SECURE BROWSING CyberArtical Editorial Team

Your browser is already secure by default, so keep it that way

The onion-shaped Tor Browser icon displayed on a computer screen

There is a whole genre of article that treats a fresh browser install as raw material to be hardened — a long list of toggles, flags and add-ons before it is fit to use. NCSC’s guidance takes a different view. Its stated position is that browsers are "secure by default", and that the work is to "prevent them from becoming insecure". That inverts the task. Most of what follows is about not undoing protections you already have.

Four things to leave alone or switch on

  • NCSC: browsers are "secure by default"; the objective is to "prevent them from becoming insecure".
  • NCSC: "Ensure automatic updates are turned on for both the browser and it’s extensions."
  • NCSC lists "preventing users bypassing certificate warnings" among the critical security features to manage.
  • FTC: keep your browser’s default security settings and "heed browser warnings".
  • NCSC on add-ons: extensions "increase the potential attack surface of your web browser, as this software may also contain security vulnerabilities."

Start by not touching the defaults

The FTC’s browser advice for avoiding malware opens with keeping the default security settings. That is easy to read past, but it is a real instruction: the shipped configuration is the tested one, and most of the settings people are told to change in tutorials were chosen deliberately by people who thought about them longer than the tutorial did.

Where a guide tells you to disable a warning, relax a block, or turn off a safe-browsing feature to make a site work, that guide is asking you to move your browser out of its default posture. That is the direction NCSC is warning about.

Turn on updates for the browser and its extensions

NCSC’s wording covers both: automatic updates on for the browser and for its extensions. People remember the first half.

An extension that has stopped updating is not neutral. NCSC describes extensions as increasing the potential attack surface of the browser because the extension software may itself contain vulnerabilities. An abandoned extension keeps its permissions and stops getting fixes.

CISA adds a small habit that makes updates actually land: "Routinely update your browser, close it out frequently." A browser left open for weeks may have downloaded an update it has not yet applied.

Certificate warnings are not an obstacle to get past

NCSC lists preventing users from bypassing certificate warnings among the critical security features to manage. It is worth sitting with what that implies. In a managed environment, the recommended configuration is one where clicking through the warning is not available at all.

As an individual you cannot usually remove the button, so the rule has to be behavioural: a certificate warning means stop. Not "I recognise this site, it is probably a renewal problem." The FTC’s version is the same instruction in three words — heed browser warnings.

The same applies to the download and site warnings the browser raises. They are the default protections NCSC is describing.

The padlock is not one of your security features

While you are auditing what you rely on, retire this one. The FBI’s public service announcement I-061019-PSA states: "Do not trust a website just because it has a lock icon or ‘https’ in the browser address bar." It was issued because criminals routinely fit valid certificates to phishing sites.

The FBI describes what the indicator was meant to convey — that traffic is encrypted and visitors can share data safely. Encryption of the connection says nothing about the honesty of whoever is at the other end. The FTC puts the consequence directly: your data "may be encrypted on its way to the site, but it won’t be safe from scammers operating the site."

What still works is reading the address. The FBI’s rule is to check "for misspellings or wrong domains within a link (e.g., if an address that should end in ‘.gov’ ends in ‘.com’ instead)". The FTC’s stronger version is to type the address yourself rather than following a link from a message.

How to tell you have got this right

  1. Open your browser’s About page. It should report that it is up to date, and the update setting should be automatic rather than "check now".
  2. Open the extensions page. Every extension listed should be one you can name a use for, and each should have automatic updates enabled.
  3. Check that safe-browsing or equivalent protection is at its default level, not reduced.
  4. Try to recall the last time you clicked through a warning. If you can, that is the habit to change.

The limits of a well-configured browser

A browser in its default, updated state protects the connection and blocks a decent share of known-bad destinations. It cannot tell that the plausible-looking shop you have chosen to buy from has no intention of sending anything.

That is a judgement problem, not a settings problem, and no amount of configuration substitutes for it. If a site does take your money or your details, the FTC’s fraud report page and the FBI’s IC3 are the places that want to hear about it.

Sources: NCSC UK — Managing web browser security · FTC — How to recognize, remove and avoid malware · FBI IC3 — PSA I-061019 on the lock icon and HTTPS · CISA — Best practices against tracking technologies and spyware · FTC — Are public Wi-Fi networks safe?

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from NCSC UK, the FTC and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories