Yes — twenty minutes a month, on a recurring calendar block, covers nearly all personal security maintenance: install pending updates and restart everything, confirm your backups actually ran and restore-test one file, check your email against recent breach data, scan card and bank statements for anomalies, and glance at one rotating item from the deeper list below. Security decays — settings drift, devices accumulate, credentials age — and a fixed routine beats both panic-response after incidents and the illusion that one busy weekend a year is enough.
The core routine (every month, ~20 minutes)
- Updates and restarts (5 min). Computers and phones: check for pending updates and restart anything nagging. Browser fully closed and reopened. Router: firmware check or verify auto-update is still on. The restart is the step that matters — pending-update machines are the most common "but I thought it updated itself" failure.
- Backup verification (3 min). Confirm the last backup dates on both your external drive and cloud copy. Once a quarter, restore one file and open it — a backup you have never restored from is a hope. Check that the backup drive is actually connected and not quietly full.
- Breach exposure (2 min). Search your primary and alias addresses on Have I Been Pwned. A new hit means: change that password, and any reuse of it, per our breach-notification guide.
- Money scan (5 min). Card statements and bank activity for unfamiliar charges — small recurring ones especially, the subscription-trap signature. Enable alerts if you haven't; reviewing with alerts on shrinks this step permanently.
- One glance item (5 min): rotate through the deeper checks below — one per month.
The rotating deeper checks (one per month)
- Month 1 — Account recovery audit: primary email's recovery email, phone, and backup codes are current and yours. This is the highest-value single check on the list.
- Month 2 — Active sessions sweep: Google, Apple, Microsoft sign-in pages: revoke sessions on devices you no longer own; review connected third-party apps.
- Month 3 — Password manager health: run its security/audit report; change the oldest reused or weak entries; confirm MFA is on for the top ten accounts.
- Month 4 — Phone deep pass: pending OS update installed, app updates applied, a quick permissions glance — anything new holding location or microphone that shouldn't.
- Month 5 — IoT and network: router firmware and settings intact (no mystery port-forwards), smart-device firmware updates in their apps, guest network still isolated.
- Month 6 — Annual-tier items: credit-report pull (free weekly at annualcreditreport.com; verify the freeze status you set), password-manager recovery kit still exists on paper, physical security review — where do documents with SSNs live?
What triggers an off-schedule pass?
Four events mean run the relevant section immediately, not at month's end: a security alert for an unfamiliar sign-in; a breach notification naming a service you use; a lost device (sessions revocation + password rotation for what it could reach); and any phishing message you interacted with — clicked, entered, approved — which triggers the phishing-response steps rather than the routine list.
How do you make it stick?
Treat it like any recurring obligation: a named calendar event with a 20-minute block, ideally anchored to a habit you already keep — first Saturday with coffee. Keep the checklist itself in your notes app so the agenda costs zero memory. And be honest about the psychology: the routine's value is that it makes decay visible. Each month you'll find small things — a stalled backup, an expired card still set as default, a device you forgot you owned — and each small thing fixed is a failure mode quietly removed. The alternative is that all of it accumulates until the day something goes wrong, when you discover every answer at the worst possible moment.
What about households?
Run it with your partner, and scale the briefing to the household's risk takers: kids get the phishing and permissions talk in their language; parents get the scam-call and deepfake-voice reminders; everyone gets the family codeword refreshed twice a year. Ten extra minutes of conversation prevents most of the incidents that the technical checklist can't — because the majority of household breaches still begin with a person, not a device.
For more context, read How to set up sign-in alerts on the accounts that matter.
For more context, read authenticator app setup.
For more context, read 3-2-1 backup rule.

