Guide

How to choose mobile security software in Australia

A working procedure for deciding whether to pay for a mobile security subscription, and which one, without relying on anyone's marketing claims — including the claims of the product this site links to.

The awkward truth about this category is that the shopping decision and the safety decision are only loosely connected. Most of what keeps a phone out of trouble costs nothing: keeping the operating system current, installing apps from the official store, using a screen lock, turning on a backup, and treating unexpected messages with suspicion. Paid software sits on top of that baseline. It can add real value, particularly on older Android devices and for people who want password management and link filtering in one place, but it cannot substitute for the baseline, and a purchase made before the baseline is in place is money spent in the wrong order.

So this guide starts with the question a vendor cannot answer for you: what are you actually covering?

Step one: name the risk you are buying against

Write down the thing you would be upset about. The answers people give tend to fall into five groups, and each points somewhere different.

Matching the concern to the kind of product that addresses it
If your concern isWhat actually addresses itWhere a paid suite helps
A malicious app or file on the deviceInstalling only from the official store, keeping the operating system updated, removing apps you no longer useOn Android, a scanner adds a second check over installed apps and downloads
Scam links in texts, email and messaging appsHabit: never opening a link from an unexpected message, and going to the organisation's own app or site insteadWeb and link filtering can flag known bad addresses before the page loads
Accounts being taken overUnique passwords and multi-factor authentication on email and banking firstA bundled password manager, if you will genuinely move your passwords into it
Losing the handsetScreen lock, device encryption, the platform's own find-and-erase service, and a current backupSome suites add their own locate and lock tools, which duplicate rather than replace the platform's
A child's deviceConversations, plus the platform's family settings; the eSafety Commissioner publishes advice for parents and carersContent filtering and screen-time features, where the suite offers them on your platform

If every row you care about is already covered by the middle column, the honest conclusion is that you may not need to buy anything. That conclusion is allowed. A guide that cannot reach it is not a guide.

Step two: check what your platform permits

A feature list is written once and sold on both platforms, but the platforms do not grant the same access. On Android, an app can be given broad permission to inspect other installed applications and files. On iOS, the operating system's design keeps apps largely separated from one another, which means a security product there works mostly at the network and browser level rather than by scanning the device. The practical consequence is that two people can buy the identical subscription and receive substantially different things.

Before paying, find the vendor's own per-platform feature table and confirm that the feature you are buying for exists on the device you own. This is covered in detail on the Android and iOS page.

Step three: decide how much of a bundle you want

Most products in this category are bundles. A typical one might combine malware scanning, web filtering, a VPN, a password manager, breach notifications and some device clean-up tools. Bundles are genuinely cheaper than buying each part separately, and they are also how unused features get paid for year after year.

A reasonable test: for each component, ask whether you would pay for it on its own. If the answer is no for everything except one item, price that item separately before buying the bundle. If the answer is yes for three or more, the bundle is probably the better value. The features page defines each of these terms so the list can be read without guessing.

Step four: read the money terms before the feature list

This is where most later regret originates. Four things to establish, all of which the vendor must state somewhere:

  1. The renewal price

    The advertised first-term price and the ongoing price are often different. Find the ongoing figure and decide based on that, in Australian dollars, including GST if it applies.

  2. The renewal mechanism

    Establish whether the subscription renews automatically, how far ahead you are notified, and whether you can switch that off at purchase rather than later.

  3. The cancellation route

    If you buy through the Apple App Store or Google Play, the subscription is managed in your store account and cancelled there. If you buy directly from the vendor, it is cancelled with the vendor. Knowing which applies before you pay saves considerable time afterwards.

  4. The refund position

    Note what the vendor offers, and note separately that consumer guarantees under the Australian Consumer Law apply regardless of a vendor's own policy. The ACCC sets out how those guarantees work. The subscriptions page covers this in more depth.

Step five: look at what the product collects

Security software, by its nature, sees a lot: which apps are installed, which addresses the browser requests, sometimes the contents of a scan log. Read the vendor's privacy policy rather than the feature page, and look for three things — what is collected, whether any of it is shared with third parties, and where it is stored. If the product includes a VPN, the logging policy for that component matters more than for anything else in the bundle, because a VPN provider sits in the path of all your traffic.

Australian readers can complain to the Office of the Australian Information Commissioner about the handling of their personal information, and the OAIC publishes the Australian Privacy Principles that set the standard.

Step six: install, then check it is doing something

After purchase, confirm the product is active rather than assuming it. Open it once a month for the first quarter: check that the licence is registered to your device, that any real-time component reports itself as running, and that updates are being applied. A subscription that lapsed silently protects nobody, and a licence that was applied to the wrong handset is a common and quietly expensive mistake in households with several devices.

A note on what this cannot fix

No security product prevents you from typing your banking password into a convincing copy of your bank's website, approving a payment to a scammer, or handing remote access to someone who has phoned claiming to be from a telco. Those are the approaches that cause the most financial harm to Australians, and the defence for them is procedural, not technical: independently verify who you are talking to, using contact details you looked up yourself. Scamwatch publishes current examples.

Claims to treat carefully while shopping

  • "Complete" or "total" protection. No product stops everything, and a seller in Australia has to be able to substantiate what it advertises.
  • Detection percentages without a named source. If a figure is not attributed to a published test by an independent laboratory, with a date, it is not evidence.
  • A warning about your specific device, shown by a web page. A website cannot scan your phone. Anything that appears to do so is an advertising device.
  • Countdown timers and "offer ends tonight". Pressure to act quickly is not information about the product.
  • Feature lists with no platform column. Ask for the per-platform breakdown before paying.

Where the product covered on this site fits

TotalAV is an antivirus product. The offer Avalon Base links to is the vendor's mobile offer, listed for mobile devices and tablets running Android, iOS and Windows. This site does not publish a score for it, a price for it, or a feature comparison against other vendors, because it has not tested it and because the commercial relationship makes any such ranking worth less than the paper it is written on. What is useful is the procedure above, applied to the vendor's own current documentation.

Visit the TotalAV website

Related reading on this site