Tech Made Easy

Locking Down Your Online Accounts: A Security Audit You Can Do in an Afternoon

Person reviewing online account security settings on a laptop at a home desk.

Key Takeaways

  • Reused passwords are one of the most common reasons accounts get compromised.
  • Two-factor authentication blocks the vast majority of automated account takeover attempts.
  • Recovery options like backup emails and phone numbers can lock you out if they're outdated.
  • Connected third-party apps can retain access to your accounts long after you stop using them.
  • Running this audit regularly — not just once — keeps your security posture up to date.
45–120 min

Summary

18 items · 45 minutes – 2 hours

Why a Security Audit Is Worth Your Afternoon

Most account compromises don't happen because someone cracked a sophisticated system. They happen because of a reused password from a data breach, an old recovery email that someone else now controls, or a forgotten app that still has full access to your account. These are fixable problems — and fixing them doesn't require any technical expertise.

This checklist walks you through every major area of account security in a logical order. Work through it on your primary accounts first: email, banking, social media, and any account tied to a payment method. For a broader picture of staying safe online, see our complete guide for everyday users.

Passwords

Check whether you are reusing the same password across multiple accounts, and replace any duplicates with unique ones. Must
Ensure every password is at least 12 characters long and combines letters, numbers, and symbols — or use a long passphrase. Must
Set up a password manager to generate and store strong, unique passwords so you don't have to remember them all yourself. Should
Change the password on any account that appeared in a known data breach — you can check breach databases like Have I Been Pwned. Must

Two-Factor Authentication (2FA)

Enable two-factor authentication on every account that supports it, starting with email, banking, and social media. Must
Where possible, use an authenticator app (such as a TOTP app) rather than SMS text messages, which can be intercepted. Should
Save your backup codes in a secure location — losing access to your 2FA device without backup codes can lock you out permanently. Must

Recovery Options

Verify that your recovery email address is current and that you still have full access to it. Must
Confirm that the recovery phone number on each account is your current number, not an old one. Must
Review security questions, if used, and replace answers that could be guessed from your social media profiles. Should

Connected Apps and Permissions

Go to the settings of each major account and review the list of third-party apps that have been granted access. Must
Revoke access for any app you no longer use or don't recognise. Must
Check the permission level of remaining apps — remove write or delete access from any app that only needs to read data. Should
Avoid using 'Sign in with Google/Facebook' for new services unless you regularly audit which apps are connected. Nice to have

Active Sessions and Devices

View active login sessions for your email and social media accounts and sign out of any device or location you don't recognise. Must
Remove old or unused devices from your trusted devices list in account settings. Should
If you see a suspicious active session, change your password and enable 2FA immediately before ending the session. Must

Email Account — Your Master Key

Treat your primary email account as the highest-priority item: it controls password resets for nearly every other service. Must
Make sure your email account has a unique, strong password and 2FA enabled before securing anything else. Must

Tools That Make the Audit Easier

You don't need special software to complete this audit, but a few tools will save you significant time and make your improvements stick long-term.

Required

Password Manager

Generates and securely stores unique passwords for every account, so you only need to remember one master password.

Required

Authenticator App (TOTP)

Provides time-based one-time codes for two-factor authentication, a more secure alternative to SMS codes.

Required

Have I Been Pwned (haveibeenpwned.com)

A free public service that lets you check whether your email address has appeared in a known data breach.

Optional

Secure Notes App or Printed Backup

Stores 2FA backup codes somewhere safe and accessible if you lose access to your authenticator device.

Once you have a password manager set up, the rest of the checklist becomes much more manageable. You'll also want to run the audit from a device you trust — not a public computer or a shared tablet.

Don't Run This Audit on a Public or Shared Device

Using a library computer, hotel kiosk, or a device someone else also uses exposes your passwords and session activity to serious risk. Always complete a security audit on a private device connected to a network you trust. If you must use a shared device in an emergency, change your passwords again from a private device as soon as possible.

SMS Two-Factor Authentication Is Better Than Nothing — But Not Perfect

Text message codes can be intercepted through SIM-swapping attacks, where someone convinces your carrier to redirect your number to their phone. For most people, SMS 2FA is still a significant improvement over no 2FA at all. However, for high-value accounts like email and banking, consider upgrading to an authenticator app when the option is available. For more on why credentials get exposed, see why strong passwords still get stolen.

After the Audit: Keep It Going

Running this audit once gives you a solid baseline, but account security isn't a one-time task. Threat landscapes change, services get breached, and your own habits evolve. Aim to repeat this checklist every six to twelve months, or immediately after you hear that a service you use has been involved in a data breach.

If you want to go further, the privacy settings audit for smartphone users covers app permissions and location access on your phone — a natural next step after locking down your accounts. For habits that protect you inside apps day to day, see our guide on keeping personal information safer while using everyday apps.

If You Spot a Breach, Act in This Order

If you find evidence of unauthorised access — an unrecognised session, a login alert you didn't trigger, or your email appearing in a major breach — act systematically. First, secure your email account (change password, confirm 2FA). Second, change the password on any account that shares that credential. Third, review active sessions and revoke access to unrecognised devices. Acting on your email account first matters most, since it controls recovery for everything else.

Tech Made Easy Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech Made Easy Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.