A laptop displays cybersecurity protections as a locked Wi-Fi connection and a phishing email warning appear in a modern office.
A VPN and an antivirus do different jobs, and that gap decides what a "VPN threat protection" feature can safely replace. Many providers now bundle malicious-site blocking, ad filtering, and even file scanning into their apps. That makes the marketing question reasonable: can the VPN stand in for a dedicated antivirus on a Windows PC? The evidence says a VPN on its own can't. Its threat features are best treated as an extra layer.

Three different things sold under one label​

"VPN protection" can mean three separate things:

  • The tunnel. It encrypts your connection and hides your traffic from the local network and your ISP. It does nothing about a malicious file already on your disk.
  • A web filter. This blocks known-bad domains, trackers, ads, and sometimes phishing pages. It works at the connection or browser level.
  • An antivirus engine. This scans files on the device and watches what programs do. Some VPN subscriptions bundle one, but it is a separate component with its own platform support.

Surfshark's own FAQ makes the same distinction. It says a VPN protects privacy while antivirus protects the device. It also says a VPN can't do much once malware is already inside the machine. That is a vendor selling both products, so read it as a candid limit, not neutral advice.

What the independent evidence shows​

NordVPN's anti-phishing result. AV-Comparatives approved NordVPN Threat Protection Pro in a 2024 anti-phishing test. The test ran in May 2024 against 275 live phishing URLs on Windows, with 250 legitimate banking sites checked for false alarms. NordVPN blocked 85% and had no false alarms. That meets the lab's pass bar of at least 85% with zero false alarms.

The result is real, but narrow. It covers one feature, one version, one platform, and one month. It says nothing about malware already on the machine or about VPN threat filters in general. The lab said fifteen vendors submitted products and eight passed.

Surfshark's engine. Surfshark says the core of its antivirus engine is powered by the Avira Endpoint Protection SDK. It also says it mirrors Avira's engine and security-intelligence updates through its own servers. If a faulty update appears, it can halt distribution. TechRadar suggests VPN partners may lag behind Avira's own users. I found no evidence that quantifies such a lag, so treat it as a plausible risk, not a measured one. The same applies to TechRadar's claim about CyberGhost using Intego's frontend and Avira's engine, which I couldn't corroborate from primary sources.

Surfshark's product page adds practical limits:

  • Antivirus is sold only inside the Surfshark One bundle, not on its own.
  • It supports Windows 10 and later, macOS 11 and later, and Android 10 and later.
  • It doesn't run on Windows ARM or on non-64-bit Android.

Check those limits before assuming a Copilot+ Arm laptop is covered. Surfshark's feature descriptions also differ by page on which advanced detection is Windows-only, so confirm your exact OS in the app.

Where Microsoft Defender fits​

On Windows, you already have an antivirus. Microsoft describes Windows Security as including Microsoft Defender Antivirus, Windows Firewall, and Smart App Control. It says Defender provides real-time protection from the first boot.

TechRadar says Defender blocked 95.5% of threats with one false positive in AV-Comparatives' July–August 2026 run. I couldn't confirm that from the lab's page. The factsheet text describes the test setup:

  • 200 live malicious URLs.
  • Updated Windows 11 Pro 64-bit.
  • Cloud connectivity and product updates allowed.
  • Microsoft Defender Antivirus among the 20 products tested.

The per-product figures sit in a chart that wasn't readable in the text I could see. Treat the 95.5% figure as TechRadar's reading, not a confirmed number.

Other reports on the longer February–May 2026 run put Defender at 99.0% protection, blocking 396 of 400 cases. Those are secondary sources. They also describe Defender as sitting in the lab's top cluster with Bitdefender, Avast, AVG, Norton, and Kaspersky, which scored 99.3–99.8%. One secondary source reports zero false positives in that round. The takeaway is the same either way: Defender is competitive in these web-threat tests. The lab itself warns that a high score doesn't mean a product stops every web threat.

Should you stack a second antivirus?​

TechRadar's verdict is a layered mix of VPN, free antivirus, and OS protection. On Windows that advice needs a correction. Microsoft documents that when you install a compatible non-Microsoft antivirus, Defender Antivirus turns itself off automatically. So you aren't really running two real-time engines side by side. You are swapping one for the other.

For most Windows users, this is a sensible setup:

  1. Keep Defender active, or deliberately choose one third-party suite to replace it.
  2. Add a VPN if you want connection privacy, for example on public Wi-Fi.
  3. Treat any VPN web filter as a bonus layer, not the main defense.
  4. Keep Windows, browsers, and third-party apps patched. AV-Comparatives notes that patching sharply reduces the risk from exploits.

TechRadar's claims that paid suites are "insurance," or that a free tier is enough for everyone, aren't backed by the sources I checked. Paid suites do bundle extras such as password managers, backup, and identity monitoring. Those are separate features, not proof of better detection.

How to check your own PC​

Microsoft's documented steps:

  1. Search for Windows Security in the Start menu and open it.
  2. Go to Virus & threat protection. This page shows your current threats and last scan, and it manages settings for Defender and any third-party antivirus.
  3. Check that Real-time protection is on under Manage settings.
  4. To run a quick scan, select Quick scan.
  5. To scan one file or folder, right-click it in File Explorer and choose Scan with Microsoft Defender. On Windows 11 you may need Show more options first.
  6. If you suspect persistent malware, use the Microsoft Defender Antivirus (offline scan) option under scan options. It restarts the PC and scans from the Windows Recovery Environment, where malware has a harder time hiding. Save your work first. Results appear under Protection history.
  7. Under Protection updates, select Check for updates to make sure security intelligence is current.

If you turn off real-time protection temporarily, files you open or download won't be scanned until it switches back on. Microsoft says tamper protection must be off first if it is enabled.

The Mac angle​

TechRadar leans on Apple's protections as a contrast. Apple's documentation says macOS 10.15 and later require notarization by default. Notarization helps ensure apps are free of known malware. macOS also includes built-in antivirus protection that blocks and, if needed, removes malware. Apple describes these as layers of protection, not a guarantee. Its documentation also notes that in the EU, alternative app marketplaces and direct downloads from developers' websites bring additional risks. So "Apple has no antivirus" is wrong, and so is "built-in means invulnerable."

Bottom line​

A VPN's threat filter is a useful layer, and NordVPN's anti-phishing result shows it can be measured. But a filter that blocks bad sites can't replace a scanner that inspects files and behavior on the device. On Windows, the sensible baseline is a confirmed-active antivirus, either Defender or one third-party suite, with a VPN added for privacy. Verify the exact tier, operating system, and settings before you trust any bundled "antivirus" to cover your devices.

 

References

  1. VPN threat protection vs. dedicated antivirus: Are VPNs really enough? TechRadar 2026-10-07T15:44:24+00:00
  2. App security overview - Apple Support support.apple.com
  3. Protect your devices with Surfshark Antivirus surfshark.com