Key Takeaways
- Reused passwords are one of the most common reasons accounts get compromised.
- Two-factor authentication blocks the vast majority of automated account takeover attempts.
- Recovery options like backup emails and phone numbers can lock you out if they're outdated.
- Connected third-party apps can retain access to your accounts long after you stop using them.
- Running this audit regularly — not just once — keeps your security posture up to date.
Summary
18 items · 45 minutes – 2 hours
Why a Security Audit Is Worth Your Afternoon
Most account compromises don't happen because someone cracked a sophisticated system. They happen because of a reused password from a data breach, an old recovery email that someone else now controls, or a forgotten app that still has full access to your account. These are fixable problems — and fixing them doesn't require any technical expertise.
This checklist walks you through every major area of account security in a logical order. Work through it on your primary accounts first: email, banking, social media, and any account tied to a payment method. For a broader picture of staying safe online, see our complete guide for everyday users.
Passwords
Two-Factor Authentication (2FA)
Recovery Options
Connected Apps and Permissions
Active Sessions and Devices
Email Account — Your Master Key
Tools That Make the Audit Easier
You don't need special software to complete this audit, but a few tools will save you significant time and make your improvements stick long-term.
Password Manager
Generates and securely stores unique passwords for every account, so you only need to remember one master password.
Authenticator App (TOTP)
Provides time-based one-time codes for two-factor authentication, a more secure alternative to SMS codes.
Have I Been Pwned (haveibeenpwned.com)
A free public service that lets you check whether your email address has appeared in a known data breach.
Secure Notes App or Printed Backup
Stores 2FA backup codes somewhere safe and accessible if you lose access to your authenticator device.
Once you have a password manager set up, the rest of the checklist becomes much more manageable. You'll also want to run the audit from a device you trust — not a public computer or a shared tablet.
Don't Run This Audit on a Public or Shared Device
Using a library computer, hotel kiosk, or a device someone else also uses exposes your passwords and session activity to serious risk. Always complete a security audit on a private device connected to a network you trust. If you must use a shared device in an emergency, change your passwords again from a private device as soon as possible.
SMS Two-Factor Authentication Is Better Than Nothing — But Not Perfect
Text message codes can be intercepted through SIM-swapping attacks, where someone convinces your carrier to redirect your number to their phone. For most people, SMS 2FA is still a significant improvement over no 2FA at all. However, for high-value accounts like email and banking, consider upgrading to an authenticator app when the option is available. For more on why credentials get exposed, see why strong passwords still get stolen.
After the Audit: Keep It Going
Running this audit once gives you a solid baseline, but account security isn't a one-time task. Threat landscapes change, services get breached, and your own habits evolve. Aim to repeat this checklist every six to twelve months, or immediately after you hear that a service you use has been involved in a data breach.
If you want to go further, the privacy settings audit for smartphone users covers app permissions and location access on your phone — a natural next step after locking down your accounts. For habits that protect you inside apps day to day, see our guide on keeping personal information safer while using everyday apps.
If You Spot a Breach, Act in This Order
If you find evidence of unauthorised access — an unrecognised session, a login alert you didn't trigger, or your email appearing in a major breach — act systematically. First, secure your email account (change password, confirm 2FA). Second, change the password on any account that shares that credential. Third, review active sessions and revoke access to unrecognised devices. Acting on your email account first matters most, since it controls recovery for everything else.
