How to use this: print it, put it somewhere you'll see it, and check boxes as they become true.
Each line links back to the lesson that explains it — from the
Personal Cybersecurity course.
Print → Save as PDF gives a clean copy; site navigation is hidden in print.
The Done-Once List
- Password manager installed — app + browser extension, autofill ON (2.3)
- Master passphrase: 4–5 random words; emergency kit printed, filed where family can find it (2.3)
- High-value accounts (email, carrier, bank, cloud) on generated, unique passwords (1.4, 2.4)
- Security questions replaced with stored lies (2.4)
- App-based 2FA on primary email; recovery codes in the manager (3.1, 3.4)
- Passkey on at least one high-value account (3.3)
- Every device: auto-updates, screen lock + biometrics, find-my-device, disk encryption confirmed (4.1)
- Phone auto-backup on and recent; one local backup drive; one restore actually tested (4.3)
- Router: admin password changed, WPA2-AES or WPA3, firmware current, IoT on guest network (4.5)
- Have I Been Pwned alerts on every address (5.1)
- Carrier PIN set (5.4) · Credit frozen at Equifax, Experian, TransUnion (5.4)
- Transaction alerts on every card; IRS IP PIN enrolled (5.4)
The Quarterly 15 Minutes
- Open the manager's health report (Watchtower etc.) — fix anything flagged breached or reused (2.4, 5.1)
- Check for updates that don't auto-apply — the router first (4.5)
- Spot-check recovery codes exist in the manager for your 2FA accounts (3.4)
- Glance at third-party grants + signed-in devices on master-key accounts; revoke strangers (5.5)
- Restore one file from backup and open it (4.3)
| Last quarterly check (date) | |
|---|---|
| Annual account purge — last done (5.5) |
The Second Tier — worth a line each
- SIM PIN set on the phone itself (4.1)
- Lock-screen message previews off — 2FA codes shouldn't show on a locked phone (4.1)
- App permissions skimmed; location/microphone revoked where unjustified (4.1)
- Browser extensions: few, recognized, audited (4.4)
- New signups get a masked/alias address by default (5.2)
- IoT end-of-life check: anything no longer updated is an appliance, not a computer (4.5)
- Legacy contact / inactive-account manager set on Apple/Google accounts (2.3)
- Never paste passwords, card numbers, or sensitive documents into AI chatbots
When an Alert Fires — the 20-minute drill (5.3)
- Open the site via the manager, never via the alert's links → change that password
- Manager report: hunt the reuse — verify blast radius is one site
- Active sessions: recognize everything, or sign out everywhere
- 2FA in scope? Regenerate recovery codes into the manager
- Someone's actually in an account? → bluesecurityops.com/safety/i-was-scammed/