<< 3) If there is worthwhile add-on software out there, please recommend, I'm fine with paying actual $ for good products. >>
Alas, there are no good products you could add that will help. Staying safe requires Vigilance, NOT more software.
You also need to put this in perspective. FAR, far, far more stuff is compromised due to poor choices of passwords, than will ever be compromised by drive-by Malware attacks, PROVIDED you are properly skeptical and practice the safe-computing skills you [should have] taught your ten-year-old. Email passwords that are short, too easy to guess, or made up with only a dictionary-word or two are MUCH more of a risk than malware -- IF you are Vigilant.
And regular users have less to fear because Advanced hacks not already seen and fixed require Really Advanced calibre hacking skills. If you are not a Target (because you are not a public figure or an activist) you are unlikely to bear the brunt of a Targeted attack.
Regular Mac users just get the messages from criminals that "Your Windows subscription has expired, pay here".