Why One Audit Per Year Is Worth Your Time
Most people only think about account security after something goes wrong — a suspicious login notification, a friend saying your social media account sent them a strange message, or a data breach appearing in the news. By then, the damage may already be done.
The good news is that a focused, once-a-year review covers the majority of real-world vulnerabilities for the average person. You don't need to be a cybersecurity expert. You need a reliable process and the willingness to spend an hour on it.
This checklist walks you through the four major areas where everyday accounts tend to develop weaknesses: passwords, account access controls, recovery information, and forgotten accounts. Work through each group at your own pace — all 22 items can realistically be completed in a single sitting.
If you're also auditing where your money goes each month, the monthly expense audit checklist is a natural companion to this exercise — you may spot old subscriptions tied to accounts you've already abandoned.
Passwords
Two-Factor Authentication (2FA)
Recovery Information
Old and Forgotten Accounts
Device and Session Security
Tools You'll Need Before You Start
You don't need specialized software to complete this audit, but a few tools make it significantly faster and more thorough. Before you begin, gather the following:
Password Manager
Generates, stores, and auto-fills unique passwords for every account so you're not relying on memory or reuse.
Authenticator App
Provides time-based one-time codes for two-factor authentication, which are more secure than SMS codes.
Breach-Checking Service
Checks whether your email address or credentials appear in publicly known data breaches.
Secure Note Storage or Printed Backup
Stores 2FA backup codes and recovery keys in a physically secure location separate from your devices.
If you use a smart home ecosystem, your router admin panel and connected device accounts deserve the same scrutiny as your email. The smart home security setup checklist covers that ground specifically.
Don't Store Passwords in a Notes App or Spreadsheet
Text files, notes apps, and unencrypted spreadsheets offer no protection if your device is compromised or stolen. A dedicated password manager encrypts your credentials and requires a master password to access them. Using one is one of the highest-impact changes most people can make to their overall security posture.
Free Breach-Checking Tools Vary in Scope
No single service indexes every known breach. A clean result does not guarantee your credentials are unexposed — it means they haven't appeared in the breaches that service has catalogued. Treat breach checks as a useful signal, not a definitive clearance.
Once you've confirmed your tools are in place, move through the checklist groups in order. Skipping ahead — especially past the password and two-factor sections — reduces the effectiveness of the later steps.
After the Audit: What to Do If You Find a Problem
If you discover during this audit that an account has already been accessed without your permission — unfamiliar login times, sent messages you didn't write, or settings you didn't change — act immediately rather than finishing the checklist first.
The account recovery steps after a hack walk you through the right sequence: securing your email first, then resetting passwords in priority order, then notifying relevant institutions.
For most people, though, this audit is about prevention. Common habits that feel protective — like using a unique capitalization pattern or adding a number to the end of a familiar password — offer far less real protection than they appear to. The security habits that don't actually protect you article explains why and what to do instead.
Set a calendar reminder for the same time next year. Security isn't a one-time fix — it's a maintenance habit, much like reviewing your household bills or checking your credit report.
This article is for general informational purposes only. It does not constitute professional cybersecurity or legal advice. For concerns about active breaches or sensitive accounts, consult a qualified security professional or contact the relevant platform's support team directly.



