Key Takeaways
- Weak or reused passwords are the most common entry point for account compromises.
- Two-factor authentication adds a meaningful second layer of protection to your accounts.
- Outdated software on any device can expose you to known, patchable vulnerabilities.
- Reviewing app permissions and connected third-party accounts is often overlooked but important.
- Running this audit once or twice a year significantly reduces your exposure to common threats.
Summary
22 items · 30–60 minutes
Why a Security Audit Matters
Most security problems don't announce themselves. A compromised password, an overly permissive app, or an outdated device quietly creates risk until something goes wrong. A periodic security audit is simply a structured way to catch those gaps before they become serious.
This checklist is designed for everyday users — no technical background required. It covers passwords, two-factor authentication, device settings, privacy controls, and connected accounts. Work through it at your own pace; you don't need to complete it in a single sitting.
It's also worth understanding the distinction between online privacy and online security — they overlap, but they're not the same thing. See our guide to privacy vs. security for a clear breakdown before you begin.
Don't Skip Email — It's Your Master Key
Your primary email account is connected to virtually every other account you own. If it's compromised, an attacker can reset passwords across all your other services. Prioritise securing your email account above everything else in this checklist.
What You'll Need
Before starting the audit, gather a few basic tools. Having these ready will let you move through the checklist efficiently without stopping mid-task.
Password manager
Generates and stores strong, unique passwords for every account so you don't have to remember them.
Authenticator app
Provides time-based one-time codes for two-factor authentication, which is more secure than SMS-based codes.
Breach-checking service
Allows you to check whether your email address has appeared in a known data breach.
Note-taking app or printed checklist
Helps you track which items you've completed and note any follow-up actions.
The Complete Security Audit Checklist
Work through each group in order. Items marked must are non-negotiable fundamentals. Should items are strongly recommended, and nice-to-have items are worth adding if you have the time. For a deeper look at any individual topic — such as two-factor authentication — see our two-factor authentication explainer or our guide to how password managers work.
Passwords
Two-Factor Authentication
Devices and Software
App Permissions and Connected Accounts
Email and Phishing Awareness
Backup and Recovery
Save Your Recovery Codes Somewhere Safe
When you enable two-factor authentication, most services provide one-time recovery codes in case you lose access to your authentication method. Do not skip this step. Store these codes somewhere secure and offline — such as a printed document in a safe place. Without them, recovering a locked account can be extremely difficult.
Making This a Regular Habit
Running this audit once is useful; running it annually is genuinely protective. Security threats evolve, and accounts you open today may have different settings or new vulnerabilities a year from now. Consider pairing this review with another annual habit — such as a financial review or a home organization audit — so it becomes a natural part of your yearly routine.
If you have children who use devices or online accounts, their security posture deserves its own review. Our article on children and online safety covers the specific risks young people face. And if you use smart home devices, the habits in keeping smart home devices secure apply directly to this checklist's device section.
The goal isn't perfection — it's awareness. Each item you address meaningfully reduces your exposure to the most common online threats.
