David Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. He has published his articles on such online media as Hackernoon, Tripwire, Infosecinstitute, and Cybrary.
- The Five Best VPN Providers for UK Citizens
The Five Best VPN Providers for UK Citizens
A Virtual Private Network (VPN) is no longer optional in an era of cybercrime epidemics, commercial tracking, and breaches of confidentiality by third parties. But the question is no longer if to get a VPN, but what VPN provider to choose.
While it's not exactly a clear cut choice - individual users have unique preferences - there are some VPNs that offer a more secure range of services. And privacy and security are the whole point, so they are the dominant criteria for choosing the best VPN for UK residents.
In the UK, VPN is a practical necessity for general privacy, online security, and bypassing censorship. Getting a VPN is especially important for those in the UK who aim at getting access to unrestricted Internet. While these VPN providers are not located in the UK, they easily cater to this market.
1. How to Select the Best VPN for UK Residents
Every VPN allows the bypassing of restrictions in certain regions as well as the encryption of data. And most of them are very easy to use - you just select a server, and it should connect relatively quickly.
VPNs are easy to understand, at least at a high-level. They change simply your IP address to a different location. Your traffic is redirected through a server in a particular country before being sent to the internet service provider.
The best VPN providers for the UK will have VPN applications for Android, Mac, IOS and Windows.They will also have extensions for Chrome and Firefox. But these are just the basics. When choosing the best VPN, the most relevant questions are:
- How many servers does the company provide, and in what countries?
- What is the logging policy of the VPN provider?
- What kind of security protocols does it use?
- What country of origin is the VPN provider based in?
2. UK Digital Surveillance
The United Kingdom is a surveillance state. The UK has more CCTV cameras per head than any other country in the world, with one per 14 people according to the British Security Industry Authority (BISA).
It is an official member of the 5 Eyes agreement which allows intelligence agencies in Canada, New Zealand, the USA, the UK, and Australia to spy on civilians and exchange data.
The 5 Eyes agreement is linked to the PRISM, xKeyScore, and Tempora privacy invasion regimes.
This is significant because intelligence agencies from the countries above can demand VPN providers for the UK to give up their logging history, with all of your data. So the best VPNs are those that are not located within the borders of the United Kingdom.
With all this in mind, the best VPN providers are:
- CyberGhost VPN
All of the above UK VPN providers do a great job at unblocking sites such as YouTube, Hulu, Netflix, BBC iPlayer, and many other popular streaming services. Some have servers optimized specifically for certain platforms, which will lead to enhanced performance.
Intro to NordVPN
NordVPN is arguably the best choice as a VPN for UK citizens and huge name in the online privacy industry. Its parent company is Telefincom S.A.
NordVPN allows users to connect up to 6 devices at the same time and has 24/7 customer support. It has applications for Windows, Mac, IOS, Android, Android TV, and Linux. It also features extensions for Chrome and Firefox.
NordVPN has more servers than any other provider, coming in at over 5,000. The provider has over 400 UK servers, which will enhance the speed of UK residents while connecting. It really excels for streaming HD content, which is what some of its servers are optimized for.
Payment and Pricing
NordVPN offers 4 subscription packages. The monthly subscription costs $11.95 per month. The yearly plan costs $6.99 per month. The two-year plan costs $4.99 per month. And the three-year plan costs just $3.49 per month. A free trial is available with all plans.
NordVPN accepts a variety of payment methods. These include Visa, Mastercard, Amex, Discover, AliPay, Amazon Pay, UnionPay, SoFort, GiroPay, Bitcoin, Ripple, and Ethereum.
Security and Encryption
NordVPN can double encrypt all data, adding an additional layer of security. Your data is passed not through one but through two servers. This feature is optional and perhaps even overkill. Encrypting data once should be enough, especially for those who just want to stream Netflix.
It uses AES 256-bit encryption which is the industry standard. Much like the ‘smart location’ feature for ExpressVPN, NordVPN has a ‘Quick Connect’ feature to find the best server near you in a different country.
NordVPN uses Next Generation Encryption (“NGE”) and Perfect Forward Secrecy (“PFS”)
It also has an optional feature called CyberSec which functions as an ad blocker.
The provider also has customized peer-to-peer servers for torrents. This means you can avoid bandwidth throttling when internet service providers decrease bandwidth on the IP address of torrent related sites.
NordVPN has a killswitch for Mac, Windows, Android, and IOS. They also provide a customizable killswitch for advanced users, specifying which applications should be blocked if a disruption occurs. The default killswitch is system-wide, meaning it blocks all traffic in the event of a disruption.
NordVPN is located in Panama, outside of the 14 Eyes and 5 Eyes spy networks. Panama has no mandatory data retention laws forcing providers to keep logs for extended time periods.
Panama is a country with a very friendly jurisdiction in terms of upholding the privacy rights of citizens.
NordVPN has a no-logs policy. They do track basic information such as basic performance data and email address. Your web activity logs are not kept so they do not know what you are looking at.
NordVPN has been audited by PriceWaterhouseCoopers (“PWC”), a top four accounting and compliance firm. The company has said that NordVPN does not log any customer data or keep IP address records. This means that there is third-party proof that they do not keep connection or activity logs.
This 2018 audit is not publicly available, but has been shared with pre-selected journalists.
These audits are highly important. Many providers have a no-log policy but keep logs anyway. Claims cannot be relied upon, which is why third-party audits are so necessary.
There are few real disadvantages with NordVPN. The most commonly cited problem is connectivity issues with certain servers and variable speeds. Also, it is quite expensive.
NordVPN is not accessible to Russian users. In March 2019, it received a directive from Russian authorities which it refused to comply with and is now banned in the region.
While all of the best VPNs are easy to use, NordVPN is one of the most intuitive and sleekest applications across devices and platforms. It’s very well designed.
It has a huge list of servers, especially in the UK. It also has servers designed specifically for streaming content. For UK residents abroad, it is perfect for gaining access to content.
It uses all of the latest security protocols such as NGE, perfect forward secrecy, and AES 256. It is one of the most secure VPN providers in the market. Its main flaw is that it lacks consistency across servers.
Intro to Surfshark
Surfshark is a relatively new VPN but it doesn’t mean that it is not already one of the best ones for the UK and other countries.
This service provides apps for Windows, Mac, iOS, Android, Linux, and FireTV as well as browser extensions for Google Chrome and Firefox. Such a wide variety of supported platforms is especially great to have because Surfshark allows unlimited simultaneous device connections.
The one area where Surfshark seems a bit lackluster compared to other VPNs on this list is the number of servers: it has 1040+ servers in 61+ countries. However, how uniformly they are distributed helps keep the speed at more than acceptable levels at all times even when connecting to a server that is situated across the Pond or in Eastern Asia.
Payment and Pricing
Surfshark is probably the least expensive VPN around. It has three plans: the 1-month one costs £9.49, which, while rather pricey, is still generally less than other providers ask for a similar level of quality and security. The fun, though, starts with the longer plans. The 1-year plan will cost you £4.79 a month or £57.48 per year. If that’s too much, you can always go with the 2-year plan which costs only £1.59 per month (£38.16 total). A 7-day free trial is available if you want to try Surfshark before buying it.
Another great thing about Surfshark is that it can be paid for using a credit card, PayPal, Alipay, Google Pay, or cryptocurrencies such as Bitcoin, Ethereum, or Ripple.
Security and Encryption
Despite its low prices, Surfshark definitely does not lack in terms of security. It uses AES 256-bit encryption which is the toughest one to crack (in fact, it is impossible to do at all with modern-day computers).
Users can choose between the OpenVPN, IKEv2, or Shadowsocks protocols in the app. It’s generally advisable to go with OpenVPN but on some devices, IKEv2 is a better option. Shadowsocks is the protocol to use if the former two are blocked by the network. Such a thing can happen in a corporate or educational environment so it’s great to have this possibility.
Like NordVPN, Surfshark enables double encryption with its MultiHop feature. It does, however, affect one’s speed negatively when turned on.
The CleanWeb feature in the Surfshark app serves as an ad blocker. Additionally, there is the ability to whitelist certain websites and IPs that you do not want to go through the VPN tunnel.
Obviously, Surfshark has a kill switch as any VPN should. Without this function, it is too dangerous to browse the Web.
In 2018, the company underwent an independent audit that confirmed its high degree of security. Unlike NordVPN, Surfshark has made the audit results public.
Surfshark is based in the British Virgin Islands. It is an offshore territory and is just as safe as Panama in terms of data retention laws. This jurisdiction is considered to be outside of the 14 Eyes’ influence.
Surfshark makes it abundantly clear that it does not collect and store its users’ connection and activity data. Since it is located in a safe haven for privacy, logging isn’t such a big concern anyway but it is great to see that the high standard is still upheld.
As was mentioned before, Surfshark’s server park is not as huge as those of its primary competitors. Despite that fact, its speeds are still rather high as a rule.
However, there is a bit of a disadvantage for the Brits hidden here. The problem is that there are only three locations inside the UK: London, Glasgow, and Manchester. Additionally, there is one more location in the Republic of Ireland. It is easy to imagine a situation where all these servers become overburdened, especially since some people from outside the British Isles will inevitably connect to them.
Another problem is the necessity to tie one’s credit card to a free trial account. It comes with auto-renewal to boot and one should be careful with the free trial if they do not plan on buying Surfshark.
Surfshark is a speedy and reliable service for anyone living in the UK. With it, it easy to stream and torrent as well as to protect one’s privacy online.
Its somewhat limited server network is more than made up for by its great prices. The total sum one has to pay for Surfshark’s 2-year plan is smaller than what three or four months worth of using many other VPNs cost.
The best thing is that it isn’t a compromise because Surfshark really does for this lower price most of what the other services on this list do for much higher ones.
2.3 CyberGhost VPN
Intro to CyberGhost VPN
CyberGhost VPN is a Romanian based UK VPN provider that was founded in 2011. They offer over 5944 servers in over 90 countries and allow up to 7 simultaneous device connections with 24/7 support.
The Romanian provider has applications for Windows, Mac, IOS, Android, Android TV, Linux, and routers. When first logging in, CyberGhost VPN asks what you intend to use the VPN for. The options include:
- Surf anonymously
- Unblock streaming websites
- Protect my Internet/Wi-Fi connection
- Torrent anonymously
- Unblock basic websites
This specification allows CyberGhost VPN to identify the servers that best suit your needs. Both NordVPN and ExpressVPN lack this level of detail. This server specialization is what sets CyberGhost VPN apart from other providers.
Payment and Pricing
CyberGhost VPN is one of the most affordable VPN providers that also offers an impressive range of services. A one-month plan costs $12.99. A six-month plan costs $7.99 per month. And an eighteen-month plan costs just $2.75 a month.
They also provide a 45-day money-back. Payment can be made in a variety of options including credit card, PayPal, and Bitcoin. CyberGhost VPN provides a free option. While far better than no security at all, the free option does lack many essential features.
Security and Encryption
CyberGhost VPN uses the standard AES 256-bit encryption. They also deploy perfect forward secrecy that randomly generates a new private key each time you log in. In addition, they have a killswitch to stop traffic getting leaked in the event of a disruption.
The CyberGhost VPN Chrome extension also offers a host of additional tools for increased security. These tools include an ad blocker, force HTTPS tool, and do not track tool. The application also features a killswitch which cannot be disabled.
CyberGhost VPN is a very open and transparent company. They have a public transparency report page that outlines any malicious activity found on their servers. They also list DMCA requests, law enforcement notices, and requests from national departments.
CyberGhost VPN is based in Romania, meaning it is outside of the 14 Eyes and 5 Eyes information sharing networks. Like the BVI and Panama, there are no mandatory data retention laws in Romania.
In 2009, the constitutional court of Romania (“CCR”) ruled that the implementation of the EU data retention directive was unconstitutional and violated the human right to privacy. In 2014, legislators applied more pressure to get the directive enacted with a revised edition.
However, these 2014 attempts were again struck down by the CCR, who seem to be upholding the rights of Romanian citizens.
The implications are that VPN providers do not have to keep customer data (logs) and the court will uphold the privacy rights of citizens - a very rare phenomenon in the modern era.
CyberGhost VPN publicly states that they do not keep activity or connection logs. There have been questions surrounding the installation of a root activity log when using specific privacy features. However, CyberGhost VPN removed this log in a subsequent update.
While they have a clear and unambiguous no log policy, they have not been audited by a reputable third-party. This is very relevant. Many highly regarded “no log” VPN providers later turned customers over to the authorities using withheld logs.
One annoyance is that creating a CyberGhost VPN account can be confusing. If you let CyberGhost VPN setup an account for you and then change your username/password, you will technically have two accounts.
If you are upgrading an account, ensure you are logging into the account with the premium features.
CyberGhost VPN was bought out in 2017 by a large Israeli company (the CrossRider Group, now known as Kape). Its parent company has a less than stellar reputation, said to have been the creators of malware in the past.
Also, their premium plans cost far more than the standard packages and it does not work well in China. CyberGhost VPN has not been audited, and they use third-party applications such as MixPanel and Instabug to collect statistical data through their VPN clients.
What's great about CyberGhost VPN is that it has specific servers designed for torrenting and streaming content. But even within these categories, it has designated servers designed for certain sites (Hulu, Netflix, BBC iPlayer, etc). These features are missing in many other top-level VPNs.
CyberGhost VPN is a great mix of affordability, speed, intuitiveness, and functionality. While they might not be as robust in terms of security compared to ExpressVPN or NordVPN, they do have function-specific servers and are a lot cheaper overall.
It's perfect for torrenting and people who want to stream abroad. It is also widely regarded as a super-fast VPN. CyberGhost VPN is most likely the best free VPN option for people looking for online security without paying anything, though this free service comes with limited functionality.
While great for streaming, it’s less ideal for people who are really serious about online security, such as cybersecurity specialists and people sending and looking at sensitive data.
Intro to ExpressVPN
ExpressVPN is one of the biggest names in the VPN industry for multiple reasons. Their servers are located in over 164 locations spanning 94 countries, with over 3,000 in total.
Additionally, they also have a massive range for all operating systems, including Mac, Windows, Linux, Android, and IOS. They offer a VPN service for routers and have extensions for Chrome and Firefox.
Pricing and Payment
Express VPN offers 3 main subscription plans. A one-month plan costs $12.95 a month. A six-month plan costs $9.99 per month. A twelve-month plan costs $8.32 per month. They also offer 24/7 support and a 30-day money back guarantee.
Payments can be made using Visa, Mastercard, American Express, Discover, JCB, Visa Electron, Diners Club International PayPal, Alipay, UnionPay, iDEAL, Klarna, WebMoney, Giropay, Yandex Money, Interac Online, Mint, OneCard, Carte Bleue, Maestro, FanaPay, and more.
There is an onion site provided for those who are really interested in anonymity. It accepts more payment methods than any other provider and also supports bitcoin payments.
Security and Encryption
The ExpressVPN killswitch is known as a ‘network lock’. A killswitch protects data when the internet connection is disrupted or when switching WiFi networks, as well as when your computer puts itself in sleep mode or powers off.
The network lock kicks in automatically, and a small sign pops up in the top right of the screen indicating “Network Lock Active” when there are any internet connectivity issues. Network Lock can be turned off, but this is not recommended. It cannot be turned off for routers.
ExpressVPN also uses perfect forward secrecy. Even if your device or session was compromised, the hacker cannot access past data. Every 60 minutes, a new key is generated. This means that a hacker can only access, at best, data one has been using for the last 60 minutes.
ExpressVPN goes further than all other VPN providers in terms of securing your data and ensuring online privacy. It also allows split tunneling for advanced users, meaning that the VPN routes traffic only for selected applications.
ExpressVPN is located in the British Virgin Islands, not the UK. This country has more robust personal privacy laws than the UK, which places a greater emphasis on intelligence gathering and national concerns compared to privacy and individual liberties.
The British Virgin Islands (BVI) is also out of the reach of European privacy law, and is not subject to European court rulings relating to data privacy as its own independent jurisdiction. This is why it is the perfect VPN for the UK.
BVI is even outside the notorious 14 Eyes Agreement, an expansion of the 5 Eyes where 14 countries seek to expand their influence over the public realm. The BVI is a self-governing group of islands located in the Caribbean.
The 14 Eyes agreement, like the 5 Eyes agreement, allows intelligence agencies to intercept international communications, not just domestic. This means that intelligence agencies can legally spy on the citizens of other countries and then exchange the data.
Express VPN keeps a no log policy. This means that they do not store logging history about customers who use their service. Unlike many other providers, their logging policy is very clear.
They do not keep activity logs. These are the most invasive logs that determine what content a user is looking at, along with the user location. But they also don’t keep connection logs, which contains information such as timestamps, source IP address, and the VPN IP address.
Many no log providers do not keep activity logs but will keep connection logs. ExpressVPN does collect some minimal information such as the choice of VPN server location, date (not time) of connection, and the total amount of data used per day. This is for technical reasons.
ExpressVPN cannot know what users are connected to particular IP addresses, or what websites a user visited, according to their website.
The only real disadvantage with ExpressVPN is that you have to pay a little more in comparison to other VPN providers. But for $3 - $5 extra per month, this should not be all that much of a concern. In fact, it's a bargain considering all it provides.
Many low-cost VPNs operate on razor-thin profit margins. This means that they have an incentive to sell logging information. And they are certainly not going to go to court against Federal authorities on behalf of customers paying them $0.99 a month.
Another possible downside of ExpressVPN is that it only connects 3 devices at once. Other providers offer more. But in practice, few regular users should need to operate more than 3 devices simultaneously.
ExpressVPN does not offer specific VPN servers for torrenting or streaming, unlike some other top VPN providers. But the biggest disadvantage of ExpressVPN is that its no-logging policy has not been audited by a reputable third-party provider.
Aside from this, they are the best UK VPN provider in the market.
In short, ExpressVPN ticks all of the boxes. The provider is located in a country with one of the best jurisdictions possible, the British Virgin Islands. No country or agency can compel the BVI to hand over customer data, and there are no data retention laws in the BVI.
ExpressVPN does not keep any customer logs, so it has nothing to show. They have a massive number of servers located across the world, an excellent killswitch feature, responsive customer support, a 30-day money back guarantee, and interoperability with all major platforms and devices.
They are one of the fastest and most reliable VPN providers and the applications work seamlessly across devices and platforms.
Additionally, they have servers in more countries than any other provider and the application is remarkably easy to use. They are one of few providers to work well in China, where VPNs are officially banned.
Find more information in our detailed ExpressVPN review.
Intro to IPVanish
IPVanish has been around for a long time, operating under Murdoch Marketing in 1999 and based in Florida, USA. They offer over 1,300 servers in 75 countries, predominantly in Europe and the USA. It allows 10 devices to be connected simultaneously, far more than most VPNs.
They are compatible with all major operating systems including Windows, Mac, Amazon Fire TV, Android, and IOS. For more technical customers, IPVanish allows configuring VPN apps for Kodi, Ubuntu, Chromebook, router, and Windows Phone configurations.
IPVanish has a large number of testimonials, social proofs, and endorsements from reputable industries on its main webpage and offers 24/7 support and a 7-day money back guarantee.
Payment and Pricing
IPVanish offers three affordable packages. The one-month package is just $5.00 a month. The three-month package is $4.50 a month. And the yearly package is $3.25 a month. IPVanish accepts all major payment methods but does not accept cryptocurrencies.
Overall, IPVanish is a very affordable provider.
Security and Encryption
Like most good VPN providers, IPVanish uses industry standard AES-256 encryption. But they also provide some additional security features, the main one being SOCKS. This is an extra protocol for obfuscation but without any performance penalty, making it perfect for torrenting files.
You don’t have to download any additional software to use the SOCKS protocol. However, while this is an advantage, SOCKS is not encrypted, which means it must be used with care. Users have to educate themselves about the protocol before using it effectively.
IPVanish offers a killswitch for Windows and Mac, DNS and IPv6 leak protection. It is unfortunate that there is no built-in killswitch for mobile applications, which means that smartphones can be a point of vulnerability if the connection drops.
IPVanish is based in the USA, and this raises serious concerns about their ability to secure customer data. The USA is a core member of the 5 Eyes agreement. In fact, the USA is probably the worst place a VPN provider can have their headquarters, with the possible exception of China.
The US is home to a series of draconian privacy laws and has a well-documented history of spying on citizens. Commercial entities and government departments often collude at the expense of online citizens.
Unfortunately, IPVanish has made headlines for handing over data to the Federal authorities. These complaints took place in 2016, and they have since been taken over by a new company, known as StackPath.
They still maintain that they keep a no-log policy. According to the company -
“We have a strict policy against the collection of both connection and activity logs. We will never store the metadata about your VPN session or information about how you used the service.”
This raises the very serious concern that “no log” providers are, in fact, keeping logs. This is not the only case where this has happened.
IPVanish is not the fastest VPN on the market, though this is obviously server and time dependent. The fact that they are located in the USA, handed data over to the authorities, and have been taken over recently are serious concerns about this provider.
The IPVanish interface is a little more ‘digital’ than other interfaces, with a black background and green writing. It seems to be orientated for more technical users than for regular people who simply want to stream movies. But it is still very user-friendly and easy to navigate.
It's also a very ‘cool’ interface that will appear to script kiddies and technical users. The server client features a graph in real time of both uploads and download speeds as well as other metrics such as the protocol used, server name, and time connected.
While this might not be essential, it definitely adds to the appeal. Because IPVanish offers a lot of complex and technical features, its interface can appear a little less user-friendly at first glance.
IPVanish excels at details missed by many other providers. You can select a server from a map, without having server ‘arrows’ overlapping each other. There are options to filter the servers by country, city, or ping time. You can also choose which server connects on startup.
For these reasons, IPVanish is the perfect VPN for technical users. It has the most options and features compared to nearly all other providers and is often favored by cybersecurity specialists for this reason. It is generally a ‘niche’ choice, good for distinct purposes.
For those who want to stream and avail of general online safety, there are alternative options.
Find more information in our detailed IPVanish review.
3. What About the Speed?
VPN providers can, in some instances, increase speed by avoiding bandwidth throttling, a tactic used by internet service providers to save money. But in truth, a VPN will nearly always reduce speeds from about 5% - 15% in total.
Some experts explain it by the encryption process.
In practice, there are too many variables to accurately gauge VPN speeds for the various providers. VPN speeds will depend on:
- If the server you are connecting to is busy or not
- The distance between you and the server
- The speed of your internet connection
- Upload speed v download speed
- Different hardware and software configurations for testing
- Many other items such as time of day, device, current activity, operating system, etc
Tests and studies on internet speeds give conflicting results. And even the results given are just an average of all server locations as accessed from one particular country. But users might want to select a particular server location frequently (such as Ireland) and avoid others completely (such as China).
Users might also want to complete certain activities, such as downloading torrents, uploading files, or streaming a movie. Different VPNs might be better or worse at these activities. Further, tests are only accurate over the time period through which the testing was completed.
It is best to just assume that using a VPN will slow down your overall speeds a little, but that this is a small price to pay for security and privacy. In information technology and many other areas, it is always going to be a tradeoff between convenience and security.
However, many tests do indicate that ExpressVPN is consistently fast across all regions and time periods due to the technology that they use. Other providers can be very variable in terms of their speeds. CyberGhost VPN and NordVPN are also very fast according to a number of reports.
4. Overall Best VPN Services for the UK?
While every VPN on this list is perfectly suited to UK citizens, the absolute best is hard to determine. It seems like there is a tie between NordVPN, Surfshark, and ExpressVPN.
There are arguments to be made for each of them. They are all fast, secure, and reliable. In the end, it largely comes to personal preference as much as to technical differences.
NordVPN and ExpressVPN have the largest numbers of servers in the largest number of countries. However, it does not render all other services useless. Not everyone needs VPN connections in so many countries.
Surfshark has the best quality-to-price ratio and can be safely said to be the workhorse VPN for many people. It does everything it has to without demanding large investments. On the other hand, its server park is not very big.
CyberGhost VPN is ideal for those who want to stream content without any hassle or sophisticated security concerns.
IPVanish is great for technical users but there are questions about its location and logging policies. Regardless, UK civilians need a VPN to protect their information in an age of mass privacy breaches and international geoblocks.