Cyber Security

Account Security Audit: A Room-by-Room Walkthrough

Account Security Audit: A Room-by-Room Walkthrough

Photo credit: GadgetLite.net | All Things Tech

Work through this checklist to review your passwords, recovery settings, active sessions, and two-factor authentication all at once.

Key Takeaways

  • Weak or reused passwords remain the most common way accounts get compromised.
  • Two-factor authentication adds a critical second barrier even if a password leaks.
  • Active sessions and connected apps are easy to overlook but simple to clean up.
  • Recovery options like backup email and phone number must be kept current.
  • A regular audit — every few months — catches problems before they become crises.

Why a Security Audit Belongs on Your Calendar

Most account breaches don't happen with a dramatic hack. They happen quietly — through a password reused across sites, an old recovery email no longer in use, or a forgotten app that still has access to your calendar. A security audit is simply the habit of checking those overlooked corners on a regular schedule.

Think of it like inspecting each room in your house. You're not waiting for something to go wrong — you're making sure everything is locked and nothing is left open by accident. This checklist walks you through four "rooms": passwords, two-factor authentication (2FA), active sessions, and recovery settings. No technical background required.

Once you're done here, consider pairing this with a full app privacy audit to check which apps still have permission to access your accounts. And if you're setting up a new phone or laptop, this device setup checklist covers security from the very first login.

Passwords

Check every important account (email, banking, social media, cloud storage) and confirm each uses a unique password not shared with any other site. Must
Replace any password shorter than 12 characters with a longer passphrase or randomly generated string. Must
Search your email's inbox for any breach notification emails from services you use and change those passwords immediately. Must
Enable a password manager to store and auto-fill credentials so you aren't tempted to reuse passwords for convenience. Should
Run your email address through a breach-checking tool (such as a reputable public service like Have I Been Pwned) to see if any credentials have been exposed. Should

Two-Factor Authentication (2FA)

Enable 2FA on your primary email account — this is your highest-value target because password resets for other accounts flow through it. Must
Enable 2FA on financial accounts, cloud storage, and any account that stores sensitive personal information. Must
Switch from SMS-based 2FA to an authenticator app wherever the service allows it, since SMS codes can be intercepted. Should
Save or print backup codes for each account that offers them, and store them somewhere secure offline. Should
Review social media and shopping accounts and add 2FA to any that currently have none. Nice to have

Active Sessions and Connected Apps

Open the security settings of each major account and review the list of active sessions; sign out any devices or locations you don't recognize. Must
Revoke access for any third-party app or service you no longer actively use, especially those with write permissions. Must
Check which apps are connected via "Sign in with Google" or "Sign in with Apple" and remove any you no longer need. Should
Review your email account's filter and forwarding rules to confirm no unknown address is receiving copies of your messages. Should

Recovery Settings

Verify that your recovery email address for each account is current and belongs to an inbox you actively check. Must
Confirm your recovery phone number is up to date and tied to a number you still own. Must
Review and update any security questions (where still used) — avoid answers that can be guessed from social media profiles. Should
Store a copy of your password manager's master recovery key or emergency kit in a secure physical location. Should
Add a trusted contact or legacy access option on services that support it, so your accounts are recoverable in an emergency. Nice to have

Tools You'll Need Before You Start

You don't need specialized software to complete this audit — most of the work happens inside account settings pages you already have access to. That said, a few tools make the process much smoother and more thorough.

Required

Password manager

Stores all your unique passwords securely so you can audit and update them without relying on memory.

Required

Authenticator app

Generates time-based one-time codes for 2FA, providing a more secure alternative to SMS verification.

Required

Breach-checking service (e.g., Have I Been Pwned)

Lets you check whether your email address appears in any known data breaches, signaling passwords that need changing.

Optional

Secure offline storage (notebook or safe)

Provides a physical backup location for 2FA recovery codes and your password manager's emergency access key.

If you're unsure which 2FA method is right for your situation, our comparison of SMS codes, authenticator apps, and hardware keys breaks down the practical differences in plain terms.

After the Audit: Keeping What You Fixed

Completing this checklist once is a good start. The real protection comes from repeating it every three to six months, or any time you hear about a major data breach affecting a service you use. Set a recurring reminder in your calendar so it doesn't slip through the cracks.

Don't Skip the Recovery Settings Room

Outdated recovery email addresses and phone numbers are one of the most common reasons people permanently lose access to their accounts. If a recovery option points to an old email or a phone number you no longer own, you may be locked out with no way back in. Take the extra five minutes to verify these settings — it's far easier to update them now than to recover access later.

Public Wi-Fi is one of the fastest ways to undo good account hygiene. If you log into accounts at cafés, airports, or hotels, read up on protecting your accounts on shared networks to keep your credentials safe outside the home.

Finally, account security is only part of the picture. Make sure your files and photos have the same level of care applied to them — our personal data backup audit checklist is a natural next step once your logins are locked down.

Cyber Security Editorial Team

Author

Cyber Security Editorial Team

Cyber Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.