Tech & Electronics

Your Complete Online Safety Audit: A Step-by-Step Checklist

Share
Laptop displaying a security padlock icon surrounded by digital safety symbols on a desk

Key Takeaways

Weak or reused passwords remain the leading cause of account compromises — address these first.
Two-factor authentication (2FA) adds a critical second layer of protection beyond passwords alone.
App and account permissions often accumulate silently; reviewing them regularly limits unnecessary data exposure.
Software updates patch known security vulnerabilities — delaying them leaves devices exposed.
Auditing connected devices and third-party app access helps close gaps you may not know exist.
30–60 min

Summary

22 items · 30–60 minutes

Why an Online Safety Audit Matters

Most people set up accounts, install apps, and connect devices over months or years — and rarely look back. Over time, that accumulation creates real risk: old accounts with weak passwords, apps with broad permissions you forgot you granted, and software running versions with known security flaws. An online safety audit is a structured way to close those gaps before someone else finds them.

This checklist walks through the core areas that security professionals consistently flag as most vulnerable for everyday consumers: credentials, two-factor authentication, app permissions, device software, and network habits. You don't need technical expertise — just time and the willingness to act on what you find.

If you're new to thinking about your digital footprint, our introduction to online privacy covers the foundational concepts before you dive in. For a broader look at your financial exposure online, pairing this audit with an annual credit report checkup is also worth considering.

Passwords & Credentials

Identify all accounts that share the same password and assign each a unique one. Must
Replace any password shorter than 12 characters or based on obvious personal information (birthdays, pet names) with a longer, randomized passphrase. Must
Set up a password manager to generate and store strong, unique credentials for every account. Should
Check whether your email address appears in any known data breach using a reputable breach-checking service (such as haveibeenpwned.com). Should
Delete or deactivate old accounts you no longer use — dormant accounts with weak passwords are frequent targets. Should

Two-Factor Authentication (2FA)

Enable two-factor authentication on your primary email account — this is your highest-priority action. Must
Enable 2FA on all financial accounts, including banking, investment, and payment apps. Must
Switch any SMS-based 2FA codes to an authenticator app (such as Google Authenticator or Authy) where the service supports it — authenticator apps are more resistant to SIM-swapping attacks. Should
Store backup codes for 2FA-enabled accounts in a safe, offline location. Nice to have

App & Account Permissions

Review which third-party apps have been granted access to your Google, Apple, or Facebook account and revoke any you don't recognize or actively use. Must
Check app permissions on your smartphone (location, microphone, camera, contacts) and remove access that doesn't match the app's core function. Should
Audit which apps have permission to send you notifications and disable those that serve no useful purpose. Nice to have

Software & Device Updates

Install all pending operating system updates on every device — phone, laptop, tablet, and desktop. Must
Update all installed apps, including ones you rarely open, as outdated apps can contain exploitable vulnerabilities. Must
Check that your home router firmware is up to date by logging into the router's admin interface. Should
Enable automatic updates where available so future patches are applied without delay. Should

Network & Browsing Habits

Change your home Wi-Fi password if it's the factory default or hasn't been changed in over a year. Must
Avoid logging into sensitive accounts (banking, email) over public Wi-Fi; use a mobile data connection or a VPN instead. Should
Review browser extensions and remove any you didn't install intentionally or no longer need. Should
Clear saved passwords from your browser and migrate them to a dedicated password manager. Nice to have
Review privacy settings in your primary browser — disable third-party cookies and restrict cross-site tracking where supported. Nice to have

Tools You'll Need to Complete This Audit

You don't need specialist software to complete most of this checklist, but a few tools will make it significantly faster and more thorough. Gather these before you start.

Required

Password Manager

Generates and securely stores unique, complex passwords so you don't have to remember or reuse them.

Required

Authenticator App

Provides time-based one-time codes for two-factor authentication, replacing less secure SMS codes.

Required

Breach-Checking Service (e.g., haveibeenpwned.com)

Checks whether your email address appears in publicly known data breach databases.

Required

Router Admin Interface

Accessed via a browser to review and update your home router's firmware and network security settings.

Optional

VPN (Virtual Private Network)

Encrypts your internet connection when using public Wi-Fi networks to reduce interception risk.

Once you've completed your security audit, you may also find value in auditing your digital spending habits — our subscription app audit checklist helps you identify apps you're paying for but no longer using, which often carry their own permission and privacy risks.

Don't Overlook Your Email Account

Your primary email address is the recovery key for almost every other account you own. If an attacker gains access to it, they can reset passwords across banking, shopping, and social platforms. Treat your email account as the single highest-priority item in this entire audit — enable a strong unique password and 2FA there before anything else.

Free 'Security Scan' Tools Can Be Risky

Be cautious of unfamiliar browser extensions or websites advertising free security scans — some are designed to harvest your credentials rather than protect them. Stick to well-documented tools with transparent privacy policies and use breach-checking services directly in your browser rather than through third-party redirects.

What to Do After the Audit

Completing this checklist gives you a clear picture of where you stand — but the value comes from acting on it. Prioritize the must items first: update every reused or weak password, enable 2FA on your most critical accounts (email and banking especially), and install any pending software updates before moving on to lower-priority items.

Set a calendar reminder to repeat this audit every six to twelve months. Your digital footprint changes constantly — new accounts get created, apps get installed, and security vulnerabilities are discovered in software you already use. A regular review habit is more effective than any one-time fix.

Your Email Is the Master Key to Everything

If you only complete one step from this entire checklist, secure your primary email account first. A compromised email address gives an attacker the ability to reset passwords on virtually every service linked to it — including financial accounts. Use a unique, strong password and enable two-factor authentication before doing anything else.

If you want to extend your financial security review beyond online accounts, a structured spending audit checklist can help you identify recurring charges tied to services you no longer use or recognize — a useful complement to your security work.

Tech & Electronics Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech & Electronics Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.