What a VPN Actually Protects You From (And What It Doesn’t)

VPN marketing promises a lot. Here’s what a VPN genuinely changes about your security and privacy — and the real gaps it leaves open.

What a VPN actually does

A VPN (virtual private network) creates an encrypted tunnel between your device and a server run by your VPN provider, then routes your internet traffic through it. The UK’s National Cyber Security Centre (NCSC) frames this as a way to protect the confidentiality and integrity of data as it travels across a less-trusted network — the core, unglamorous job a VPN is built for. In practice that gives you two concrete things: your internet service provider (ISP) and anyone else on your local network can see that you’re connected to a VPN, but not which individual sites and services you’re visiting; and the destination websites you visit see the VPN server’s IP address rather than your own, which is why VPNs are widely used to reach a different region’s content or pricing. Cloudflare’s own explainer on VPNs describes this the same way — a VPN “masks” your IP address and encrypts your connection, rather than doing anything to the content itself.

What a VPN does not do

This is the part most VPN advertising glosses over. The Electronic Frontier Foundation (EFF), a digital rights non-profit that maintains one of the most widely cited independent security guides on the web, puts it plainly in its Surveillance Self-Defense project: VPN adverts often claim to be “the only tool you need to stop cyber criminals, malware, government surveillance, and online tracking”, and that claim “vastly oversells the benefits of VPNs”. A VPN is, in EFF’s words, best suited to one thing — routing your network connection through a different network. Specifically, a VPN will not:

  • Stop malware or viruses. A VPN encrypts a connection; it doesn’t scan files or block malicious downloads. That’s a different job, done by antivirus and endpoint security software — see VPN vs Antivirus: Do You Need Both?
  • Stop phishing. If you type your password into a convincing fake login page, a VPN does nothing to warn you or stop the theft.
  • Make you anonymous on sites you’re logged into. Hiding your IP address doesn’t hide who you are from Google, Facebook or your bank once you’ve signed in with your own account.
  • Stop tracking cookies and browser fingerprinting. Advertisers and analytics tools identify you through cookies, device characteristics and account logins, none of which a VPN touches.
  • Replace a strong password or two-step verification. If your password is weak or reused, or 2-Step Verification isn’t turned on, a VPN provides no protection against someone simply logging in as you.
  • Guarantee your provider isn’t watching. A VPN moves the point of trust from your ISP to your VPN provider. If that provider logs and sells your activity, you haven’t gained privacy — you’ve just changed who has the data.

The public Wi-Fi case is weaker than it used to be — but not gone

For years, “don’t get hacked on coffee-shop Wi-Fi” was the headline reason to use a VPN. That risk was real: open or poorly secured wireless networks make it easier for another device on the same network to intercept unencrypted traffic. It’s genuinely less urgent today because the large majority of websites now use HTTPS by default, which already encrypts the content of your connection to that specific site regardless of the network you’re on. EFF makes the same point in its VPN guidance: a VPN can still protect unencrypted traffic from surveillance on a public network, but that matters less than it once did now that most web traffic is HTTPS-encrypted anyway. What a VPN still adds on public Wi-Fi is hiding which sites you’re connecting to from the network operator, and closing the gap for the small amount of traffic that still isn’t HTTPS-protected. See our dedicated guide on public Wi-Fi security for the fuller picture.

So what should you actually rely on a VPN for?

Realistically: hiding your browsing metadata from your ISP and local network, changing your apparent location for region-locked content or pricing checks, and adding a layer of protection on networks you don’t control or trust. For everything else — malware, phishing, weak credentials, account takeovers, tracking by the sites you use — you need separate tools doing separate jobs. NCSC’s own guidance treats VPNs as one layer of a wider defence-in-depth approach, not a standalone fix, and pairs it with recommendations like keeping software updated, using a password manager and turning on 2-Step Verification everywhere it’s offered. See our beginner’s guide to online privacy basics for the rest of that stack.

FAQ

Does a VPN stop my employer or school from seeing what I do?

It can hide the destination of your traffic from that network’s operator, but if you’re using a work- or school-managed device, other monitoring software installed directly on the device isn’t affected by a VPN at all.

If I use a VPN, do I still need antivirus software?

Yes. They solve different problems — a VPN protects data in transit between your device and the internet; antivirus and endpoint protection defend the device itself against malicious files and programs. See VPN vs Antivirus.

Can a VPN provider see what I do online?

Technically, yes — your traffic passes through their servers. Whether they retain or act on that visibility depends entirely on the provider’s logging policy and whether it has been independently audited. See No-Logs / Privacy-Focused VPNs.

Compare providers built for different priorities

Compare VPN options →

Sources: NCSC – VPN device security guidance; EFF Surveillance Self-Defense – VPN glossary; EFF – Choosing the VPN That’s Right for You; Cloudflare Learning Center – What is a VPN?.