Imho two that are simply a must........
ZoneAlarm available at
http://www.zonelabs.com
and......
NeoTrace - available at
http://www.neotrace.com
The former checks that nobody is 'snooping' your machine, and the latter allows you to determine just where a server or IP address exists, who owns it, and via what routing your connection is being made to it.