
Key Takeaways
Summary
22 items · 30–60 minutes
Why a Room-by-Room Approach Works
Most people think about digital security reactively—after a data breach notification arrives or a suspicious charge appears. A proactive audit changes that equation. By working through your accounts and devices in logical categories, you avoid the overwhelm of treating "online security" as one giant, undefined problem.
Think of this checklist the way you'd think about a home walkthrough before a long trip: you go room by room, checking locks, turning off appliances, closing windows. Your digital life deserves the same structured attention. If you're newer to these concepts, our beginner's security guide covers the core principles behind each of these steps.
Work through each group below at your own pace. You don't need to finish in one sitting—but do finish.
Passwords
Two-Factor Authentication (2FA)
Account Access & Connected Apps
Device Settings
Email & Phishing Exposure
App Downloads & Installation Habits
Tools That Make the Audit Easier
You don't need specialized software to complete this audit, but a few tools can cut your time significantly and improve the results. Before you start, gather what you'll need.
Password Manager
Stores unique passwords for every account, generates strong new ones, and flags reused or compromised credentials.
Authenticator App
Generates time-based one-time codes for two-factor authentication, providing stronger protection than SMS codes.
Breach-Checking Service
Checks whether your email address or credentials have appeared in known data breaches (e.g., Have I Been Pwned).
Spreadsheet or Checklist App
Tracks your audit progress across account categories so nothing gets skipped.
Once you've completed the audit, the work isn't entirely done. Consider reviewing your device-level privacy configurations as a follow-on step—privacy settings worth knowing for your gadgets walks through the settings most users skip after unboxing.
After the Audit: What Comes Next
Completing a one-time audit is genuinely valuable, but the accounts and devices you use evolve constantly. New services get added, old ones get forgotten, and threat landscapes shift. Schedule a reminder to repeat this checklist at least once a year—or immediately after any reported breach involving a service you use.
Act Immediately on Any Suspicious Activity
If you notice unrecognized logins, unexpected password-reset emails, or unfamiliar connected devices during your audit, treat these as active incidents—not items to address later. Change the affected account's password immediately, revoke all active sessions, and enable 2FA if it isn't already on. Delays give bad actors more time to escalate access.
If during this audit you discover signs that an account has already been accessed without your permission, act quickly. Our identity theft recovery guide outlines the specific steps to take, from locking down accounts to notifying credit bureaus. For building habits that protect you between audits, see the cybersecurity habits that hold up over time.
This article provides general digital security information for educational purposes. It is not a guarantee of protection against all threats. Security needs vary by individual situation; consult qualified professionals for advice tailored to your specific circumstances.
