Why You Need a Structured Approach to Personal Security
I spent three years working in incident response before I ever bothered to document any of my own security practices. That was a mistake. When a real breach happened to me personally, I realized I had no baseline — no record of what accounts I owned, what authentication methods were in place, or what my recovery steps should be. The panic cost me about fourteen hours of lost work and a lot of unnecessary stress. After that, I built a Protect Yourself Rules Worksheet and kept it updated. It changed how I handle everything from password resets to identity theft concerns. It is a single-page or multi-section document that maps out your personal digital and physical security posture. It typically includes fields for account inventory, authentication methods, recovery contact information, emergency procedures, and periodic review checkpoints. The idea is straightforward: instead of relying on memory or scattered notes, you consolidate your security-related data into one place that is both actionable and easy to maintain. I have seen versions that use spreadsheets. I have seen versions that are simple tables in a word processor. The format does not matter nearly as much as the consistency. People who abandon this approach usually do so because they treated it like a one-time exercise rather than a living document.
How to Build and Use It
Start with account inventory. List every service where you have an account that involves personal data, financial access, or sensitive communications. I mean every one. Email, banking, healthcare portals, government services, cloud storage, social media, subscription platforms. When I was building my first version, I missed about a dozen accounts simply because I assumed some low-usage services did not need tracking. Two of those turned out to be dormant accounts that had been compromised in breaches I had never seen alerts about. Next, document your authentication setup. For each account, note whether you are using passwords alone, two-factor authentication, biometric login, or hardware keys. Record the phone numbers and backup email addresses tied to each account. This section alone takes most people about twenty minutes to complete, but it is the single highest-value part of the entire worksheet. When I had to recover a locked-out account during a weekend incident, having this documented cut the resolution time from roughly four hours down to forty-five minutes. Add emergency recovery contacts. These are people who should know about your security situation if you become incapacitated or your primary devices are lost. Include at least two contacts, their relationship to you, and how to reach them through multiple channels. Do not skip this. Most people do.
Finally, build in review intervals. Set a quarterly check-in to verify that everything on the sheet is still accurate. Password managers change, phone numbers get recycled, and accounts get abandoned without your knowledge. A fifteen-minute review every ninety days keeps the document from becoming stale, which is when it becomes useless.
Get the Full Details

Where the Protect Yourself Rules Worksheet Falls Short
There are honest limitations to this approach, and ignoring them will make you feel safer than you actually are. The biggest issue is that a worksheet is static. It records what you know at a point in time. It does not protect you while threats are actively occurring. If someone gains access to your devices or your physical document, the worksheet itself can become intelligence for an attacker. I learned this the hard way after an employee at my previous job lost a notebook containing a detailed security inventory. The contents were not catastrophic, but the exposure forced a full credential rotation across every platform we used professionally. Another limitation is scope. A worksheet cannot replace actual security controls. You still need a password manager, you still need to enable multi-factor authentication on every eligible account, and you still need to keep your software updated. The worksheet is an organizational tool, not a protective tool. Treating it as a substitute for those fundamentals is a common error I see repeatedly. If you want something more dynamic, consider pairing the worksheet with an automated account monitoring service. Tools like Have I Been Pwned, your bank's fraud alerts, and built-in breach notifications from your email provider will catch events that your static document cannot. The worksheet tells you what to do when something happens. The monitoring tools tell you when something has happened.
Practical Tips That Actually Matter
Keep a physical copy in a safe location and a digital copy in an encrypted container. I use a hardware-encrypted USB drive stored in a fireproof safe at home, plus a copy in my password manager's secure notes field. This gives me access whether I am at home or traveling, while reducing the risk of either copy being exposed independently. Use specific naming conventions when listing accounts. Instead of writing "my bank account," write "Chase Checking - ending 4471." Specificity matters when you are under time pressure and trying to locate the right page in a help center queue. Include the direct support URL for each service. Call centers are slow. Being able to navigate directly to a security settings page or a breach response form saves significant time during an incident. I have seen this reduce average account recovery time from over an hour to under fifteen minutes for the same situations.
Do not overcomplicate the first draft. People tend to spend weeks refining the template instead of filling it in. The first version should take you about an hour, max. You will refine it over time as you discover what information proves useful and what does not. Perfection on day one is not the goal. Completion is.
