Tech

Your Annual Digital Security Checkup

Your Annual Digital Security Checkup

Photo credit: ResultsPoint.net | Find The Required Information

Run through this checklist once a year to catch weak passwords, unused accounts, outdated software, and other gaps before someone else finds them.

Key Takeaways

  • Weak or reused passwords are one of the most common ways accounts get compromised — a password manager makes fixing this practical.
  • Old accounts you no longer use are security liabilities; closing them removes attack surface you don't need.
  • Software updates patch known security holes that attackers actively exploit — keeping devices current matters.
  • Two-factor authentication adds a meaningful layer of protection even when a password is stolen.
  • Reviewing app permissions and connected third-party services each year limits how much data is quietly shared.

Why a Once-a-Year Review Is Worth Your Time

Most digital security problems don't happen because someone was careless. They happen because the internet changes faster than our habits do. An account opened years ago, a router that's never been updated, an app you haven't touched in months — each one is a small gap that adds up over time. Think of this checkup the same way you'd think about changing smoke alarm batteries or rotating tires: low effort, high return, easy to schedule.

This checklist covers the areas where everyday users are most exposed: passwords, old accounts, software updates, privacy settings, and backups. Work through it once a year — or after any major life event like a move, a job change, or a breach notification — and you'll close the most common attack paths before someone else finds them. For more on the everyday habits that create risk without anyone noticing, see what quietly undermines online security.

You don't need to be technical to complete this checklist. Most steps take just a few clicks once you know where to look.

Required

Password Manager

Generates, stores, and audits unique passwords for every account so you never have to reuse them.

Required

TOTP Authenticator App

Provides time-based one-time codes for two-factor authentication, a more secure alternative to SMS codes.

Required

Breach-Checking Service

Checks whether your email addresses appear in publicly known data breaches.

Required

Cloud Backup Service

Automatically backs up your files and photos so you can recover them after device loss or ransomware.

Required

Router Admin Panel

Lets you update your router's firmware and review which devices are connected to your home network.

Optional

Data Broker Opt-Out Tool

Helps you request removal of your personal information from sites that collect and resell it.

How to Work Through the Checklist

Set aside a focused block of time — an hour is usually enough for a first pass, longer if you haven't done this before. Work through one group at a time rather than jumping around. The groups are ordered roughly by impact: password and authentication problems are the most exploited, so start there.

Unused Accounts Are Not Harmless

An account you forgot about ten years ago may still hold your real name, address, payment method, and password. If that site suffers a breach, those details can be used to access other accounts or enable identity theft. Closing dormant accounts is not housekeeping — it is a concrete risk reduction.

As you go, keep a simple notes document open. Jot down any account you decided to close, any password you changed, and any permission you revoked. That record helps you pick up if you're interrupted, and gives you a reference point for next year's checkup.

If you're also planning a trip or spending time on public networks, the steps around device updates and account security carry extra weight. Our guide on protecting your data when you travel covers the additional steps worth taking before you leave home. For a deeper look at why keeping software current matters — and when it's reasonable to wait — see understanding software updates.

Passwords & Authentication

Audit your passwords using a password manager's built-in health report and replace any that are weak, reused, or older than a year. Must
Enable two-factor authentication (2FA) on every account that supports it, prioritizing email, banking, and social media. Must
Switch from SMS-based 2FA to an authenticator app (such as any TOTP-compatible app) wherever available, since text messages can be intercepted. Should
Change the default password on your home Wi-Fi router if you have never done so. Must
Review and update security questions on accounts that still use them, avoiding answers that can be found on your social media profiles. Should

Account Cleanup

List every online account you have and close or deactivate any you no longer actively use. Must
Revoke access for any third-party apps connected to your Google, Apple, Facebook, or Microsoft account that you no longer recognize or need. Must
Check whether your email address appears in known data breaches using a reputable breach-checking tool, then change affected passwords immediately. Must
Unsubscribe from email lists that have your personal data but no longer serve you, reducing your exposure in future breaches. Nice to have

Device & Software Updates

Run pending operating system updates on every device — phones, laptops, tablets, and smart TVs. Must
Update all apps, not just the ones you use daily, since outdated apps can still expose vulnerabilities. Must
Check whether your router's firmware is current; log into its admin panel or visit the manufacturer's support page. Should
Remove apps and browser extensions you no longer use — each one is a potential entry point. Should

Privacy & Data Sharing

Review location, microphone, and camera permissions for every app on your phone and revoke access where it is not clearly necessary. Must
Check your social media privacy settings to ensure your posts, contact details, and friend lists are not publicly visible beyond your intent. Should
Opt out of data broker sites that sell your personal information if you want to reduce your public data footprint. Nice to have
Review your browser's saved passwords and autofill data; delete anything stored in plain-text browser storage and move it to your password manager. Should

Backups & Recovery

Verify that automatic backups are running on your phone, computer, and any device holding important files — and test that you can actually restore from them. Must
Store at least one backup copy offline or on a separate cloud service, so ransomware or a single-service outage cannot wipe everything. Should
Confirm that your account recovery options — backup email, phone number — are still accurate and accessible. Must
Keep a secure offline note of critical account recovery codes, especially for accounts with 2FA enabled. Nice to have

After the Checkup: Staying Ahead

Completing this review once puts you ahead of the majority of internet users. Completing it every year keeps you there. Consider pairing this digital review with other annual routines — a financial check-in, for instance, covers overlapping ground around account access and fraud exposure. Our annual financial review checklist is a natural companion to this one.

Don't Skip the Breach Check

Many people discover their credentials were exposed months or years after a breach occurred. Stolen login details are often sold and reused in automated attacks long after the original incident. Checking your email against a reputable breach database and acting on any results is one of the highest-value steps in this checklist.

SMS Two-Factor Has Real Limitations

Text-message verification codes can be intercepted through SIM-swapping attacks, where a bad actor tricks your carrier into transferring your number to a device they control. For accounts holding sensitive financial or personal data, an authenticator app provides meaningfully stronger protection than SMS codes alone.

If anything in this checklist surfaced an active problem — a breach hit, suspicious account activity, or a device you can't secure — treat it as urgent rather than part of a routine. Contact the relevant service's support team, and if financial information is involved, alert your bank or card issuer. For concerns that touch identity theft or fraud, the Federal Trade Commission's IdentityTheft.gov resource is a good starting point for understanding your options.

Staying safe online isn't about being paranoid. It's about making the obvious fixes that close the gaps most attackers are looking for.

Tech Editorial Team

Author

Tech Editorial Team

Tech Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.