Summary
22 items · 30–60 minutes
Why a Room-by-Room Approach Works
Most people think about digital security only after something goes wrong — a suspicious login alert, a friend warning them about a strange message sent from their account, or a charge they don't recognise. The problem isn't that threats are invisible; it's that checking everything at once feels overwhelming.
Framing your audit as a series of distinct "rooms" — your accounts, your devices, your network, and your browsing habits — keeps the process manageable. You can complete one area, take a break, and return. Each room has its own checklist below.
For a broader foundation on staying secure day to day, see the habits that keep everyday users secure online. This checklist is where you put those habits into practice.
Room 1: Your Accounts
Room 2: Your Devices
Room 3: Your Home Network
Room 4: Your Browsing Habits
What You'll Need Before You Start
You don't need specialised tools to complete this audit, but having a few things ready will make it smoother. Work through the checklist on a device you trust — ideally one connected to your home network rather than public Wi-Fi. If you're not sure what risks public networks carry, public Wi-Fi and the risks most people ignore is worth reading first.
Password Manager
Stores and generates unique, strong passwords for every account so you only need to remember one master passphrase.
Breach-Notification Service (e.g., Have I Been Pwned)
Checks whether your email addresses appear in publicly known data breaches.
Router Admin Access
Lets you review and update your home network's security settings, firmware, and connected device list.
Authenticator App
Generates time-based one-time codes for two-factor authentication, which is more secure than SMS codes alone.
Once you've gathered your tools, move through each checklist group in order. The accounts section carries the highest risk for most people, so start there even if you only have a short window of time.
Don't Skip the Accounts Section
If time is short, prioritise your email account above everything else. Email is the recovery method for nearly every other account you own — if it's compromised, an attacker can reset passwords across your entire digital life. A strong, unique password and 2FA on your primary email address are non-negotiable first steps.
After the Audit: Staying Ahead
Completing this checklist once is a solid start, but digital safety is an ongoing practice rather than a one-time fix. Schedule a lighter version of this review every three to six months — a calendar reminder takes 30 seconds to set and pays dividends.
Two areas often surface after the first audit: browser extensions and old devices. Extensions can quietly collect more data than most users realise; browser extensions — useful add-ons or a privacy risk? gives a clear breakdown of what to watch for. And if this audit leads you to retire an old phone or laptop, work through the data safety checklist before you recycle or resell a device before it leaves your hands.
Finally, be aware that many digital threats bypass technical defences entirely by targeting human behaviour. Understanding how scammers use social engineering to bypass your common sense helps you recognise manipulation before it succeeds. Technical hygiene and awareness together are far more effective than either alone.
Set a Reminder to Repeat This Audit
Digital threats evolve, and so do your own accounts and devices. A security posture that's solid today can develop gaps as you add new apps, change providers, or forget about old accounts. Scheduling a repeat audit every three to six months — even a shortened version — keeps your defences current. Add it to your calendar now before you close this page.
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.

