CYBER WELFARE

Protect your Digital Privacy

Download Security: Deciding Before You Install

Additional resource for the lesson “Download Security: Deciding Before You Install” — Online Security course

Most unwanted software is not forced onto a device. It is installed, deliberately, by someone who believed they were getting something else. Download security is the short set of checks that happen before that decision, rather than the cleanup afterwards.

A. Why this matters

Devices are rarely compromised by force. Far more often, someone downloads a file or an app believing it is what it claims to be: a document from a colleague, a free version of paid software, a security tool a pop-up insisted was necessary.

That makes download security a matter of a few seconds of judgement rather than a technical skill. The checks are short, and they happen at a predictable moment — before you click install.

The key idea: the question is almost never ‘is this file dangerous?’. It is ‘where did this actually come from, and did I go looking for it?’.

B. Key concepts

Six ideas, roughly in the order they come up.

The source, not the file

Where the software came from matters more than what it appears to be. Official app stores, the developer’s own website, or your organization’s approved catalogue.

Why it matters to you: Almost every practical rule here reduces to this one. If the source is right, the rest is usually fine; if it is not, no amount of caution afterwards compensates.

Official stores and their checks

Google Play and the Apple App Store review submissions and scan for known malicious behaviour. Android also runs Play Protect on the device.

Why it matters to you: The checks are not perfect — the resources on fake apps and fleeceware cover what still gets through — but the difference between a store and a random website is substantial.

Did you go looking for it?

Software you searched for, versus software that appeared and suggested itself.

Why it matters to you: This single question filters out most of the problem. A download prompted by a pop-up, an ad or an unexpected message deserves a different level of suspicion from one you initiated.

Unexpected attachments

Files arriving by email or message that you were not expecting, even from someone you know.

Why it matters to you: An account that has been compromised sends real messages to real contacts. Recognising the sender is not the same as expecting the file (R17).

Sideloading and unknown sources

Installing apps from outside the official stores, which phones normally block until you allow it.

Why it matters to you: There are legitimate reasons to do this. But if a website asks you to change that setting to install something, the setting is not the problem it is solving.

Bundled extras

Installers that include additional software, pre-ticked, alongside what you actually wanted.

Why it matters to you: This is why the ‘custom’ or ‘advanced’ option in an installer is worth the extra fifteen seconds. The default path often agrees to more than you intended.

C. A practical example: the free version

You need a tool to convert a file. A search returns several results, and the first is an advertisement offering exactly that, free.

What tends to happen

  • The page has a large, prominent download button — and several smaller ones that are also advertisements.
  • The installer runs and offers, pre-ticked, two other programs you did not ask for.
  • A week later the browser has a new default search engine, and advertisements appear in places they did not before.

Nothing was broken into. Every step was agreed to, quickly, by someone who wanted to convert a file and did not want to spend ten minutes on it.

The same task, three checks later

  • Skip the advertised results and go to the developer’s own site, or check whether the app store has it.
  • Read the installer screens rather than clicking through, and choose the custom option.
  • Untick anything you did not come for.

This is not a story about malware. It is the ordinary version, which is far more common — and the checks that prevent it are the same ones that prevent the serious version.

D. Try it yourself: the four questions

Not an exercise to complete once, but a short sequence worth running the next few times you install something.

Question 1 — Did I go looking for this?

  • If it appeared and suggested itself — a pop-up, an ad, an unexpected message — that alone is a reason to stop.

Question 2 — Where is it actually coming from?

  • An official store, the developer’s own site, or somewhere else?
  • Check the address, not the page design. Convincing pages are cheap to build.

Question 3 — Does it match what I expected?

  • The developer’s name, the number of reviews, the last update date.
  • A well-known app with a handful of reviews and a developer you do not recognise is not that app.

Question 4 — What is the installer agreeing to?

  • Choose custom or advanced rather than the default.
  • Untick anything you did not come for, and read the permissions an app requests at first launch.

Four questions, perhaps twenty seconds. They catch the ordinary problem and the serious one with the same effort.

E. Videos, articles and further resources

Independent and institutional sources in English.

FTC — Malware: how to protect against, detect and remove it
How unwanted software arrives, what it does, and the sequence for removing it if something has already been installed.
https://consumer.ftc.gov/articles/malware-how-protect-against-detect-and-remove-it

NCSC (UK) — What to do if your device is infected
A calm set of steps for a device that is behaving strangely after an install.
https://www.ncsc.gov.uk/section/respond-recover/citizen-infected-devices

Google — Use Play Protect to keep your apps safe and your data private
How Android checks apps before and after installation. Platform documentation rather than independent advice.
https://support.google.com/android/answer/2812853?hl=en

FTC — How to spot, avoid and report tech support scams
The specific case where a download is pushed by a fake warning. The rule to remember: a genuine security alert never asks you to call a number.
https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams

CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world

NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Secure Behavior pillar at level FL2. The knowledge is small; the habit is what protects.

Skills

  • Telling an official source from a convincing imitation.
  • Reading an installer rather than clicking through it, and choosing the custom option.
  • Checking a developer name, review count and update date before installing.

For professionals and organizations

  • Providing an approved catalogue, so people are not making these judgements individually every time.

Awareness

  • Understanding that most unwanted software is installed deliberately, under a misunderstanding.
  • Recognising that a familiar sender is not the same as an expected file.
  • Knowing that a request to allow installation from unknown sources is itself a signal.

For future instructors and ambassadors

  • Using the ordinary example — the free tool with bundled extras — rather than a dramatic one. People recognise it.

Secure Behavior

  • Installing from official stores and developer sites as a default.
  • Refusing downloads that were suggested rather than sought.
  • Not opening attachments you were not expecting, even from people you know (R17).

For organizations

  • Restricting installation from unknown sources on managed devices.

G. Questions to sit with

  1. When did you last install something? Did you go looking for it, or did it suggest itself?
  2. Do you read installer screens, or click through to get to the end?
  3. Have you ever allowed installation from unknown sources on your phone, and is that setting still on?
  4. If a colleague sent you an unexpected attachment right now, what would you do before opening it?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply to what you install.

Before installing

  • R17 — Do not open attachments from unknown sources, and treat unexpected ones from known senders the same way.
  • R9 — Check that you are connecting over HTTPS to the site you believe you are on.
  • MS2 — If your password manager does not recognise the site, the address is not the one you saved.

Keeping the device able to defend itself

  • R6 — Keep the operating system and applications up to date, with automatic updates on.
  • R5 and MS4 — Keep the device itself locked with a strong code, so an unwanted install is not compounded by open access.

The habit worth building

  1. Install from official stores and developer sites, not from search advertisements.
  2. Refuse anything that suggested itself rather than being sought.
  3. Choose custom in installers and untick what you did not come for.
  4. Leave installation from unknown sources switched off.

Four habits, no settings to maintain. They cover the ordinary nuisance and the serious compromise with the same twenty seconds.

In short

  • Almost nothing installs itself: the decisive moment is a decision you make.
  • The source matters more than the file — official stores and developer sites, not advertised results.
  • ‘Did I go looking for this?’ filters out most of the problem on its own.
  • The custom option in an installer is where the extras are unticked.

Related resources in this course

What happens when something does get installed:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program