Why a Security Audit Belongs on Your Annual To-Do List

Most people set up an account, choose a password, and never look back — until something goes wrong. The reality is that the average person has dozens of active online accounts, and each one is a potential entry point for unauthorized access. A security audit is simply a structured review of every login you own, checking whether each account is as protected today as it should be.

Think of it the same way you might approach a yearly vehicle review — a proactive check that catches small problems before they become serious ones. Your digital accounts deserve the same attention.

This checklist walks you through the key questions to ask about every login you own, grouped into logical categories so you can work through them systematically. You don't need technical expertise — just a reliable internet connection and about 30 to 60 minutes of focused time.

Required

Password Manager

Stores, generates, and auto-fills unique, strong passwords for every account — eliminating the need to remember or reuse credentials.

Required

Authenticator App

Generates time-limited one-time codes for two-factor authentication, providing stronger account protection than SMS-based codes.

Optional

Breach Notification Service

Checks whether your email address or passwords have appeared in publicly known data breaches.

Optional

Secure Note Storage

Stores 2FA backup codes and account recovery information safely — can be a password manager's secure notes feature or an encrypted document.

How to Work Through This Checklist

Start by building a list of every account you can recall — email, banking, social media, streaming, shopping, health portals, and utility sites. Check your email inbox for account confirmation messages if you're unsure where you've registered. Work through each account against the checklist questions below.

For password-related items, a password manager can dramatically simplify the process by storing, generating, and auto-filling unique credentials for every site. For two-factor authentication (2FA) questions — which means requiring a second verification step beyond your password — our guide on what 2FA actually does explains how this protection works and why it matters.

Prioritize Your Email Account Above All Others

Your primary email address is effectively the master key to your digital life — most services allow password resets via email, meaning anyone who gains access to your inbox can take over your other accounts. Before any other step, ensure your main email account has a strong unique password and two-factor authentication enabled. Treat it as your most sensitive login.

Pay particular attention to your highest-risk accounts: primary email (often used to reset every other password), financial accounts, and any account tied to your government ID or healthcare records. These warrant the most scrutiny.

Password Strength & Uniqueness

Confirm that this account uses a password unique to it and not shared with any other site or service. Must
Verify the password is at least 12 characters long and includes a mix of letters, numbers, and symbols. Must
Check whether this password has appeared in a known data breach using a reputable breach-checking tool. Must
Replace any password that is short, simple, reused, or flagged in a breach with a strong, unique alternative. Must

Two-Factor Authentication (2FA)

Confirm whether this account offers two-factor authentication and enable it if it hasn't been set up yet. Must
Review which 2FA method is in use — prefer an authenticator app over SMS text codes where possible. Should
Locate and securely store any backup codes provided by the service in case you lose access to your 2FA device. Should

Account Recovery Options

Verify that recovery email addresses and phone numbers on file are current, accurate, and accessible to you. Must
Remove recovery options tied to old email addresses, phone numbers, or contacts you no longer control. Must
Check whether security questions are used and, if so, ensure answers are not easily guessable from public information. Should

Active Sessions & Device Access

Review the list of active sessions or devices logged into this account and sign out any you don't recognize. Must
Confirm that no unfamiliar locations or devices appear in recent login history. Must
Sign out of sessions on devices you no longer own or use, such as old phones or shared computers. Should

Connected Apps & Third-Party Access

Find the account's list of connected third-party apps or services and revoke access for any you no longer use. Should
Review what permissions each connected app holds — look for apps with access to contacts, email, or payment data that seems unnecessary. Should
Remove any app integrations granted to services that no longer exist or that you don't recognize. Must

Dormant & Unnecessary Accounts

Identify accounts you have not used in over 12 months and decide whether to close or secure them. Should
Close accounts at services that no longer exist or that you have no intention of using again. Should
Before closing any account, review it for stored payment methods, personal data, or linked subscriptions that need to be removed first. Must

Notification & Alert Settings

Enable login alerts or security notifications for high-value accounts so you are informed of any new sign-in attempts. Should
Confirm that notification emails go to an inbox you actively monitor, not a secondary account you rarely check. Should
Set up breach or compromise alerts through the account's security settings or a reputable external monitoring service where available. Nice to have

After the Audit: Keeping Your Accounts Secure Long-Term

A one-time audit is valuable, but account security is an ongoing habit. Set a calendar reminder to repeat this process at least once a year — or immediately after any data breach notification you receive. Services like haveibeenpwned.com (a widely referenced, independent breach notification resource) can alert you when your email address appears in known data leaks.

If you discover during this audit that you've reused passwords across multiple sites, prioritize changing those first. The risks of password reuse are often underestimated — see our detailed explanation of why reusing passwords is riskier than most people realize for a clear picture of how a single leaked credential can cascade into multiple compromised accounts.

For your 2FA method, note that not all second-factor options are equally secure. SMS text codes are more vulnerable to interception than authenticator apps. Our comparison of authenticator apps vs. SMS codes explains the difference and helps you decide which to use.

Don't Ignore Breach Notification Emails

If a service notifies you that your account was involved in a data breach, take it seriously and act immediately — change your password for that account and any other account using the same credentials. Delaying action after a breach notification is one of the most common ways compromised credentials lead to further harm. When in doubt about whether a breach notification email is genuine, navigate to the service's website directly rather than clicking any links in the message.

The goal isn't perfect security overnight — it's steady, meaningful improvement. Closing even a handful of forgotten accounts, enabling 2FA on your email, and replacing a few reused passwords makes a measurable difference in your overall risk exposure.