Tech & Electronics

Annual Digital Security Audit: A Checklist for Every Account and Device

Share
Laptop with security lock icon on screen beside a smartphone and checklist notepad on a clean desk.

Key Takeaways

Reused or weak passwords remain one of the most common entry points for account compromise.
App permissions and connected third-party services accumulate silently and deserve a yearly review.
Two-factor authentication significantly reduces the risk of unauthorized account access.
Outdated software on devices creates exploitable security gaps that updates typically close.
Old or dormant accounts you no longer use are security liabilities worth deleting.
45–90 min

Summary

28 items · 45–90 minutes

Why a Once-a-Year Audit Pays Off

Most people set up their accounts and devices once and rarely revisit the security settings. Meanwhile, passwords get reused across sites, apps accumulate permissions they no longer need, and old accounts sit forgotten — each one a potential doorway. An annual digital security audit is how you close those doors before someone else walks through them.

This checklist is organized into clear categories so you can work through it in one session or break it into smaller chunks across a week. If you're newer to these concepts, our beginner's guide to personal cybersecurity covers the foundational ideas that underpin everything here.

Don't Rush Through High-Stakes Items

Skipping steps like password changes or 2FA setup because they feel time-consuming is precisely the trade-off attackers rely on. Prioritize authentication and email security first — everything else can follow. If you discover a suspected active compromise (unrecognized logins, unexpected password reset emails), change your credentials and contact the service immediately before continuing the audit.

What You'll Need Before You Start

Gather these tools before diving in — having them ready makes the process far less frustrating.

Required

Password Manager

Stores, generates, and audits unique passwords for every account so you are not relying on memory or reuse.

Required

Authenticator App

Generates time-based one-time codes for two-factor authentication, replacing less secure SMS codes.

Required

Breach-Notification Service

Checks whether your email addresses have appeared in publicly known data breaches.

Optional

Antivirus / Antimalware Software

Scans computers for malware, spyware, and other threats that may have gone undetected.

Required

Secure Offline Storage (printed sheet or safe)

Provides a physical backup of 2FA recovery codes and password manager emergency kits.

The Full Audit Checklist

Work through each group systematically. Mark items as you go, and flag anything you can't resolve immediately so you can return to it within the week. For a broader look at managing digital clutter alongside security, see our guide on clearing digital clutter practically.

Passwords & Authentication

Audit your password manager (or browser-saved passwords) and replace any passwords that are reused across multiple sites. Must
Change passwords for high-value accounts — email, banking, and health portals — even if you believe they are not compromised. Must
Enable two-factor authentication (2FA) on every account that supports it, prioritizing email and financial accounts first. Must
Switch from SMS-based 2FA to an authenticator app on critical accounts, as SMS codes can be intercepted. Should
Check whether any of your email addresses appear in a known data breach using a reputable breach-notification service. Must
Review and update recovery email addresses and backup phone numbers on your most important accounts. Should

App Permissions & Connected Services

Open your smartphone's privacy or permissions settings and revoke location, microphone, camera, and contacts access for any app that doesn't genuinely need it. Must
Review which third-party apps have access to your Google, Apple, or Microsoft account and remove any you no longer use or don't recognize. Must
Check social media platforms (Facebook, Instagram, LinkedIn, X) for connected apps and revoke access to unused or unrecognized services. Should
Delete apps from your phone that you haven't opened in the past six months, as dormant apps still carry permissions and may receive fewer security updates. Should

Devices & Software

Ensure the operating system on every device — phone, tablet, laptop, and desktop — is running the latest available version. Must
Update all installed apps, especially browsers and email clients, to their current versions. Must
Verify that your home Wi-Fi router firmware is up to date and that you are using WPA3 or WPA2 encryption (check your router admin panel). Should
Confirm that automatic updates are enabled on all devices so critical security patches are applied without delay. Should
Run a full scan with a reputable antivirus or antimalware tool on computers you use regularly. Should
Check which devices are signed into your primary accounts (Google, Apple ID, Microsoft) and remove any you no longer own or recognize. Must

Old & Dormant Accounts

Make a list of online services you no longer use and delete those accounts, starting with any that store payment information. Must
Search your primary email inbox for account-creation confirmation emails to surface services you may have forgotten about. Should
Request data deletion where possible when closing accounts, particularly for services that store personal or health-related information. Nice to have

Email & Communications

Review your email forwarding rules and filters to ensure no unauthorized rules are silently redirecting copies of your messages. Must
Unsubscribe from mailing lists that you no longer read, reducing your exposure in the event of a marketing-database breach. Nice to have
Verify that your primary email account has a strong, unique password and that recovery options are up to date. Must

Backups & Recovery

Confirm that automated backups are running for your phone and any computers holding data you cannot afford to lose. Must
Store backup codes for your 2FA-enabled accounts in a secure offline location, such as a printed sheet in a safe or a locked password manager note. Must
Test at least one backup by attempting to restore a single file to verify the backup is actually functional. Should
Ensure your password manager's master password is strong and that its recovery method (emergency kit, trusted contact) is documented somewhere secure. Must

After the Audit: What to Do Next

Completing this checklist is a meaningful step, but security is not a one-time event. Schedule a calendar reminder to repeat this audit in 12 months. In the meantime, apply any urgent fixes — especially password changes or enabling two-factor authentication on accounts you flagged — within 48 hours while the audit is fresh.

For a deeper dive into browser privacy settings, data broker opt-outs, and layered privacy strategies, our complete guide to protecting your privacy online picks up where this checklist leaves off. You may also find it useful to pair this habit with a regular financial review — the monthly financial reset checklist offers a similar structured approach for your money life.

This article is for general informational purposes only. It does not constitute professional cybersecurity, legal, or financial advice. For concerns specific to your situation — such as a suspected breach or identity theft — consult a qualified professional or your relevant financial institution promptly.

Tech & Electronics Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech & Electronics Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.