Home · Guide
Cornerstone guide
Buy security in this order
Ads sell the top of the stack because that’s where the commissions live. Real household risk usually lives lower: reused passwords, no 2FA, stale devices, no backups. Fund the base first — even when that means buying nothing from us.
Affiliate disclosure: Hexento earns commissions from some security-software partner links. This guide deliberately ranks unpaid / built-in moves above several paid categories. See disclosure · methodology.
The gotcha
A VPN subscription on top of password123 and no backups is cosplay. You’re encrypting a path while leaving the doors unlocked. Order of operations beats brand loyalty.
Default stack (most people)
- 1 · Unique passwords + a manager you’ll actually use The jump from reused passwords to unique ones is the highest-leverage consumer security move available. Built-in (Apple Passwords / Google Password Manager) is allowed to win — see built-in vs dedicated. Paid managers earn the fee on mixed platforms, serious sharing, and recovery discipline — not as a morality tax.
- 2 · 2FA on email, bank, Apple/Google, and work Prefer app/hardware keys over SMS when the account offers it. If your email is soft, everything reset-able through email is soft.
- 3 · Automatic OS + browser updates Boring. Undefeated. “I’ll update later” is how old bugs stay open on the laptop that holds the tax PDF.
- 4 · Backups you have restored once Ransomware and dead drives don’t care about your VPN tier. A backup you’ve never tested is a rumor.
- 5 · Built-in malware protection, configured On modern Windows, Defender is a serious baseline (strong independent lab marks in recent tests — details on the antivirus hub). On macOS, the platform blocks a lot; paid AV is situational. Scareware pop-ups and “PC repair” upsells are not security — they’re extraction.
- 6 · Network hygiene for the life you actually live Personal hotspot on hostile Wi‑Fi when stakes are high; caution on mystery USB and fake codec sites. A consumer VPN can help on untrusted networks and ISP-visibility preference — it does not replace 1–5. Read when you don’t need a VPN before you prepay two years.
- 7 · Privacy ops only after the base holds Data-broker cleanup is real work with real tradeoffs. DIY opt-outs are allowed to beat paid services in measured tests — see DIY vs paid removal. Don’t fund a $100+/yr removal plan while your passwords are still shared across five shopping sites.
Skip paid tier-ups if…
- An ad scared you about “exposed IP” but you still reuse passwords.
- You’re stacking a suite (VPN + pass + AV + cleaner) from one checkout because the bundle looked tidy.
- You already pay for iCloud+ / Google One and haven’t used the backup and password features you already own.
- Your threat model is “my kid downloads games” and you’re shopping anonymity tools instead of account controls and browser defaults.
- You want a corporate compliance checkbox — consumer SKUs aren’t that; use what your employer ships.
Where money still makes sense (after the base)
- Dedicated password manager — mixed devices as a lifestyle, household sharing across ecosystems, or you need export/admin patterns built-ins make painful. Price reality check (2026-08 snapshot): Bitwarden Premium $19.80/yr (no classic intro trap; note the early-2026 increase from $10); NordPass and 1Password sit higher with real year-one vs renew gaps on some tiers — don’t buy on homepage “from” pricing alone.
- VPN — concrete job (hostile networks you use, deliberate ISP-visibility shift, a region library you care about). Always price year-two, not the ad.
- Paid antivirus / web shield — higher-risk browsing, shared PCs, or you want a second opinion beyond Defender and you’ll accept the renewal. Many suites double at renew (snapshot examples on the antivirus hub).
- Data removal — you’ve done the free path, exposure still matters (safety, stalking, doxx risk, relentless spam), and you value time over money. Paying first is optional for a lot of people.
What EFF-style ordering is really saying
Independent consumer-security education has repeated the same hierarchy for years: account takeover and patching dominate everyday risk; network-layer products are situational. Hexento’s version isn’t a new religion — it’s that hierarchy with prices, skip paths, and “no partner link” outcomes left intact.
A 20-minute audit (no purchase required)
- Turn on the password manager you already have; fix the worst reused logins (email first).
- Enable 2FA on email + Apple/Google + bank.
- Confirm OS update automatic; reboot if you’ve been postponing.
- Check that last week’s photos/docs exist in a backup you didn’t just invent.
- Only then open Pickguard or a hub if a paid gap remains.
FAQ
Why does Hexento sell VPN tools if VPNs are “tier 6”?
Because when the job is real, people still need a non-listicle decision. We’d rather help you skip than “win” a mis-sale. Pickguard can return no-fit on purpose.
Isn’t a suite simpler?
Simpler checkout ≠ simpler security. Suites bundle renewals and blur which layer failed. Prefer one tool you understand over five icons you ignore.
What about passkeys?
Use them where offered — they’re part of the password/2FA layer, not a reason to skip unique credentials elsewhere. Still back up recovery paths.
I’m a high-risk target. Does this order change?
Weight changes; foundations don’t vanish. High-risk folks still need airtight accounts and devices — then add hardened messaging, hardware keys, compartmentalization, and specialist help. A consumer VPN ad is still not a personal security program.
Next
Password hub · Built-in vs dedicated · Antivirus hub · VPN hub · Pickguard