Why Run a Personal Security Audit?
Most people only think about account security after something goes wrong — a suspicious email, a password reset they didn't request, or worse. But a proactive audit takes just 30 to 60 minutes and can close gaps before they become problems.
This checklist walks you through the key areas: passwords, two-factor authentication (2FA — a second verification step beyond your password), recovery options, connected apps, and login activity. You don't need to be technical to follow it. Work through each group at your own pace, focusing first on accounts that hold sensitive information — email, banking, health portals, and social media.
For a broader foundation on staying safe online, see our plain-language guide to digital safety — it pairs well with this checklist.
Password Hygiene
Two-Factor Authentication (2FA)
Recovery Options
Connected Apps & Permissions
Login & Activity Review
Tools That Make the Audit Easier
You don't need specialized software to complete this audit, but a few tools make certain steps much faster and more reliable. Below are the types of resources worth having open as you work through the checklist.
Password Manager
Generates, stores, and autofills strong unique passwords so you don't have to memorize them or reuse old ones.
Authenticator App
Provides time-based one-time codes for two-factor authentication, which are more secure than SMS codes.
Breach-Notification Service (e.g., Have I Been Pwned)
Checks whether your email address or passwords have appeared in known data breaches.
Secure Note or Encrypted Document
Stores backup codes, recovery answers, and audit notes in a safe, private location.
Once you've worked through the checklist, consider building on what you've done. Safer everyday digital habits covers how to maintain the security posture you've just established — turning a one-time audit into ongoing protection.
What to Do If You Spot a Problem
Running the audit may surface something concerning — an unfamiliar login location, an app you don't recognize, or a password flagged as compromised. Don't panic. Here's a straightforward response sequence:
- Change the affected password immediately — use a strong, unique password generated by your password manager.
- Sign out all other active sessions — most account settings offer a "sign out everywhere" option.
- Enable 2FA if it isn't already on — this prevents re-entry even if someone still has your old password.
- Check connected accounts — if your email was compromised, any account that uses it for recovery may also be at risk.
- Review recent account activity — look for password changes, new forwarding rules in email, or purchases you didn't make.
Don't Use the Same Email for Recovery Everywhere
If your primary email account is compromised, any other account that uses it as a recovery address is also at risk. Consider setting up a dedicated, low-profile email address used only for account recovery — and keep it secured with a strong password and 2FA.
After addressing any issues, it's worth reading more about online privacy habits worth building — many of the practices there complement what you've completed in this audit.




