Tech & Gadgets

Online Account Security Audit Checklist

Share
Laptop screen showing an online account security dashboard with lock and shield icons.

Key Takeaways

Reusing passwords across accounts is one of the most common and preventable security risks.
Two-factor authentication adds a meaningful layer of protection even when passwords are compromised.
Third-party apps connected to your accounts often retain access long after you stop using them.
Recovery options like backup email and phone number are frequently overlooked but critically important.
Reviewing privacy settings once or twice a year helps limit data exposure you may not notice day-to-day.
30–60 min

Summary

22 items · 30–60 minutes

Why a Security Audit Is Worth Your Time

Most people set up online accounts once and rarely revisit the underlying security settings. Passwords get reused, recovery options go stale, and third-party apps accumulate access they no longer need. A structured security audit addresses exactly these gaps — not by adding complexity, but by helping you see what's already there and fix what's quietly out of date.

This checklist covers the four areas that matter most: passwords and authentication, account recovery options, connected applications, and privacy controls. Working through it periodically — once or twice a year, or after a major life change like a new job or device — is one of the most practical things you can do for your digital safety.

For context on related habits worth building alongside this audit, see habits that quietly undermine your online privacy.

Prioritize Your Email Account First

Your primary email is the recovery key to almost every other account you own. If someone gains access to it, they can reset passwords across your entire digital life. Treat it as your most critical account and apply the strongest available security settings there before moving on to anything else.

What You'll Need Before You Start

Gather a few resources before working through the checklist. Having them ready reduces friction and means you're less likely to skip steps.

Required

Password Manager

Stores, generates, and autofills unique passwords so you don't have to remember or reuse them.

Required

Authenticator App

Generates time-based one-time codes (TOTP) for two-factor authentication, which are more secure than SMS codes.

Optional

Breach-Checking Tool

Checks whether your email addresses or passwords have appeared in known data breaches.

Required

Secure Offline Storage

A safe physical location (e.g. a locked drawer or safe) where you keep backup codes and a master passphrase note.

Prioritize the accounts that carry the most risk if compromised: your primary email, financial accounts, social profiles, and any account tied to your phone number or used for single sign-on (logging into other services via Google, Apple, or a similar provider).

The Security Audit Checklist

Work through each group below. Items marked must are non-negotiable for baseline protection. Should items are strongly recommended. Nice-to-have items offer additional hardening for those who want to go further.

Passwords

Confirm that each important account uses a unique password — not shared with any other service. Must
Replace any weak or reused passwords using a password manager to generate strong alternatives. Must
Set up a reputable password manager if you don't already use one, and store your master passphrase securely offline. Should
Check whether any of your passwords have appeared in known data breaches using a breach-checking tool (such as the free Have I Been Pwned service). Should
Enable breach monitoring alerts through your password manager or browser if available. Nice to have

Two-Factor Authentication (2FA)

Enable two-factor authentication on every account that offers it, starting with email, financial, and social accounts. Must
Switch from SMS-based codes to an authenticator app (such as a TOTP-based app) wherever the account supports it. Should
Save or print backup codes for accounts where 2FA is active and store them in a secure offline location. Should
Consider a hardware security key for your highest-value accounts if the platform supports it. Nice to have

Account Recovery Options

Verify that recovery email addresses on all important accounts are current and accessible to you. Must
Confirm that recovery phone numbers are up to date and still belong to you. Must
Review security questions where they exist — replace predictable answers with random strings stored in your password manager. Should
Check whether any accounts use a recovery email address that you no longer control (e.g. an old employer's domain). Must

Connected Apps and Third-Party Access

Review the list of third-party apps and services with access to each major account (found under Settings > Security or Privacy on most platforms). Must
Revoke access for any app you no longer use or don't recognize. Must
Note which apps have broad permissions (e.g. read and send email) versus narrow ones, and question whether broad access is necessary. Should

Privacy and Visibility Settings

Review who can see your profile, posts, or activity on social and communication platforms, and adjust to match your current preference. Should
Check location-sharing settings on accounts that collect or display your location. Should
Review ad personalization and data-sharing settings on major platforms and opt out of categories you're uncomfortable with. Nice to have
Download a copy of your account data from key platforms to understand what is stored about you. Nice to have

Revoking App Access Can Break Integrations

When you revoke a connected app's access, any functionality that app provided — automatic calendar syncing, email integrations, sign-in via that platform — will stop working immediately. Before revoking access in bulk, note which apps you actively rely on so you can re-authorize only those you need.

If you're also setting up a new device, the steps you take at that stage shape long-term security. Our guide on setting up a new device without creating a security headache later complements this audit well.

After the Audit: Staying Current

Completing this checklist once is a meaningful step — but security isn't a one-time event. Accounts accumulate new connected apps, platform settings change, and old recovery details go out of date. A brief review every six to twelve months, or any time you get a security alert, keeps things current without demanding significant ongoing effort.

Two-factor authentication deserves special attention as you maintain your accounts. SMS-based codes are convenient but carry real vulnerabilities. Our article on why a text message isn't always enough for two-factor authentication explains the differences between available methods and why they matter.

If your accounts connect to smart home devices or a shared home network, extending your security thinking to that environment is worthwhile. See home automation security habits worth keeping for practical guidance. And for a broader look at what platform privacy policies actually say about how your data is used, reading a privacy policy without losing your mind is a useful companion.

Tech & Gadgets Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech & Gadgets Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.