How to use this: print it, put it somewhere you'll see it, and check boxes as they become true. Each line links back to the lesson that explains it — from the Personal Cybersecurity course. Print → Save as PDF gives a clean copy; site navigation is hidden in print.

The Done-Once List

  • Password manager installed — app + browser extension, autofill ON (2.3)
  • Master passphrase: 4–5 random words; emergency kit printed, filed where family can find it (2.3)
  • High-value accounts (email, carrier, bank, cloud) on generated, unique passwords (1.4, 2.4)
  • Security questions replaced with stored lies (2.4)
  • App-based 2FA on primary email; recovery codes in the manager (3.1, 3.4)
  • Passkey on at least one high-value account (3.3)
  • Every device: auto-updates, screen lock + biometrics, find-my-device, disk encryption confirmed (4.1)
  • Phone auto-backup on and recent; one local backup drive; one restore actually tested (4.3)
  • Router: admin password changed, WPA2-AES or WPA3, firmware current, IoT on guest network (4.5)
  • Have I Been Pwned alerts on every address (5.1)
  • Carrier PIN set (5.4)  ·  Credit frozen at Equifax, Experian, TransUnion (5.4)
  • Transaction alerts on every card; IRS IP PIN enrolled (5.4)

The Quarterly 15 Minutes

  • Open the manager's health report (Watchtower etc.) — fix anything flagged breached or reused (2.4, 5.1)
  • Check for updates that don't auto-apply — the router first (4.5)
  • Spot-check recovery codes exist in the manager for your 2FA accounts (3.4)
  • Glance at third-party grants + signed-in devices on master-key accounts; revoke strangers (5.5)
  • Restore one file from backup and open it (4.3)
Last quarterly check (date)
Annual account purge — last done (5.5)

The Second Tier — worth a line each

  • SIM PIN set on the phone itself (4.1)
  • Lock-screen message previews off — 2FA codes shouldn't show on a locked phone (4.1)
  • App permissions skimmed; location/microphone revoked where unjustified (4.1)
  • Browser extensions: few, recognized, audited (4.4)
  • New signups get a masked/alias address by default (5.2)
  • IoT end-of-life check: anything no longer updated is an appliance, not a computer (4.5)
  • Legacy contact / inactive-account manager set on Apple/Google accounts (2.3)
  • Never paste passwords, card numbers, or sensitive documents into AI chatbots

When an Alert Fires — the 20-minute drill (5.3)

  • Open the site via the manager, never via the alert's links → change that password
  • Manager report: hunt the reuse — verify blast radius is one site
  • Active sessions: recognize everything, or sign out everywhere
  • 2FA in scope? Regenerate recovery codes into the manager
  • Someone's actually in an account? → bluesecurityops.com/safety/i-was-scammed/