Summary

22 items · 30–60 minutes

Why a Personal Security Audit Matters

Most security incidents don't happen because someone was careless — they happen because small gaps went unnoticed for too long. A personal online security audit is a structured way to surface those gaps before someone else exploits them. Think of it as a home walkthrough, but for your digital life: you're checking the locks, patching the cracks, and making sure nothing important has been left wide open.

This checklist is organized into four practical areas — passwords and accounts, device security, privacy settings, and network safety. Work through each section at your own pace. If you share devices with children, see our guide to protecting children online for additional steps tailored to family use.

Audit Your Most Sensitive Accounts First

If time is short, prioritize your primary email account above everything else. Your email is the recovery key for nearly every other account you own — if it's compromised, everything tied to it is at risk. Secure it with a strong unique password and 2FA before moving on to anything else.

What You'll Need Before You Start

Before working through the checklist, gather the tools that make the process faster and more thorough. You don't need to be technical — most of these are built into the devices and browsers you already use.

Required

Password Manager

Generates and securely stores unique passwords for every account, so you only need to remember one master password.

Required

Breach-Check Service

Searches publicly known data breach records to tell you if your email address or credentials have been exposed.

Required

Your Device Settings App

Used to review app permissions, encryption status, lock-screen settings, and software update status on your phone or computer.

Required

Router Admin Panel

Accessed via your browser to check Wi-Fi encryption type, update router firmware, and change default login credentials.

Optional

VPN (Virtual Private Network)

Encrypts your internet connection on public or untrusted networks, reducing the risk of data interception.

Optional

Authenticator App

Generates time-sensitive 2FA codes as a more secure alternative to receiving codes by SMS.

Having these ready means you can move through each section without stopping to look things up. Set aside a quiet 30 to 60 minutes where you won't be interrupted.

The Security Audit Checklist

Work through the groups below in order. Mark each item as you complete it. Items labeled must are non-negotiable for baseline protection; should items are strongly recommended; nice-to-have items add extra layers if you have the time.

Passwords & Account Access

Audit your passwords and replace any that are reused across multiple accounts with unique, strong alternatives. Must
Enable two-factor authentication (2FA) on your email, banking, and social media accounts at minimum. Must
Store all passwords in a dedicated password manager rather than in a browser or a notes app. Should
Check whether any of your email addresses appear in known data breaches using a reputable breach-checking service. Should
Review and remove any third-party apps or services that have access to your email or social accounts but that you no longer use. Should
Use a unique, randomly generated recovery email address or phone number for your most critical accounts. Nice to have

Device Security

Update the operating system on every device you own — phone, tablet, laptop, and desktop — to the current version. Must
Set a strong PIN, password, or biometric lock on every device, and make sure it activates after no more than two minutes of inactivity. Must
Enable automatic updates for all apps so security patches are applied without manual intervention. Should
Enable full-disk encryption on your laptop or desktop if it isn't already turned on by default. Should
Verify that the "Find My Device" or equivalent remote-wipe feature is active on your phone and tablet. Should
Review which apps have access to your location, microphone, camera, and contacts, and revoke any permissions that seem unnecessary. Should

Privacy Settings

Review the privacy settings on every social media platform you use, and set posts and profile details to the most restrictive option that still works for you. Must
Turn off ad personalization and data-sharing options in your phone's settings and in any browsers you use regularly. Should
Check whether your home address, phone number, or date of birth appears in people-search websites and request removal where the site provides an opt-out. Should
Review the data your browser is syncing to the cloud and remove anything you wouldn't want exposed if your account were compromised. Nice to have

Network & Connection Safety

Change your home router's default admin username and password to something unique and strong. Must
Confirm your home Wi-Fi network uses WPA3 or WPA2 encryption — not the older WEP standard. Must
Set up a separate guest network for visitors and smart home devices so they cannot access your main devices. Should
Avoid accessing sensitive accounts — banking, work email — on public Wi-Fi without a trusted VPN (virtual private network). Should
Update your router's firmware to the latest version to patch any known vulnerabilities. Nice to have
Disable remote management on your router unless you have a specific need for it. Nice to have

Many of the habits that create vulnerability — like reusing passwords or skipping updates — are covered in depth in our article on everyday habits that quietly undermine your online security.

SMS-Based 2FA Has Known Weaknesses

Receiving 2FA codes by text message is far better than no 2FA at all, but SIM-swapping attacks — where a criminal convinces your carrier to transfer your number — can intercept SMS codes. Wherever a service allows it, use an authenticator app instead of SMS for your most sensitive accounts. This single change meaningfully raises the bar for attackers.

After the Audit: Keeping Your Security Current

Completing a one-time audit is a strong start, but online threats evolve constantly. Security researchers broadly recommend revisiting core settings every three to six months — whenever a major app or OS update arrives is a natural trigger. If you travel frequently, pay extra attention to network safety; our guide to staying safe on public Wi-Fi covers the specific risks of connecting away from home.

For readers who want to go further, building safer digital habits that actually stick offers a practical framework for turning one-time fixes into lasting routines. Good security isn't about perfection — it's about consistent, manageable steps repeated over time.

Share

Technology Editorial Team · Contributor

Technology Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

The content on this site is provided for informational purposes only and should not be considered a substitute for professional advice. While we strive to provide accurate and up-to-date information, we make no guarantees regarding its completeness or accuracy. Always consult a qualified professional for advice specific to your circumstances before making any decisions.