The Cybersecurity Course · Episode 17
Read time ~7 min · No prior knowledge

Ongoing
security routines

Everything this course has built — passwords, 2FA, updates, backups, networks — slowly rots without maintenance. But the maintenance is smaller than you think: a few habits, fifteen minutes a month, half an hour a quarter and one evening a year. Here is the full schedule as checklists, plus the routines for anyone running a company.

Contents
  1. From project to routine
  2. The checklists: daily, monthly, quarterly, yearly
  3. For the company: onboarding, offboarding and vendors
  4. Five sources worth following
  5. If you only have energy for three things

From project to routine

Sixteen episodes of measures is a project — and projects end. Security that lasts is instead a routine: small, recurring maintenance that keeps the protection from rotting as passwords leak, gadgets age and threats change shape. Good news: with the automation from earlier episodes (updates, backups, monitoring), the ongoing work is surprisingly small. Here is the full schedule.

The checklists: daily, monthly, quarterly, yearly

Daily — habits, not tasks

Monthly — 15 minutes

Quarterly — 30 minutes

Yearly — one evening

For the company: onboarding, offboarding and vendors

At onboarding

  1. Individual accounts from day one — never shared logins. MFA before the first workday ends (episodes 3, 15).
  2. The least privilege sufficient for the role — expand when needed, not the other way round.
  3. Walk through the routine document (episode 15) as part of the introduction.

At offboarding — same day

  1. Close all accounts (the SSO button from episode 15 makes this one action instead of twenty).
  2. Rotate shared secrets the person had access to: WiFi, payment cards, any shared accounts.
  3. Collect equipment and revoke the device's access in MDM.

Vendor onboarding

Every new service and vendor is a new door in. Before signing: Where is the data stored, and is there a data processing agreement (episode 14)? Does the service support MFA/SSO? What does their security track record look like — and how do they notify about incidents? Five minutes of questions that save months of aftermath.

Five sources worth following

The course has an end date — the threat landscape doesn't. Five subscriptions that keep you current without drowning you:

  1. CERT-SE — Swedish alerts and weekly digests; what actually concerns you locally.
  2. Krebs on Security — investigative journalism on the crime ecosystem; this course's most-cited source.
  3. Schneier on Security — wisdom on security's principles rather than the daily noise.
  4. Have I Been Pwned — not reading but alarms: emails when your addresses appear in new breaches.
  5. SANS Internet Storm Center — short daily situation reports for those who want one notch deeper.

If you only have energy for three things

A minute of honesty: not everyone will follow the whole schedule, and three things done beat twenty things planned. The priority order, if everything else falls away:

  1. A password manager + a unique password and 2FA on your email. Episodes 2 and 3 — closes the most common way in.
  2. Automatic updates on everything. Episode 5 — closes the second most common, with no ongoing effort.
  3. A working backup with one copy out of reach. Episode 9 — makes the worst case survivable.
The final episode All that remains is tying it together. Episode 18: your personal security plan — the threat profile analysis, the three-step plan and the master checklist summarising the whole course on one page.
Next episode

Episode 18 — Your personal security plan

The course finale: the threat profile analysis, the three-step plan and the master checklist in seven categories.