Why a Personal Security Audit Matters

Most data breaches don't happen through sophisticated hacking — they exploit small, fixable oversights: a recycled password, an old recovery email, or an app with more access than it needs. The good news is that checking these things takes far less time than most people expect.

This checklist walks you through the key areas of your digital life where weak points tend to hide. You don't need to be technically minded to complete it. Work through it at your own pace — some items take seconds, others a few minutes. For a broader look at layering your defenses, see our comprehensive online safety guide.

Passwords

Identify any accounts where you reuse the same password and update each to a unique one. Must
Replace any password shorter than 12 characters or based on obvious personal information (names, birthdays) with a longer, random passphrase. Must
Check whether your email address has appeared in a known data breach using a reputable breach-checking service such as Have I Been Pwned. Must
Consider using a password manager to generate and store unique credentials — see our balanced look at password managers before choosing one. Should

Two-Factor Authentication (2FA)

Enable two-factor authentication on your primary email account — it is your most critical recovery point for all other accounts. Must
Enable 2FA on financial, banking, and payment accounts. Must
Switch any accounts using SMS-based 2FA to an authenticator app where the service allows it, as app-based codes are harder to intercept. Should
Store backup codes for 2FA-protected accounts in a secure location separate from your phone. Should

Account Recovery Settings

Verify that recovery email addresses and phone numbers on your key accounts are current and belong to you. Must
Remove old recovery options (previous phone numbers, shared email addresses) that are no longer under your control. Must
Review security questions on older accounts and replace guessable answers with random strings stored securely. Should

App Permissions

Open your phone's privacy or permissions settings and revoke location access for any app that does not genuinely need it. Must
Revoke microphone and camera access for apps that have no legitimate reason to use them. Must
Uninstall apps you haven't used in three months or more — unused apps still hold permissions and may receive less frequent security updates. Should
Switch any remaining location-dependent apps from "Always" to "While using" access. Should

Device and Lock Screen

Confirm your phone locks automatically after no more than 60 seconds of inactivity. Must
Ensure your lock screen does not display full message previews or notification content that others could read. Should
Verify your phone and computer operating systems are running the latest available security updates. Must
For a full device security review, see our guide to keeping your smartphone secure without becoming a tech expert. Nice to have

Connected Apps and Third-Party Access

Review which third-party apps have been granted access to your Google, Apple, or social media accounts and revoke any you no longer use. Must
Check active login sessions on your email and social accounts and sign out any sessions from unrecognized devices or locations. Must
Audit which apps can post on your behalf to social media and remove permissions for any you didn't intentionally grant. Nice to have

Tools That Make the Audit Easier

You don't need specialized software to complete this audit, but a few tools can speed things up significantly. Here's what's worth having open before you start.

Required

Password Manager

Generates and securely stores unique passwords for every account, removing the need to memorize or reuse credentials.

Required

Authenticator App

Produces time-based one-time codes for two-factor authentication, providing stronger 2FA than SMS text messages.

Required

Have I Been Pwned (haveibeenpwned.com)

Checks whether your email address has appeared in publicly known data breaches so you can prioritize which passwords to change first.

Required

Your Phone's Built-In Privacy Dashboard

Shows which apps hold which permissions (location, camera, microphone) in one place without requiring a third-party tool.

Optional

Secure Notes App or Encrypted Document

Stores 2FA backup codes and security question answers safely, separate from your main device.

Once you've gathered your tools, work through each checklist group in order. Prioritize the must items first — those represent the highest-risk gaps most likely to be exploited.

Don't Audit on a Public or Shared Network

Avoid logging into sensitive accounts to review settings while connected to public Wi-Fi or a network you don't control. If you need to complete the audit away from home, use your mobile data connection instead. Unsecured networks can expose credentials in transit.

Recovery Options Are Only Secure If You Control Them

A recovery phone number or email address linked to an old account, a shared family line, or a former employer's email gives someone else a potential path into your account. Check every key account for stale recovery details — this step is frequently skipped and frequently exploited.

If you share or sometimes lend your phone to others, the steps in our guide on protecting personal data when sharing or repairing your phone are a useful companion to this audit.

After completing this checklist, consider building the habits covered in everyday habits that quietly strengthen your online security to maintain the ground you've gained.