A digital-security checkup is the online equivalent of checking smoke alarms and door locks. You review the accounts and devices that matter most, fix the largest weaknesses, and remove access you no longer need. One focused hour can reduce common risks without turning you into a cybersecurity expert.
This checklist prioritizes practical actions recommended by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Trade Commission (FTC), and the National Institute of Standards and Technology (NIST).
Before You Start: Protect the Recovery Path
Your primary email account is often the key to resetting other accounts. Secure it first, followed by your password manager, mobile carrier, financial accounts, cloud storage, and social media.
Work from a trusted device and network. Do not follow security links from an unexpected email or text; open the official app or type the known website address yourself. If you believe an account is already compromised, use the provider’s official recovery process rather than a routine checkup.
Minute 0–10: Update Devices and Apps
Install available operating-system, browser, security-software, and app updates. The FTC notes that criminals look for weaknesses before vendors can fix or users can patch them, and recommends enabling automatic updates.
Check:
- Phone and tablet operating systems
- Laptop or desktop operating system
- Web browsers and extensions
- Messaging, banking, and authenticator apps
- Router firmware, if your router does not update automatically
Remove apps and browser extensions you no longer use. Each one is another component that can request permissions, collect data, or fall behind on updates.
Minute 10–20: Strengthen Your Password System
Reused passwords turn one breach into access to several accounts. Use a reputable password manager to generate and store a unique password for every important service. Protect the password manager itself with a long, unique master passphrase and multi-factor authentication.
NIST recommends password managers and emphasizes protecting the vault’s login. If you need help evaluating options, DaiLova’s guide to password manager apps explains the main features to compare.
During this checkup, prioritize changing passwords that are:
- Reused across multiple sites
- Short, predictable, or based on personal information
- Saved in an unprotected document or note
- Associated with a known breach alert
- Shared with someone who no longer needs access
Do not change every strong unique password on an arbitrary schedule. Replace passwords when they are weak, reused, exposed, or potentially compromised.
Minute 20–30: Turn On Strong MFA
Multi-factor authentication (MFA) asks for another proof of identity in addition to a password. CISA says MFA makes account takeover significantly harder. Enable it first for email, password manager, financial, work, cloud-storage, and social accounts.
Use the strongest method each service supports. Security keys and passkeys can provide phishing-resistant authentication. Authenticator apps are generally preferable to having only a password; SMS codes are also better than no MFA, though phone-based codes can face additional risks.
Store recovery codes somewhere safe and separate from the device used for login. Confirm that your backup email and phone number are current. Remove obsolete recovery addresses that belong to an old employer, school, or phone number.
Minute 30–40: Review Sessions and Connected Apps
Open the security settings for your most important accounts and review:
- Devices currently signed in
- Recent login activity and unfamiliar locations
- Third-party apps with account access
- App-specific passwords
- Email forwarding rules and filters
- Delegates or shared-account members
Sign out devices you no longer own and revoke integrations you no longer use. If you see an unknown session, follow the provider’s security steps immediately, change the password from a trusted device, and review recovery details.
Minute 40–50: Reduce Unnecessary Data Exposure
Review permissions on your phone and browser. Does a weather app need precise location all the time? Does a simple utility need contacts, microphone, or photo-library access? Set permissions to “while using,” “selected photos,” or off when full access is unnecessary.
Also check:
- Public profile visibility and old posts
- Cloud folders shared by link
- Old documents containing identification or financial details
- Saved payment methods on stores you rarely use
- Inactive accounts that still store personal information
Delete accounts you no longer need through their official account settings when practical. Before deletion, export anything you need and confirm that another service does not depend on that login.
Minute 50–60: Prepare for Loss or Phishing
Confirm that important files and photos are backed up. Test that you can access the backup; an unverified backup is only an assumption. Enable device-finding and remote-lock features on phones and laptops where available.
Review one phishing rule: urgency is not proof. The FTC recommends protecting devices with updates and accounts with MFA, but technology does not replace judgment. Be suspicious of unexpected requests to click, sign in, move money, share a verification code, or “protect” an account.
When a message claims there is a problem, contact the company through its official app, a bookmarked site, or a number you already trust—not the contact details inside the message.
Do Not Forget Your Home Network
Change the router’s default administrator password if you have never done so, use current WPA security supported by your devices, and install firmware updates. Create a guest network for visitors and consider placing less-trusted smart-home devices on it if your router supports separation.
Make a short inventory of internet-connected cameras, speakers, televisions, plugs, and appliances. Remove devices you no longer use and confirm each remaining device still receives security updates.
A Monthly Five-Minute Maintenance Routine
- Install pending updates
- Review unusual sign-in alerts
- Remove one unused app or extension
- Check that backups completed
- Resolve any password-manager security warnings
Once or twice a year, repeat the full connected-app, recovery-method, and device-session review. Pair it with a broader digital declutter so security and everyday usability improve together.
The Bottom Line
Start with the accounts that can unlock everything else: email, password manager, mobile carrier, and financial services. Update software, use unique passwords, enable the strongest MFA available, revoke stale access, verify backups, and practice navigating directly to official sites. Security is not a one-time state; it is a short maintenance habit that steadily reduces avoidable risk.