential Protection Guide

Cyber Security for Windows 10 & 11: Essential Protection Guide


19 minute read

Windows includes strong built-in security features, but keeping a PC secure still depends on how the computer is configured and how it is used.

Whether you use Windows 11 or still need Windows 10, the most important protections include keeping security updates current, using Microsoft Defender Antivirus and Windows Firewall, protecting your account, avoiding phishing, encrypting important data and maintaining reliable backups.

Windows 10 security changed significantly after 14 October 2025. Normal Microsoft support for Windows 10 ended on that date. A Windows 10 PC will continue to work, but without an applicable Extended Security Updates programme it no longer receives Microsoft's normal security fixes.

If your computer supports Windows 11 and you have no specific reason to remain on Windows 10, moving to Windows 11 is normally the safer long-term choice.

Quick security checklist: Install legitimate Windows updates, make sure Windows Security reports no unresolved problems, keep the firewall enabled, use a PIN/Windows Hello or other strong sign-in method, enable multi-factor authentication on important online accounts, use BitLocker or Device Encryption where available, avoid unknown downloads and phishing links, use Standard accounts for everyday users and keep at least one independent backup of important files.

1. Start With a Supported Version of Windows

The security features installed on a PC are only part of the picture. The operating system itself also needs to receive security updates.

CURRENT WINDOWS PLATFORM

Windows 11

Windows 11 remains Microsoft's supported desktop Windows platform and continues to receive current security updates and security-feature development on supported hardware.

LEGACY WINDOWS

Windows 10

Normal Windows 10 support ended on 14 October 2025. Windows 10 can continue working, but standard security servicing has ended unless an applicable Extended Security Updates programme is being used.

Windows 10 Consumer Extended Security Updates

Eligible personal Windows 10 version 22H2 PCs can enrol in Microsoft's Consumer Extended Security Updates programme.

Microsoft currently provides eligible enrolled consumer devices with critical and important security updates through:

12 October 2027

ESU does not provide:

  • New Windows 10 features.
  • A new Windows 10 version.
  • Normal feature development.
  • Full Microsoft technical support.

Antivirus software cannot replace operating-system security updates. Running an unsupported copy of Windows with antivirus installed can still leave vulnerabilities in Windows itself unpatched.

If you are unsure whether an older PC can move to Windows 11, see our Windows 11 compatibility guide.

2. Keep Windows Security Updates Current

Security updates fix vulnerabilities discovered in Windows and its components.

Windows 11

Open:

Settings → Windows Update

Then select:

Check for updates

Windows 10

Open:

Settings → Update & Security → Windows Update

Then select:

Check for updates

Windows 10 users: if the PC is not enrolled in an applicable ESU programme, seeing “You're up to date” does not mean Windows 10 has returned to normal Microsoft support.

Restart when required

Some security updates do not finish installing until Windows restarts.

If Windows shows a pending restart, save your work and allow the restart to complete rather than leaving the update unfinished indefinitely.

Avoid unofficial Windows security patches

Use Microsoft's Windows Update system for normal Windows servicing.

Be cautious of third-party tools claiming to:

  • Extend Windows support unofficially.
  • Provide replacement Windows security patches.
  • Bypass update eligibility.
  • Install modified Windows updates.

Hardware drivers can legitimately come from the computer or component manufacturer, but Windows operating-system updates should normally come from Microsoft.

3. Check the Windows Security App

Windows Security is built into Windows 10 and Windows 11 and provides a central place to check many important protection features.

Open the Start menu and search for:

Windows Security

The main areas can include:

Virus & threat protection

Microsoft Defender Antivirus status, scans, malware protection and related settings.

Account protection

Information about Windows sign-in and account security.

Firewall & network protection

Check firewall status for the network profiles used by the PC.

App & browser control

Reputation-based protection, Microsoft Defender SmartScreen and related protection against unsafe apps, files and websites.

Device security

Hardware-backed security such as TPM information, Secure Boot and core-isolation features where supported.

Device performance & health

Windows can report certain storage, application, battery and system-health issues.

Do not simply assume the green shield means every aspect of your online security is covered. Windows Security protects the device, but secure passwords, account protection, backups and careful behaviour are still essential.

4. Make Sure Antivirus Protection Is Active

Windows includes Microsoft Defender Antivirus.

It provides protection against threats including:

  • Viruses.
  • Malware.
  • Ransomware.
  • Spyware.
  • Potentially unwanted applications.
  • Suspicious downloaded files.

Check Defender status

Open:

Windows Security → Virus & threat protection

Check whether Windows reports that protection is active and whether any action is required.

Real-time protection

Microsoft Defender Antivirus normally provides continuous real-time scanning while the PC is being used.

Do not permanently disable real-time protection simply because an online guide suggests it may improve performance.

Be suspicious of instructions telling you to disable Defender before installing unknown software. Malware frequently relies on persuading users to weaken security controls first.

Do you need another antivirus?

For many home users, the security built into a properly updated Windows installation provides a strong baseline.

However, that does not mean that another security product is never appropriate.

A third-party security package may still make sense where:

  • A business has a centrally managed security platform.
  • An organisation has specific compliance requirements.
  • You need features not included in the standard Windows security tools.
  • An IT administrator specifies a particular endpoint-security product.

If another recognised antivirus product is installed and active, Microsoft Defender Antivirus may automatically move out of its normal active-antivirus role. Avoid running multiple competing real-time antivirus products unless the vendors specifically support that configuration.

5. Keep Windows Firewall Enabled

Windows includes a built-in firewall that controls network traffic entering and leaving the computer.

Open:

Windows Security → Firewall & network protection

You may see network profiles including:

  • Domain network.
  • Private network.
  • Public network.

The active profile should normally show that the firewall is enabled.

Do not disable the entire Windows Firewall just to make one application work. If legitimate software needs network access, investigate the specific firewall rule or vendor instructions instead.

Public vs Private networks

Windows treats networks differently depending on how they are classified.

Private network

Appropriate for a trusted network such as your own secured home network where local device discovery may be required.

Public network

More restrictive and normally appropriate for networks you do not control, such as public Wi-Fi.

Do not mark an unknown café, hotel or airport network as Private merely to make device sharing easier.

6. Use SmartScreen and Reputation-Based Protection

Windows includes reputation-based protection designed to warn about suspicious apps, files, downloads and websites.

In Windows Security, open:

App & browser control

and review the available Reputation-based protection settings.

Microsoft Defender SmartScreen can help protect against:

  • Known malicious websites.
  • Phishing pages.
  • Suspicious downloads.
  • Potentially unwanted applications.
  • Files with poor or unknown reputation.

Do not automatically click “Run anyway” when Windows warns about an unknown application. First verify where the file came from and why Windows is warning you.

Smart App Control is different

Current Windows 11 versions can also provide Smart App Control on eligible installations.

Smart App Control is a Windows 11 security feature designed to help block untrusted or potentially harmful applications.

Smart App Control is not available in Windows 10. Do not follow a Windows 11 guide expecting to find every security feature on a Windows 10 PC.

7. Use Separate User Accounts

If more than one person uses the computer, give each person their own Windows account.

This helps keep:

  • Files separate.
  • Browser profiles separate.
  • Application settings separate.
  • Permissions easier to manage.

Use Standard accounts for everyday users

Not everyone needs Administrator access.

Using a Standard account reduces the amount of system access available to an accidental or malicious action performed under that account.

8. Protect Your Windows and Online Accounts

Device security is weakened if somebody can easily take over the account used to access it.

Use Windows Hello

Supported Windows devices can use Windows Hello sign-in methods such as:

  • PIN.
  • Fingerprint.
  • Facial recognition.

Open:

Settings → Accounts → Sign-in options

to see the methods available on your device.

A Windows Hello PIN is tied to that device. It is not simply another reusable online-account password.

Use multi-factor authentication

For important online services, enable multi-factor authentication where available.

This is particularly important for:

  • Email.
  • Microsoft accounts.
  • Google accounts.
  • Online banking.
  • Cloud storage.
  • Business services.
  • Password managers.

If an attacker learns your password, an additional authentication step can prevent that password alone from being enough to access the account.

Use passkeys where available

Passkeys are increasingly available as an alternative to traditional passwords.

They can provide stronger resistance to phishing because the credential is tied to the legitimate service rather than being something you type into any page that asks for it.

Never reuse important passwords

If the same password is used across several websites, one compromised service can expose your other accounts.

Use unique passwords for important accounts and consider a reputable password manager if you have difficulty managing them securely.

9. Lock the PC When You Walk Away

Security controls provide little benefit if an unattended computer remains unlocked.

The fastest manual method is:

Windows key + L

This immediately locks Windows.

Dynamic Lock

Windows can also use Dynamic Lock with a paired Bluetooth device such as a phone.

When Windows detects that the paired device has moved away, it can automatically lock the PC.

Dynamic Lock can be useful as an additional precaution, but it should not replace the habit of manually locking the PC when leaving it unattended.

Windows key + L is immediate. Dynamic Lock relies on Bluetooth detection and is better treated as an additional safeguard rather than your primary locking method.

10. Encrypt Important Drives

Encryption protects stored data if a computer or drive is lost, stolen or removed from its normal Windows environment.

Device Encryption

Compatible Windows devices can support Microsoft's simpler Device Encryption feature.

Device Encryption is available on a wider range of devices and can include Windows Home where the hardware and configuration support it.

BitLocker Drive Encryption

Windows Pro, Enterprise and Education provide the full BitLocker Drive Encryption management tools.

BitLocker can be used to protect:

  • The Windows system drive.
  • Additional internal drives.
  • External storage.
  • USB drives using BitLocker To Go.

Protect the recovery key

A BitLocker recovery key is a unique 48-digit number that can be required if Windows cannot unlock an encrypted drive normally.

Microsoft Support cannot retrieve, provide or recreate a lost recovery key.

Make sure you know where the recovery key is stored before relying on BitLocker encryption.

For detailed guidance, see:

11. Treat Email, Messages and Login Pages as Security Risks

Many successful cyber attacks do not begin by technically “hacking Windows”.

They begin by convincing somebody to:

  • Open a malicious attachment.
  • Click a fake login page.
  • Install remote-access software.
  • Reveal a password.
  • Approve an unexpected authentication request.
  • Send money to a fraudulent bank account.

Signs of a phishing message

Be cautious when a message:

  • Creates artificial urgency.
  • Threatens account closure.
  • Claims an unexpected payment is due.
  • Requests a password or security code.
  • Asks you to bypass normal company procedure.
  • Contains an unexpected attachment.
  • Uses a link that does not match the organisation it claims to represent.
  • Requests a sudden change of bank details.

Do not approve an authentication request you did not initiate. An unexpected MFA prompt can mean somebody already has your password and is attempting to sign in.

Open important websites yourself

For banking, Microsoft accounts, cloud services or other sensitive services, it can be safer to open the known website yourself rather than following an unexpected email link.

12. Install Software From Trusted Sources

Installing unknown software is one of the quickest ways to compromise a Windows PC.

Before installing anything:

  • Check who publishes it.
  • Use the developer's official website where possible.
  • Avoid unofficial “download portal” repackaged installers.
  • Do not use pirated or cracked software.
  • Take Windows security warnings seriously.
  • Check that the software is still supported.

Be particularly cautious with software that asks you to disable antivirus protection, turn off SmartScreen or run an unexplained command as Administrator.

Administrator permission matters

When Windows displays a User Account Control prompt, check what program is asking for permission before selecting Yes.

Administrator permission can allow software to make major changes to the computer.

13. Keep Backups That Ransomware Cannot Destroy

A backup is one of the most important security protections because not every incident can be prevented.

Backups can help recover from:

  • Ransomware.
  • Drive failure.
  • Accidental deletion.
  • Computer theft.
  • A damaged Windows installation.
  • Malicious file deletion.

Do not rely on one copy

If the only copy of an important file is stored on your PC, it is not backed up.

A stronger backup arrangement can include:

  • Your working copy on the computer.
  • A separate external backup.
  • A reputable cloud or off-site backup.

An external drive that is permanently connected to the computer may also be accessible to ransomware. A backup strategy should include a copy that is not continuously exposed to the PC.

Test that you can restore files

A backup that has never been checked may fail when you actually need it.

Periodically confirm that important files can genuinely be restored.

14. Protect Your Browser

The web browser is one of the main routes through which a computer interacts with potentially hostile content.

For safer browsing:

  • Keep the browser updated.
  • Remove extensions you no longer use.
  • Install extensions only from reputable sources.
  • Do not ignore certificate or security warnings.
  • Avoid downloading unknown executable files.
  • Do not allow websites to install unexpected software.
  • Check the real domain before entering login information.

Browser extensions can access sensitive information

Some extensions can read or alter information on websites you visit.

Periodically review installed extensions and remove anything:

  • You do not recognise.
  • You no longer need.
  • That has changed ownership unexpectedly.
  • That requests permissions unrelated to its purpose.

15. Secure Your Wi-Fi and Home Network

Windows security cannot compensate for a badly configured network.

Change the router administrator password

Do not leave a router using a publicly known default administrator password.

Use modern Wi-Fi encryption

Use the strongest security mode supported by your router and devices, preferably a modern WPA2 or WPA3 configuration rather than obsolete standards.

Keep router firmware current

Check the router manufacturer's support information for security and firmware updates.

Be cautious on public Wi-Fi

On networks you do not control:

  • Use the Windows Public network profile.
  • Avoid unnecessary file sharing.
  • Prefer encrypted websites.
  • Be cautious with sensitive account activity.
  • Consider using your mobile connection where the public network appears suspicious.

A VPN is not a replacement for antivirus, updates or safe browsing. It protects particular network traffic; it does not make malicious websites, files or applications safe.

16. Be Careful With Remote Access

Remote-access software is legitimate and useful, but scammers frequently misuse it.

Never give an unknown caller remote access to your computer simply because they claim to be from:

  • Microsoft.
  • Your bank.
  • Your broadband provider.
  • A retailer.
  • A security company.

Microsoft does not unexpectedly call ordinary users to tell them their PC has a virus and ask for remote access. Treat unsolicited technical-support calls as suspicious.

Remote Desktop

If you deliberately use Microsoft's Remote Desktop feature:

  • Use strong account security.
  • Limit which users can connect.
  • Keep Windows updated.
  • Avoid directly exposing Remote Desktop to the open internet without appropriate network security.

17. Extra Security for Small Businesses

A small business should not treat cyber security as simply an employee's personal Windows settings.

At minimum, consider having documented rules covering:

User accounts

Give each person their own account and remove access promptly when staff leave.

Administrator access

Limit administrator permissions rather than giving every user unrestricted control.

Multi-factor authentication

Protect email, cloud storage, accounting and other important business services.

Updates

Maintain supported Windows, applications, browsers and network equipment.

Backups

Keep reliable backups and test that important business information can be restored.

Staff awareness

Make sure staff know how to report suspicious emails, payment requests and possible security incidents.

This article is general Windows security guidance, not a compliance assessment. Businesses handling regulated, confidential, health, financial or significant customer information should obtain appropriate professional security and compliance advice.

18. What to Do If You Think the PC Is Infected

If you notice unexpected behaviour such as security software being disabled, unknown programs appearing, browser redirects or suspicious account activity:

1

Disconnect if necessary
If active malicious activity is clearly taking place, disconnecting the PC from the network can limit further communication while you investigate.

2

Open Windows Security
Check Virus & threat protection and review any warnings or detected threats.

3

Run an appropriate scan
Microsoft Defender provides several scanning options, including more thorough scans when required.

4

Protect online accounts
If passwords may have been exposed, change them from a known-safe device and review account sign-in activity.

5

Check multi-factor authentication
Remove unknown devices or authentication methods and secure important accounts.

6

Restore carefully
Do not restore infected or unverified files straight back onto a cleaned computer.

If a business computer may have suffered a data breach, ransomware incident or significant account compromise, obtain professional assistance promptly. There may also be legal, contractual or regulatory reporting obligations depending on the information involved.

Windows 10 & 11 Security Checklist

1

Use a supported Windows configuration
Prefer Windows 11 on compatible hardware. If Windows 10 is necessary, understand its end-of-support and ESU position.

2

Install legitimate security updates
Use Windows Update and restart when required.

3

Check Windows Security
Resolve warnings rather than ignoring them.

4

Keep antivirus active
Microsoft Defender Antivirus provides built-in malware protection unless another recognised security product is managing that role.

5

Keep the firewall enabled
Do not disable all firewall protection to fix one program.

6

Use SmartScreen and reputation protection
Do not automatically bypass warnings about unknown applications.

7

Protect sign-in
Use Windows Hello, unique passwords, MFA and passkeys where appropriate.

8

Limit Administrator access
Use Standard accounts for ordinary users where practical.

9

Encrypt important drives
Use Device Encryption or BitLocker where appropriate and protect the recovery key.

10

Think before clicking
Phishing, fake support and malicious downloads remain major routes into Windows PCs.

11

Maintain independent backups
Make sure important data exists somewhere other than the live computer.

12

Secure the network
Protect the router, Wi-Fi and remote-access configuration as well as Windows itself.

Related Windows Security Guides

Frequently Asked Questions

Does Windows 11 include antivirus protection?

Yes. Windows 11 includes Microsoft Defender Antivirus as part of Windows Security. It provides built-in real-time protection against viruses, malware and other threats.

Does Windows 10 still include Microsoft Defender Antivirus?

Yes, but Windows 10 itself reached normal end of support on 14 October 2025. Antivirus protection does not replace operating-system security updates.

Do I need third-party antivirus with Windows 11?

Many home users use the security built into Windows successfully. A third-party security product can still be appropriate for particular business, management or specialist requirements. Avoid running competing real-time antivirus systems unless the products specifically support that setup.

Should Windows Firewall be turned on?

Yes. The Windows Firewall should normally remain enabled. If a legitimate application has a network problem, investigate the specific firewall rule rather than disabling the entire firewall.

What is Microsoft Defender SmartScreen?

SmartScreen is a reputation-based security feature that helps warn about phishing sites, malicious downloads, suspicious files and potentially unwanted applications.

Does Windows 10 have Smart App Control?

No. Smart App Control is a Windows 11 security feature. Windows 10 still has other reputation-based protections including Microsoft Defender SmartScreen.

Is a Windows Hello PIN safer than using no password?

Yes. A Windows Hello PIN is an authentication method tied to the particular device. Supported computers can also use Windows Hello fingerprint or facial recognition.

Should I use multi-factor authentication?

Yes for important accounts wherever it is available, particularly email, cloud storage, financial services and business accounts. It adds another barrier if a password is stolen.

What is the difference between BitLocker and Device Encryption?

Device Encryption is Microsoft's simpler encryption experience and is available on a wider range of compatible devices, including some Windows Home systems. Full BitLocker Drive Encryption management is available with Windows Pro, Enterprise and Education.

Why is the BitLocker recovery key important?

The 48-digit recovery key may be required if Windows cannot unlock an encrypted drive normally. Microsoft cannot recreate a lost BitLocker recovery key, so make sure it is stored safely.

Is Windows 10 safe to use in 2026?

Windows 10 continues to function, but normal support ended on 14 October 2025. Microsoft recommends moving compatible PCs to Windows 11. Eligible Windows 10 22H2 personal PCs can use Consumer ESU for critical and important security updates through 12 October 2027.

Can antivirus make unsupported Windows 10 secure again?

No. Antivirus can help detect malware, but it cannot replace security fixes for vulnerabilities in Windows itself.

What is the most important defence against ransomware?

There is no single defence. Keep Windows and applications patched, use active security protection, avoid suspicious files and links, protect accounts and maintain independent backups that can be restored after an incident.

Should I use an Administrator account every day?

Not necessarily. Standard accounts are sufficient for most everyday users and reduce the ability to make system-wide changes without administrator approval.

Is a VPN the same as antivirus?

No. A VPN protects particular network traffic and privacy aspects of a connection. It does not scan malicious files, patch Windows or make unsafe websites and applications trustworthy.

What should I do if I think my PC has been hacked?

Check Windows Security, run appropriate malware scans and secure potentially compromised online accounts from a known-safe device. For serious ransomware, business-data or account compromise incidents, seek professional security assistance promptly.

« Back to Blog

Need Help? Visit Our Help Centre

to top