Security advice arrives faster than anyone can apply it. New tools, new settings, new warnings, new “essential” checklists. Most of it is written as if attention were free and every risk carried equal weight. Living that way is impossible. The only sustainable approach is a filter: a simple way to decide which advice deserves time and which advice can wait.
I call it the Worth-It Test. It is the standard I use before I change a setting, adopt a tool, or recommend anything on this site.
Why Most Advice Fails the Test

A large share of security writing optimizes for completeness or for worst-case scenarios. Both produce long lists. Neither produces durable habits for people who already have jobs, families, and limited patience for configuration.
The result is familiar: readers bookmark the article, feel briefly resolved, and then change nothing. Or they implement everything once and quietly abandon the system when it becomes too heavy. In both cases the advice failed a basic requirement—it did not fit the life it was supposed to protect.
The real constraint is not knowledge
Most adults already know the headline recommendations: unique passwords, some form of second factor, care with unexpected links. The constraint is attention and follow-through. Advice that ignores that constraint is not practical, no matter how technically correct it is.
The Worth-It Test in Practice
Before I spend time on a new security step, I ask three questions:
Does this address a failure that actually happens to people like me?
Not a theoretical attack, not a headline risk that primarily affects large organizations—something that shows up in ordinary account takeovers, lost devices, or everyday privacy leaks.Is the ongoing cost (time, attention, friction) proportional to the reduction in risk?
A control that requires constant maintenance or adds daily irritation usually fails this test unless the risk it prevents is both high and frequent.Can I explain the payoff in one plain sentence?
If I cannot, I do not understand it well enough to adopt it, and I will not ask anyone else to adopt it either.
Any recommendation that fails one of the three questions is postponed or discarded. The test is deliberately strict. Attention is limited; only the controls that survive the filter earn a permanent place.
What survives the test for most adults
Working recovery methods on the accounts that matter
Unique passwords or passkeys for those same accounts
A short, ordered response to login alerts and breach notices
Basic device locks and the ability to locate or erase a lost phone
Deliberate handling of location data and app permissions on the devices used daily
Everything else is situational. Some people need more because of travel, work, or specific threats. Most people do not.
Minimum Effort: Applying the Test to the Next Piece of Advice
When you encounter a new recommendation, run it through the same three questions before you act. The minimum-effort version looks like this:
Write the advice down in one sentence.
Ask whether the problem it solves has ever affected you or someone whose situation resembles yours.
Estimate the recurring time or friction it would add.
Keep it only if the payoff is clear and the cost feels sustainable.
Most advice will not pass. That is the point. The goal is a short list of controls you actually maintain, not a long list you abandon.
What this replaces
It replaces the background guilt that comes from unread security articles and unfinished checklists. Once the filter is in place, the unread advice is no longer a moral failing. It is simply material that did not earn a place.
If You Want to Go Further
For people who want a more structured version of the same idea, three additional practices help:
Keep a single running note titled “Security steps that earned their place.” Add an item only after it has survived a month of real use.
When a breach or news story prompts a wave of new recommendations, wait forty-eight hours before changing anything. The delay filters the reactive suggestions from the durable ones.
Periodically review the note and remove anything you have stopped using. A control you no longer maintain is not a control; it is clutter.
These habits keep the system honest. They also make it obvious when a new tool or setting is genuinely worth adding.
A note on paid products
The Worth-It Test applies equally to free settings and paid services. A password manager, a VPN, or an identity-monitoring subscription must still clear the same three questions. If the free alternative already covers the realistic risk, the paid option rarely earns its place. When it does, the reason should be explainable in one sentence.
What This Site Is Built On
Every article published here is run through the same filter. I only write about practices I have used or tested. I only recommend tools that survived real use. I always separate a minimum-effort path from an optional advanced path so readers can stop at the point that matches their own risk and available attention.
The signature line is not a slogan. It is the operational conclusion of the Worth-It Test:
You don’t have to do everything. Just do the next thing.

The Next Thing
Open the most recent piece of security advice you bookmarked or left unfinished. Run it through the three questions. Keep it only if it survives. Then choose one action from the advice that did survive and do that action today.
That is how the list stays short enough to live with.
You don’t have to do everything. Just do the next thing.
No notes yet — be the first to inscribe one.