Windows 11 Security Guides

63 free step-by-step guides covering the whole picture: removing malware that is already there, turning on the Windows 11 protections that stop the next one, securing the accounts most attacks actually target, and locking down your router and smart home devices.

Every fix uses tools built into Windows or into the service itself. Nothing here requires buying software, and every step that could affect your files says so before you reach it.

Start Here

Match what you are seeing to the closest row, then open the guide that walks you through it. If something is happening right now, disconnect the PC from the internet before you start.

What you are seeingLikely causeStart here
Files renamed with a strange extension and a ransom noteRansomware, still possibly runningRansomware response
You let a "support agent" onto the PC remotelyRemote access scam with full control of the machineAfter a remote access scam
Fans loud and the PC slow with nothing openA cryptominer using your CPU or GPURemove a cryptominer
Ads and redirects on every siteA hijacked browser or a malicious extensionAudit browser extensions
Malware keeps coming back after every scanA scheduled task or service is restoring itClear persistence
Sign-in alerts from places you have never beenA reused password exposed in a breachCheck breach exposure
Phone suddenly lost signal and accounts are resettingA SIM swap in progressSIM swap response
A camera feed or PC reachable from the internetPort forwarding or UPnP opening the firewallClose open ports

Something Is Wrong Right Now (11 guides)

Start here if an infection, a scam call, or a hijacked account has already happened. These are ordered by what to do first.

Harden Windows 11 (10 guides)

The settings that stop the next infection doing damage. Every one of these is built into Windows and costs nothing.

Accounts, Passwords, and Identity (9 guides)

Most compromises start with a credential, not with malware. Fix the account layer and the rest gets much harder to attack.

Network, Router, and Smart Home (8 guides)

Your router is the one device every other device depends on, and cheap smart gadgets are the weakest thing on the network.

Scams and Online Safety (8 guides)

The attacks that reach real people every day arrive by email, text, and phone — not through a vulnerability.

Backups and Safe Disposal (5 guides)

The layer that decides whether an incident is an inconvenience or a disaster — plus how to hand a PC on without handing over your data.

More Security Guides (12 guides)

Everything else in the security and privacy category, newest first.

The Order That Actually Works

Security advice tends to arrive as a long undifferentiated list. It is not equally weighted. If you do four things and stop, do these: unique passwords in a password manager, two-factor authentication on your email, a backup that is not always connected, and a standard user account for daily use. Those four remove the routes behind the overwhelming majority of real incidents.

Cleanup comes before hardening. Turning on protections while something is already running on the machine gives you a false sense of the state it is in — and some settings will not stick until the infection is gone. Work through removal first, verify with an offline scan, then harden.

Assume account compromise travels with device compromise. If malware ran on the PC, change passwords from a different device and revoke active sessions afterwards, because a stolen session token keeps working long after the password changes.

Finally, treat backups as the layer that decides how bad an incident is. Every other control on this page reduces the chance of something happening. A backup that is offline, tested, and recent is what makes it survivable when one of them fails.

Common Questions

What should I do first if I think my PC is infected?
Disconnect it from the internet, then run a full scan followed by a Microsoft Defender Offline scan. The offline scan matters most, because it runs before Windows loads and catches things that hide from a live scan. Only after that should you change passwords, and do it from a different device.
Is Microsoft Defender good enough on its own?
For most home users, yes — provided real-time protection, cloud-delivered protection, and tamper protection are all on. The bigger wins are the settings people leave off: Memory Integrity, Controlled Folder Access, potentially unwanted app blocking, and a standard user account.
Which security setting gives the most protection for the least effort?
Unique passwords in a password manager with two-factor authentication on your email account. Most compromises begin with a reused credential rather than with malware, so fixing the account layer removes the most common route in.
Do I need to pay for antivirus?
No. Windows Security is competitive with paid products in independent testing, and paid suites often disable Windows own layers while adding upsells. Spend the money on a backup drive instead.
How do I know whether a warning is real or a scam?
Real Windows warnings never include a phone number, never appear inside a browser tab, and never use countdown timers or sirens. Windows Security lives in Settings, not in a pop-up. If a number is shown, it is a scam.
Should I use a VPN for security?
A VPN protects traffic on untrusted networks and hides your IP address from sites you visit. It does not stop malware, phishing, or account takeover. It is a useful tool for a specific problem, not a general security product.
How often should I change my passwords?
Only when there is a reason: a breach notification, a suspected compromise, or a password you know is reused. Forced rotation on a schedule tends to produce weaker, more predictable passwords. Unique and long beats frequently changed.
Is two-factor authentication by SMS worth using?
It is much better than no second factor and stops automated credential-stuffing attacks. It is the weakest common option because a SIM swap defeats it, so use an authenticator app or a passkey on email, banking, and anything holding money.
What is a passkey and should I use one?
A passkey replaces a password with a private key held on your device and unlocked by your face, fingerprint, or PIN. It cannot be phished, reused, or leaked in a breach because the site never stores anything reusable. Use them wherever they are offered.
Does a factory reset remove all malware?
Usually, but not always. Reset This PC preserves the EFI and recovery partitions, so a bootkit can survive it. If you suspect something below Windows, do a clean install and delete every partition on the disk first.
Are my smart home devices a real security risk?
Yes, mainly because they stop receiving updates quickly and sit on the same network as your PCs. Putting them on an isolated guest network means a compromised device cannot reach your computers or your files.
How do I know if my details are already in a breach?
Check your email address at haveibeenpwned.com, and use the password health check built into your browser or password manager. Register for future notifications rather than checking manually — you will usually hear before the breached company tells you.