Why Run a Personal Security Audit?

Most people only think about account security after something goes wrong — a suspicious email, a password reset they didn't request, or worse. But a proactive audit takes just 30 to 60 minutes and can close gaps before they become problems.

This checklist walks you through the key areas: passwords, two-factor authentication (2FA — a second verification step beyond your password), recovery options, connected apps, and login activity. You don't need to be technical to follow it. Work through each group at your own pace, focusing first on accounts that hold sensitive information — email, banking, health portals, and social media.

For a broader foundation on staying safe online, see our plain-language guide to digital safety — it pairs well with this checklist.

Password Hygiene

Identify any accounts where you reuse the same password and replace each with a unique one. Must
Replace any password shorter than 12 characters or made of simple words with a longer, randomized alternative. Must
Check your email address and known passwords against a breach-notification service (such as Have I Been Pwned) to see if they've appeared in known data leaks. Must
Set up a password manager to generate and store strong, unique passwords going forward. Should
Delete saved passwords stored directly in your browser if you're now using a dedicated password manager. Nice to have

Two-Factor Authentication (2FA)

Enable 2FA on your primary email account — this is the highest-priority account to secure, as it controls password resets for everything else. Must
Enable 2FA on banking, financial, and health-portal accounts. Must
Enable 2FA on social media and any account linked to a payment method. Should
Switch SMS-based 2FA to an authenticator app where the option exists — authenticator apps are less vulnerable to SIM-swapping attacks. Should
Save or print your 2FA backup codes and store them somewhere physically secure. Must

Recovery Options

Confirm your recovery email address is current and an account you still actively control. Must
Confirm your recovery phone number is a number you currently own. Must
Review any security questions set on older accounts and update answers that could be guessed from public information (e.g., social media profiles). Should
Add a trusted contact or backup method to accounts that support it. Nice to have

Connected Apps & Permissions

Open the security settings of each major account and review every third-party app or service that has been granted access. Must
Revoke access for any app you no longer use, recognize, or trust. Must
Check whether any connected app has broad permissions (e.g., read and send email) that seem excessive for its stated purpose. Should

Login & Activity Review

Open recent login or device activity in each key account and look for unfamiliar locations, devices, or times. Must
Sign out any sessions for devices you no longer own or recognize. Must
Check your email's sent folder, forwarding rules, and filters for anything you didn't set up yourself. Should
Enable login notifications (email or push alerts for new sign-ins) on accounts that offer this feature. Nice to have

Tools That Make the Audit Easier

You don't need specialized software to complete this audit, but a few tools make certain steps much faster and more reliable. Below are the types of resources worth having open as you work through the checklist.

Required

Password Manager

Generates, stores, and autofills strong unique passwords so you don't have to memorize them or reuse old ones.

Required

Authenticator App

Provides time-based one-time codes for two-factor authentication, which are more secure than SMS codes.

Required

Breach-Notification Service (e.g., Have I Been Pwned)

Checks whether your email address or passwords have appeared in known data breaches.

Optional

Secure Note or Encrypted Document

Stores backup codes, recovery answers, and audit notes in a safe, private location.

Once you've worked through the checklist, consider building on what you've done. Safer everyday digital habits covers how to maintain the security posture you've just established — turning a one-time audit into ongoing protection.

What to Do If You Spot a Problem

Running the audit may surface something concerning — an unfamiliar login location, an app you don't recognize, or a password flagged as compromised. Don't panic. Here's a straightforward response sequence:

  1. Change the affected password immediately — use a strong, unique password generated by your password manager.
  2. Sign out all other active sessions — most account settings offer a "sign out everywhere" option.
  3. Enable 2FA if it isn't already on — this prevents re-entry even if someone still has your old password.
  4. Check connected accounts — if your email was compromised, any account that uses it for recovery may also be at risk.
  5. Review recent account activity — look for password changes, new forwarding rules in email, or purchases you didn't make.

Don't Use the Same Email for Recovery Everywhere

If your primary email account is compromised, any other account that uses it as a recovery address is also at risk. Consider setting up a dedicated, low-profile email address used only for account recovery — and keep it secured with a strong password and 2FA.

After addressing any issues, it's worth reading more about online privacy habits worth building — many of the practices there complement what you've completed in this audit.