Ongoing
security routines
Everything this course has built — passwords, 2FA, updates, backups, networks — slowly rots without maintenance. But the maintenance is smaller than you think: a few habits, fifteen minutes a month, half an hour a quarter and one evening a year. Here is the full schedule as checklists, plus the routines for anyone running a company.
From project to routine
Sixteen episodes of measures is a project — and projects end. Security that lasts is instead a routine: small, recurring maintenance that keeps the protection from rotting as passwords leak, gadgets age and threats change shape. Good news: with the automation from earlier episodes (updates, backups, monitoring), the ongoing work is surprisingly small. Here is the full schedule.
The checklists: daily, monthly, quarterly, yearly
Daily — habits, not tasks
- Pause at strong emotions in messages — urgency, fear, winnings (episode 4).
- Verify via your own route instead of clicking in emails/texts.
- Let the password manager generate at every new signup (episode 2).
- Never approve a 2FA request you didn't initiate yourself (episode 3).
Monthly — 15 minutes
- Restart browsers and devices so pending updates take effect (episode 5).
- Skim bank and card statements for unknown transactions.
- Act on the password manager's warnings about leaked/weak passwords.
- Verify the backup actually ran (episode 9 — a green tick, not an assumption).
Quarterly — 30 minutes
- The router's device list: do you recognise everything? (episodes 10 and 13)
- App permissions on the phone: revoke the unreasonable (episode 8).
- Active sessions on email and social media: log out unknown devices.
- Clean up sharing links in the cloud — the "Shared by me" view (episode 14).
- Browser extensions: remove what you don't use (episode 7).
Yearly — one evening
- Test-restore the backup — three random files; that's the zero in 3-2-1-1-0 (episode 9).
- HIBP search on all your addresses + actions (episode 12).
- Retire accounts and subscriptions unused for a year.
- Inventory device update status: does everything still receive security fixes? (episodes 5, 8, 13)
- Check recovery details and backup codes: current numbers, codes still in place (episode 3).
- Review your security plan (episode 18) and update it.
For the company: onboarding, offboarding and vendors
At onboarding
- Individual accounts from day one — never shared logins. MFA before the first workday ends (episodes 3, 15).
- The least privilege sufficient for the role — expand when needed, not the other way round.
- Walk through the routine document (episode 15) as part of the introduction.
At offboarding — same day
- Close all accounts (the SSO button from episode 15 makes this one action instead of twenty).
- Rotate shared secrets the person had access to: WiFi, payment cards, any shared accounts.
- Collect equipment and revoke the device's access in MDM.
Vendor onboarding
Every new service and vendor is a new door in. Before signing: Where is the data stored, and is there a data processing agreement (episode 14)? Does the service support MFA/SSO? What does their security track record look like — and how do they notify about incidents? Five minutes of questions that save months of aftermath.
Five sources worth following
The course has an end date — the threat landscape doesn't. Five subscriptions that keep you current without drowning you:
- CERT-SE — Swedish alerts and weekly digests; what actually concerns you locally.
- Krebs on Security — investigative journalism on the crime ecosystem; this course's most-cited source.
- Schneier on Security — wisdom on security's principles rather than the daily noise.
- Have I Been Pwned — not reading but alarms: emails when your addresses appear in new breaches.
- SANS Internet Storm Center — short daily situation reports for those who want one notch deeper.
If you only have energy for three things
A minute of honesty: not everyone will follow the whole schedule, and three things done beat twenty things planned. The priority order, if everything else falls away:
- A password manager + a unique password and 2FA on your email. Episodes 2 and 3 — closes the most common way in.
- Automatic updates on everything. Episode 5 — closes the second most common, with no ongoing effort.
- A working backup with one copy out of reach. Episode 9 — makes the worst case survivable.
Episode 18 — Your personal security plan
The course finale: the threat profile analysis, the three-step plan and the master checklist in seven categories.