Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Guides
Guides

The monthly personal security checklist: 20 minutes, first Saturday

A repeatable 20-minute routine — updates, backups, breach check, statement scan, and a permissions glance — keeps your security posture from quietly rotting between emergencies.

Colin Reyes, · July 30, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Person working through a printed checklist with coffee at a desk

Yes — twenty minutes a month, on a recurring calendar block, covers nearly all personal security maintenance: install pending updates and restart everything, confirm your backups actually ran and restore-test one file, check your email against recent breach data, scan card and bank statements for anomalies, and glance at one rotating item from the deeper list below. Security decays — settings drift, devices accumulate, credentials age — and a fixed routine beats both panic-response after incidents and the illusion that one busy weekend a year is enough.

The core routine (every month, ~20 minutes)

  1. Updates and restarts (5 min). Computers and phones: check for pending updates and restart anything nagging. Browser fully closed and reopened. Router: firmware check or verify auto-update is still on. The restart is the step that matters — pending-update machines are the most common "but I thought it updated itself" failure.
  2. Backup verification (3 min). Confirm the last backup dates on both your external drive and cloud copy. Once a quarter, restore one file and open it — a backup you have never restored from is a hope. Check that the backup drive is actually connected and not quietly full.
  3. Breach exposure (2 min). Search your primary and alias addresses on Have I Been Pwned. A new hit means: change that password, and any reuse of it, per our breach-notification guide.
  4. Money scan (5 min). Card statements and bank activity for unfamiliar charges — small recurring ones especially, the subscription-trap signature. Enable alerts if you haven't; reviewing with alerts on shrinks this step permanently.
  5. One glance item (5 min): rotate through the deeper checks below — one per month.

The rotating deeper checks (one per month)

What triggers an off-schedule pass?

Four events mean run the relevant section immediately, not at month's end: a security alert for an unfamiliar sign-in; a breach notification naming a service you use; a lost device (sessions revocation + password rotation for what it could reach); and any phishing message you interacted with — clicked, entered, approved — which triggers the phishing-response steps rather than the routine list.

How do you make it stick?

Treat it like any recurring obligation: a named calendar event with a 20-minute block, ideally anchored to a habit you already keep — first Saturday with coffee. Keep the checklist itself in your notes app so the agenda costs zero memory. And be honest about the psychology: the routine's value is that it makes decay visible. Each month you'll find small things — a stalled backup, an expired card still set as default, a device you forgot you owned — and each small thing fixed is a failure mode quietly removed. The alternative is that all of it accumulates until the day something goes wrong, when you discover every answer at the worst possible moment.

What about households?

Run it with your partner, and scale the briefing to the household's risk takers: kids get the phishing and permissions talk in their language; parents get the scam-call and deepfake-voice reminders; everyone gets the family codeword refreshed twice a year. Ten extra minutes of conversation prevents most of the incidents that the technical checklist can't — because the majority of household breaches still begin with a person, not a device.

Frequently Asked Questions

How often should I do a security checkup?
Twenty minutes monthly covers updates, backup verification, breach exposure, statement scans, and one rotating deeper check — plus immediate passes after lost devices, unfamiliar sign-in alerts, or breach notifications.
What is the single most important monthly check?
Account recovery audit: confirm your primary email's recovery email, phone, and backup codes are current and genuinely yours. Whoever controls recovery controls the account — everything else is downstream of that.
How do I check if my email was in a data breach?
Search your addresses on Have I Been Pwned — a monthly habit that takes a minute. A new hit means changing that password and every reuse of it immediately.
Do I really need to test restoring a backup?
Quarterly, yes — restore one file and open it. Backup failures are silent: the drive fills, the job skips files, the encryption key went missing. An untested backup is a hope, not a backup.