Why One Audit Per Year Is Worth Your Time

Most people only think about account security after something goes wrong — a suspicious login notification, a friend saying your social media account sent them a strange message, or a data breach appearing in the news. By then, the damage may already be done.

The good news is that a focused, once-a-year review covers the majority of real-world vulnerabilities for the average person. You don't need to be a cybersecurity expert. You need a reliable process and the willingness to spend an hour on it.

This checklist walks you through the four major areas where everyday accounts tend to develop weaknesses: passwords, account access controls, recovery information, and forgotten accounts. Work through each group at your own pace — all 22 items can realistically be completed in a single sitting.

If you're also auditing where your money goes each month, the monthly expense audit checklist is a natural companion to this exercise — you may spot old subscriptions tied to accounts you've already abandoned.

Passwords

Identify any accounts where you reuse the same password and update each to a unique, randomly generated one. Must
Change any password shorter than 12 characters on accounts that hold financial, medical, or personal data. Must
Replace any password that includes easily guessable personal information such as a name, birthday, or street address. Must
Store all updated passwords in a dedicated password manager rather than a browser's built-in save function or a notes app. Should
Review your password manager's security dashboard (if available) and resolve any flagged weak or compromised entries. Should

Two-Factor Authentication (2FA)

Enable two-factor authentication on your primary email account — this is your most critical account to protect. Must
Enable 2FA on all financial accounts, including banking, investment, and payment platforms. Must
Switch SMS-based 2FA codes to an authenticator app on any account that supports it, since text messages are more vulnerable to interception. Should
Save or print backup codes for 2FA-protected accounts and store them somewhere physically secure. Should
Enable 2FA on social media accounts, especially those linked to other services or used for login. Should

Recovery Information

Verify that the recovery email address on each important account is one you still actively access. Must
Confirm that the recovery phone number attached to each account is current and in your possession. Must
Review security questions on older accounts and update answers that are based on publicly available personal information. Should
Check that your primary email account does not forward copies to an old or unfamiliar address. Must

Old and Forgotten Accounts

Search your email inbox for account creation confirmations from services you no longer use and request deletion where possible. Should
Revoke third-party app permissions on your Google, Apple, and Facebook accounts by reviewing connected apps in account settings. Must
Delete or deactivate accounts on platforms you haven't logged into in over a year. Should
Check if your email address appears in known data breaches using a reputable breach-checking service. Should

Device and Session Security

Review active login sessions on your primary email and social accounts and sign out of any device or location you don't recognize. Must
Ensure your primary devices use a PIN, password, or biometric lock to prevent unauthorized physical access. Must
Confirm that your home Wi-Fi network uses WPA2 or WPA3 encryption and that your router's admin password is not the factory default. Should
Check that your operating system and key apps are set to receive automatic security updates. Nice to have

Tools You'll Need Before You Start

You don't need specialized software to complete this audit, but a few tools make it significantly faster and more thorough. Before you begin, gather the following:

Required

Password Manager

Generates, stores, and auto-fills unique passwords for every account so you're not relying on memory or reuse.

Required

Authenticator App

Provides time-based one-time codes for two-factor authentication, which are more secure than SMS codes.

Required

Breach-Checking Service

Checks whether your email address or credentials appear in publicly known data breaches.

Optional

Secure Note Storage or Printed Backup

Stores 2FA backup codes and recovery keys in a physically secure location separate from your devices.

If you use a smart home ecosystem, your router admin panel and connected device accounts deserve the same scrutiny as your email. The smart home security setup checklist covers that ground specifically.

Don't Store Passwords in a Notes App or Spreadsheet

Text files, notes apps, and unencrypted spreadsheets offer no protection if your device is compromised or stolen. A dedicated password manager encrypts your credentials and requires a master password to access them. Using one is one of the highest-impact changes most people can make to their overall security posture.

Free Breach-Checking Tools Vary in Scope

No single service indexes every known breach. A clean result does not guarantee your credentials are unexposed — it means they haven't appeared in the breaches that service has catalogued. Treat breach checks as a useful signal, not a definitive clearance.

Once you've confirmed your tools are in place, move through the checklist groups in order. Skipping ahead — especially past the password and two-factor sections — reduces the effectiveness of the later steps.

After the Audit: What to Do If You Find a Problem

If you discover during this audit that an account has already been accessed without your permission — unfamiliar login times, sent messages you didn't write, or settings you didn't change — act immediately rather than finishing the checklist first.

The account recovery steps after a hack walk you through the right sequence: securing your email first, then resetting passwords in priority order, then notifying relevant institutions.

For most people, though, this audit is about prevention. Common habits that feel protective — like using a unique capitalization pattern or adding a number to the end of a familiar password — offer far less real protection than they appear to. The security habits that don't actually protect you article explains why and what to do instead.

Set a calendar reminder for the same time next year. Security isn't a one-time fix — it's a maintenance habit, much like reviewing your household bills or checking your credit report.

This article is for general informational purposes only. It does not constitute professional cybersecurity or legal advice. For concerns about active breaches or sensitive accounts, consult a qualified security professional or contact the relevant platform's support team directly.