Summary

22 items · 30–60 minutes

Why a Room-by-Room Approach Works

Most people think about digital security only after something goes wrong — a suspicious login alert, a friend warning them about a strange message sent from their account, or a charge they don't recognise. The problem isn't that threats are invisible; it's that checking everything at once feels overwhelming.

Framing your audit as a series of distinct "rooms" — your accounts, your devices, your network, and your browsing habits — keeps the process manageable. You can complete one area, take a break, and return. Each room has its own checklist below.

For a broader foundation on staying secure day to day, see the habits that keep everyday users secure online. This checklist is where you put those habits into practice.

Room 1: Your Accounts

Audit your most-used accounts (email, banking, social media) and confirm each uses a unique, strong password of at least 12 characters. Must
Enable two-factor authentication (2FA) on every account that supports it, prioritising email and financial accounts first. Must
Check whether your email address appears in any known data breaches using a reputable breach-notification service such as Have I Been Pwned. Must
Review the list of third-party apps connected to your Google, Apple, or social media accounts and revoke access for anything you no longer use. Should
Update recovery phone numbers and backup email addresses on critical accounts to ensure they're current. Should

Room 2: Your Devices

Install pending operating system updates on all devices — smartphones, computers, and tablets — since updates frequently patch known security vulnerabilities. Must
Verify that automatic updates are turned on for your operating system and core applications so future patches apply without delay. Must
Confirm that screen lock is enabled on every mobile device, using a PIN, passphrase, or biometric that isn't trivially guessable. Must
Review installed apps and uninstall anything you no longer use — unused apps can still collect data and receive insecure updates in the background. Should
Check app permissions (location, microphone, camera, contacts) and revoke access that seems unnecessary for the app's core function. Should
Confirm that device encryption is enabled, particularly on laptops and Android phones where it may not be on by default. Nice to have

Room 3: Your Home Network

Log in to your home router's admin panel and change the default admin username and password if you haven't already. Must
Confirm your Wi-Fi network uses WPA3 or at minimum WPA2 encryption — older standards like WEP are no longer considered secure. Must
Check for available firmware updates for your router and apply them, as manufacturers release security patches for routers just as they do for phones. Should
Set up a separate guest network for smart home devices or visitors so that a compromised device doesn't sit alongside your primary devices. Nice to have

Room 4: Your Browsing Habits

Confirm that the sites where you enter passwords or payment details show HTTPS (the padlock icon) in the browser address bar before submitting anything. Must
Review saved passwords in your browser and migrate them to a dedicated password manager if you haven't already. Should
Audit installed browser extensions and remove any you didn't intentionally install or no longer need. Should
Clear stored cookies and cached data periodically, especially in browsers you use for financial or sensitive tasks. Nice to have
Consider enabling your browser's built-in phishing and malware protection settings if they aren't already active. Nice to have

What You'll Need Before You Start

You don't need specialised tools to complete this audit, but having a few things ready will make it smoother. Work through the checklist on a device you trust — ideally one connected to your home network rather than public Wi-Fi. If you're not sure what risks public networks carry, public Wi-Fi and the risks most people ignore is worth reading first.

Required

Password Manager

Stores and generates unique, strong passwords for every account so you only need to remember one master passphrase.

Required

Breach-Notification Service (e.g., Have I Been Pwned)

Checks whether your email addresses appear in publicly known data breaches.

Required

Router Admin Access

Lets you review and update your home network's security settings, firmware, and connected device list.

Optional

Authenticator App

Generates time-based one-time codes for two-factor authentication, which is more secure than SMS codes alone.

Once you've gathered your tools, move through each checklist group in order. The accounts section carries the highest risk for most people, so start there even if you only have a short window of time.

Don't Skip the Accounts Section

If time is short, prioritise your email account above everything else. Email is the recovery method for nearly every other account you own — if it's compromised, an attacker can reset passwords across your entire digital life. A strong, unique password and 2FA on your primary email address are non-negotiable first steps.

After the Audit: Staying Ahead

Completing this checklist once is a solid start, but digital safety is an ongoing practice rather than a one-time fix. Schedule a lighter version of this review every three to six months — a calendar reminder takes 30 seconds to set and pays dividends.

Two areas often surface after the first audit: browser extensions and old devices. Extensions can quietly collect more data than most users realise; browser extensions — useful add-ons or a privacy risk? gives a clear breakdown of what to watch for. And if this audit leads you to retire an old phone or laptop, work through the data safety checklist before you recycle or resell a device before it leaves your hands.

Finally, be aware that many digital threats bypass technical defences entirely by targeting human behaviour. Understanding how scammers use social engineering to bypass your common sense helps you recognise manipulation before it succeeds. Technical hygiene and awareness together are far more effective than either alone.

Set a Reminder to Repeat This Audit

Digital threats evolve, and so do your own accounts and devices. A security posture that's solid today can develop gaps as you add new apps, change providers, or forget about old accounts. Scheduling a repeat audit every three to six months — even a shortened version — keeps your defences current. Add it to your calendar now before you close this page.

Share

Tech Explained Editorial Team · Contributor

Tech Explained Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.