Back to all posts
August 6, 2026·8 min read·Digital Wellness

Digital Hygiene: A Weekly Routine That Takes Twenty Minutes

Digital hygiene is usually presented as a list of two hundred things nobody does. Here is the short version: a twenty-minute weekly pass, a monthly one, and the things you can safely ignore.

By Guardino Team · Guardino Technologies

Most digital hygiene advice fails for the same reason most fitness advice fails: it is a list of forty things, all of them reasonable, none of them scheduled, and so none of them done.

This is the short version. Twenty minutes a week, thirty minutes a month, an hour twice a year. Everything else is optional.

The weekly pass: twenty minutes

Pick a fixed time. Sunday evening works for most people because there is a natural boundary and nothing else is competing for the slot.

1. Close the tabs (2 minutes).

Not for tidiness. Open tabs are a to-do list you never wrote and cannot finish, and they carry a small constant weight. Anything genuinely worth returning to goes into whatever list you actually use. Everything else closes.

If you find the same tab surviving four weeks in a row, that is information: either do the thing or admit you are not going to.

2. Empty the downloads folder (2 minutes).

This is the folder where installers, attachments and half-read PDFs accumulate. It is worth clearing partly because it is where anything downloaded from a bad link would sit, and partly because it is the single fastest visible win, which matters for making the routine stick.

3. Check what is on the phone home screen (3 minutes).

Not a full audit. Just look at the first screen and ask which of these you opened deliberately this week and which one opened you. Anything in the second category moves off the first screen. This is a small move with a disproportionate effect, because most compulsive opening is triggered by position rather than intention.

4. Review the week's screen time, briefly (3 minutes).

Both iOS and Android report this without any extra software. Look at the total and the top three, then stop. The goal is not to feel bad; it is to notice a change. A number that has drifted up thirty percent over a month is the useful signal, and you will only see it if you look at it weekly.

5. Deal with the notification that annoyed you (5 minutes).

There will have been one. An app that started sending marketing notifications, a group that never stops. Turn it off now rather than continuing to dismiss it forever. Over a few months this single habit removes most of the interruption load without a big decluttering project.

6. One password (5 minutes).

Not all of them. One. Pick an account you care about, check whether the password is unique, and if it is not, change it. Twelve weeks of this covers your important accounts without ever requiring an afternoon.

The monthly pass: thirty minutes

1. Check which apps have access to your main accounts.

Google, Apple, Microsoft and the major social platforms all have a page listing every third-party app you have ever granted access to. Most people have between fifteen and forty, of which they recognise about six. Remove the ones you do not use. This is the highest-value item on the whole list after multi-factor authentication, because an old integration you forgot about is a live door.

2. Update everything.

Phone, laptop, browser, and the router if it has a firmware page. Most exploited vulnerabilities are old ones on unpatched devices rather than clever new ones.

3. Look at the subscriptions.

Not strictly hygiene, but it lives in the same drawer and nobody else does it. Cancel one thing.

4. Check your email is protected.

If multi-factor authentication is not on your primary email account, stop reading and go and turn it on. Email is the reset mechanism for every other account you own. An attacker with your email does not need any of your other passwords.

5. Delete an account you no longer use.

One per month. The service you signed up for in 2019 and never opened again is still holding your data and is still capable of being breached. This is slow, unglamorous work and it is the only thing that actually reduces your exposure surface over time.

Twice a year: one hour

Search for your own email address in a breach checker. There are reputable services that tell you which breaches an address has appeared in. Change the passwords for anything listed that you still use.

Review the recovery options on your important accounts. Old phone numbers and dead backup addresses are a common way people lock themselves out permanently, and a less common but real way attackers get in.

Look at what your devices are actually doing. If you run any kind of filtering or network visibility, this is the moment to look at the aggregate picture rather than the daily one. Twice a year is often enough to notice a device that has started phoning somewhere unexpected.

Ask whether the background layers are still on. Filtering, backups, and updates all fail silently. A backup that stopped running in March is worse than no backup, because you thought you had one.

What to leave off the list

Some standard advice is not worth your twenty minutes.

Clearing cookies and history on a schedule. This logs you out of things and makes your week slightly worse. It does very little for privacy, because the tracking that matters does not primarily depend on cookies you can clear.

Rotating good passwords. Current guidance from most security bodies is against routine expiry, because it pushes people toward predictable variations. Change a password when there is a reason: a breach, a shared credential, or a password you reused.

Stacking browser extensions. Each one can read what you do on the pages it runs on. Two or three from sources you trust is reasonable. Eleven is a larger risk than the thing they were installed to prevent.

Trying to become invisible. It is not achievable for a person living a normal life, and pursuing it consumes the attention that the achievable items need. Aim for less exposed, not for absent.

The layers that work while you are not doing anything

The honest weakness of any routine is that it depends on you doing it, and you will not, some weeks.

That is the argument for having one or two things that run without you:

  • A filtering resolver that blocks known phishing and malware domains for every device on your network. This works on the weeks you skip the routine, and it does not require you to correctly identify a suspicious link at 11pm.
  • Automatic updates, everywhere they can be turned on.
  • Automatic backups, checked twice a year to make sure they are still running.
  • A password manager, which turns the weekly password item from a chore into a two-minute check.

The routine catches what these miss. These catch what the routine misses. Between them you get most of the available benefit without ever having done an afternoon of digital spring cleaning, which is fortunate, because nobody does that either.

Related reading

Frequently asked questions

Is a weekly routine actually necessary, or is this just tidiness?+

Most of the value is in the monthly and quarterly items rather than the weekly ones, and the weekly pass matters mainly because it is short enough to actually happen. The things that genuinely reduce risk, unique passwords on the accounts that matter, multi-factor authentication on email, and removing access from apps you no longer use, are not weekly tasks. The weekly pass exists to keep the backlog small enough that the monthly one takes ten minutes instead of an afternoon you never schedule.

Which single change gives the most benefit for the least effort?+

Multi-factor authentication on your email account, if you have not already. Email is the reset mechanism for everything else, so an attacker with your email has every other account regardless of how good those passwords are. It takes about four minutes to set up and it is the one item on any digital hygiene list that is genuinely disproportionate in value.

How does filtering fit into this, if at all?+

It is a background layer rather than a routine task, which is precisely why it is worth having: it works on the weeks you do nothing. A resolver that blocks known phishing and malware domains removes a class of problem without asking you to be alert, and a filter on the sites that pull at your attention removes a class of decision. Neither replaces the routine, and both reduce how much the routine has to catch.

What is on most digital hygiene lists that I can safely ignore?+

Clearing cookies and browser history on a schedule, which mostly inconveniences you rather than anyone else. Changing good passwords on a rotation, which current guidance advises against because it pushes people toward weaker, more predictable passwords. Elaborate browser-extension stacks, which add attack surface and rarely earn it. And anything framed as making you invisible online, which is not achievable and distracts from the changes that do work.

Ready

Reclaim your attention.

Set up Guardino in two minutes. Your first 300K queries are on us.

Start your protection

Continue reading