Why a Security Audit Belongs on Your Annual To-Do List

Most of us accumulate online accounts the way we accumulate receipts — frequently, without much thought, and with no real system for reviewing them later. A security audit is simply a structured pass through everything you've signed up for, so you can spot weak spots before someone else does.

You don't need to be technically sophisticated to do this well. What you need is a block of uninterrupted time, a methodical approach, and the tools below. If you share a computer or tablet with others, see our companion piece on keeping accounts secure on shared devices — those risks compound the ones covered here.

This checklist moves through four distinct phases: building your account inventory, reviewing passwords, auditing connected apps, and verifying privacy settings. Work through them in order for best results.

Required

Password manager

Generates, stores, and autofills strong unique passwords; also flags reused or compromised credentials during the audit.

Required

Email inbox search

Search terms like 'welcome to' or 'verify your email' help surface accounts you may have forgotten you created.

Required

Have I Been Pwned (haveibeenpwned.com)

Free public tool that checks whether your email addresses appear in known data breach databases.

Optional

Authenticator app

Generates time-based one-time codes for two-factor authentication, more secure than SMS-based codes.

Optional

Spreadsheet or notes app

Tracks your account inventory, deletion status, and follow-up items during the audit.

What You'll Need Before You Start

Gather these resources before diving into the checklist. Having them ready prevents you from losing momentum mid-audit.

If you're not already using a password manager, this audit is a natural moment to consider one. Our editorial team has a full explainer on how password managers work and why security professionals trust them that addresses the most common concerns about putting all your credentials in one place.

Don't Change Passwords Without a Manager Ready

If you update dozens of passwords during this audit but don't store them reliably, you risk locking yourself out of accounts. Set up or open your password manager before making any password changes. Avoid using browser-saved passwords as your sole storage — if you lose access to that browser profile, those credentials may be unrecoverable.

The Full Security Audit Checklist

Work through each group below. Mark items as you complete them — the order matters because later steps build on earlier ones.

Account Inventory

Search your primary email inbox for phrases like 'welcome,' 'confirm your account,' and 'verify your email' to compile a list of every service you've ever registered with. Must
Repeat the inbox search for any secondary email addresses you've used to sign up for things. Must
Check your password manager's saved logins vault (or your browser's saved passwords) as a secondary source of accounts. Must
Flag accounts you no longer use and request deletion or deactivation directly through each service's settings — not just unsubscribing from email. Should

Password Review

Run a password audit report inside your password manager to identify reused, weak, or previously breached passwords. Must
Change any reused password immediately, prioritizing email, banking, and healthcare accounts first. Must
Check your email addresses against Have I Been Pwned to see if they appear in known breach datasets. Must
Replace every flagged password with a unique, randomly generated password of at least 16 characters. Must
Update security questions on accounts that still use them — treat the answers as passwords and store them in your manager rather than using real personal information. Should

Two-Factor Authentication

Enable two-factor authentication (2FA) on your primary email account — this is your highest-priority action if it isn't already active. Must
Enable 2FA on financial, banking, and payment accounts. Must
Enable 2FA on social media, cloud storage, and any account that contains sensitive personal data. Should
Switch from SMS-based 2FA to an authenticator app where the service supports it, as SMS codes can be intercepted. Should
Save backup or recovery codes for 2FA-enabled accounts in a secure offline location. Must

Connected Apps and Permissions

Navigate to the security or connected apps section of your major accounts (Google, Apple ID, Facebook, Microsoft) and review every third-party app that has been granted access. Must
Revoke access for any app you no longer use or don't recognize. Must
Review what permissions each remaining connected app holds — read-only access is significantly safer than full account access. Should

Privacy Settings Review

Review the privacy and data-sharing settings on your most-used platforms, as services often reset or expand defaults after major updates. Should
Audit active login sessions in your account security settings and terminate any sessions you don't recognize or that show unfamiliar device names or locations. Must
Check whether any accounts allow data to be shared with advertisers or data brokers and opt out where the service provides that option. Nice to have
Confirm your account recovery options — backup email addresses and phone numbers — are current and still accessible to you. Must

Once you've enabled two-factor authentication on your most critical accounts, read our detailed walkthrough: A First-Timer's Roadmap to Two-Factor Authentication. It covers authenticator apps, backup codes, and what to do if you lose access to your second factor.

Your Email Account Is the Master Key

Virtually every other account you own can be reset through your primary email address. If an attacker gains access to your inbox, they can reset passwords across every linked service. Treat email security — a strong unique password and 2FA — as the single most important action in this entire checklist. Do not skip or defer it.

Your account audit pairs well with a broader look at your devices. The home network security checklist covers router settings and device permissions that affect every account you access from home. And if you're prepping an old phone or laptop for donation, don't skip the device retirement checklist — saved passwords and session tokens can persist if accounts aren't removed properly.

After the Audit: Keeping Things Tidy

A one-time audit closes existing gaps, but account security drifts over time. Services update their privacy settings, you sign up for new things, and old connected apps accumulate. Setting a calendar reminder to repeat this process annually — or after any major data breach notification — is the simplest way to stay ahead.

If you want to go deeper on device-level privacy, our guide to privacy settings worth adjusting on phones and connected devices walks through the controls that actually matter. And if you've noticed unusual battery drain or high background data usage since the audit, that's worth investigating separately — signs an app is running quietly in the background explains what to look for.

Security isn't a destination — it's a habit. This checklist gives you a solid baseline to return to whenever you need it.