Tech

Account Security Audit Checklist

Person reviewing an account security checklist on a laptop in a home office

Key Takeaways

  • Reusing passwords across accounts is one of the most common reasons accounts get compromised.
  • Two-factor authentication blocks most automated login attempts even when a password is exposed.
  • Connected third-party apps can retain access to your accounts long after you stop using them.
  • Reviewing recent account activity helps catch unauthorized access before damage spreads.
  • Recovery options like backup email and phone number are often outdated and need periodic checks.
30–60 min

Summary

18 items · 30 to 60 minutes

Why a periodic security audit matters

Most people set up an account once and never revisit its security settings. That gap matters. Passwords get exposed in data breaches. Recovery phone numbers go stale. Apps you authorized years ago still have access to your data. A security audit is a structured way to close those gaps before someone else finds them.

This checklist covers the accounts that carry the most risk if compromised: email, financial accounts, social media, and any account tied to payment methods. Work through each section at your own pace. You do not need to complete everything in one sitting, but finishing the full audit within a week gives you a consistent baseline to build from.

For broader context on why even complex passwords sometimes fail, see why strong passwords still get compromised.

What you will need

Before you start, gather a few things to make the process faster.

Required

Password manager

Generates and stores strong, unique passwords so you can replace reused or weak ones during the audit.

Required

Authentication app

Replaces SMS-based two-factor codes with more secure time-based codes during the 2FA section.

Required

Breach check service (e.g., Have I Been Pwned)

Checks whether your email address appears in publicly known data breach databases.

Optional

Pen and paper or a secure notes app

Records backup codes and tracks which accounts you have already reviewed.

The audit checklist

Work through each group in order. Items marked must address the highest-risk gaps. Items marked should are strongly worth doing. Items marked nice to have add an extra layer but are optional.

Passwords

Change any password you have reused across more than one account, starting with email and financial accounts. Must
Replace any password shorter than 12 characters or made up of common words and numbers. Must
Store all passwords in a dedicated password manager rather than a browser or notes app. Should
Check whether your email address appears in a known data breach using a service such as Have I Been Pwned (haveibeenpwned.com). Should

Two-factor authentication

Enable two-factor authentication (2FA) on your email account, which is the recovery point for most other accounts. Must
Enable 2FA on any account tied to a payment method or financial data. Must
Switch SMS-based 2FA codes to an authenticator app where the service allows it, as authenticator apps are harder to intercept. Should
Save backup codes provided during 2FA setup in a secure, offline location. Should

Recovery options

Verify that the backup email address on each account is current and one you still control. Must
Confirm the recovery phone number is a number you still own. Must
Update any security questions that use answers easily found on your social media profiles. Should

Connected apps and permissions

Open the connected apps or third-party access section in your email and social accounts and revoke access for any app you no longer use. Must
Review which apps have permission to read contacts, messages, or calendar data and remove access where it is not needed. Should
Check OAuth connections ("Sign in with Google" or "Sign in with Apple" links) and disconnect any unfamiliar services. Should

Account activity review

Check the recent login history on your email account for unfamiliar devices or locations and sign out any sessions you do not recognize. Must
Review active sessions on social media accounts and remove any device you no longer use. Should
Look for any account notifications or emails about password resets or login attempts you did not initiate. Must

Social media privacy

Review who can see your profile, posts, and contact information on each social platform you use. Should
Remove personal details such as your full birthdate, home address, or phone number from public-facing profile fields. Nice to have

Start with your email account

Your email account controls password resets for nearly every other service you use. If it is compromised, an attacker can reset access to your bank, social media, and shopping accounts. Prioritize securing it with a strong unique password and two-factor authentication before moving to any other account on this list.

After the audit

Once you finish, note the date. A good target is to repeat this audit every six months, or immediately after any account shows suspicious activity or appears in a breach notification.

Building consistent habits between audits reduces how much work each review requires. The article digital security habits worth building from the start covers the day-to-day practices that keep your accounts in better shape over time.

If any of your accounts involve financial data, this audit pairs well with a broader review of your financial standing. A savings checkup checklist walks through a similar periodic review approach for your financial accounts.

Tech Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.