Tech

Annual Online Safety Audit: Everything Worth Reviewing at Least Once a Year

A practical checklist covering passwords, app permissions, account recovery options, and privacy settings you should review every year.

Annual Online Safety Audit: Everything Worth Reviewing at Least Once a Year

Photo: ReadersChronicle.com | Your Comprehensive Learning Destination editorial

—— In This Article
  1. Why a Yearly Review Actually Matters
  2. The Full Audit Checklist

Key Takeaways

  • Reused or weak passwords remain the most common entry point for unauthorized account access.
  • App permissions and account recovery options accumulate silently — they need a deliberate annual review.
  • Privacy settings on social platforms and devices are frequently reset or changed by software updates.
  • Two-factor authentication (2FA) is one of the highest-impact protections you can enable on any account.
  • Old, unused accounts you have forgotten about can still expose your personal data if breached.

Why a Yearly Review Actually Matters

Most people set up their accounts and devices once and never look back. But your digital footprint changes constantly — you download new apps, share new information, and create new accounts throughout the year. Meanwhile, the security landscape shifts too: apps update their permission requests, platforms quietly revise their privacy defaults, and breach databases grow.

Think of this audit the same way you think about annual checkups for your home or your finances. Just as a seasonal home maintenance checklist catches small problems before they become expensive ones, a yearly online safety review catches digital vulnerabilities before they become serious incidents. It is also a natural companion to an annual savings and debt review — both reward the habit of deliberately pausing to assess your situation.

This checklist is designed for everyday users, not IT professionals. Work through it at your own pace — most people complete it in under an hour.

Required

Password Manager

Stores unique passwords for every account and flags weak or reused credentials during your audit.

Required

Authenticator App

Generates time-based one-time codes for two-factor authentication, more secure than SMS codes.

Required

Breach Notification Service

Checks whether your email address appears in known data breaches so you know which accounts to prioritize.

Optional

Encrypted Note or Offline Document

Stores backup 2FA recovery codes safely outside your primary devices.

The Full Audit Checklist

Work through each group below. Pay particular attention to the must items — these represent the protections with the highest real-world impact for the broadest range of people.

Passwords and Authentication

Audit your password manager and update any passwords flagged as weak, reused, or compromised. Must
Enable two-factor authentication (2FA) on all accounts that support it, prioritizing email, banking, and social media. Must
Check whether any of your email addresses appear in known data breaches using a reputable breach-notification service. Must
Replace SMS-based 2FA codes with an authenticator app on high-value accounts where possible, since SMS can be intercepted. Should
Set up a password manager if you do not already use one, so you can maintain unique passwords across every account. Must

Account Recovery Options

Verify that recovery email addresses and phone numbers are current and accessible across all major accounts. Must
Confirm that security questions use answers only you would know — avoid publicly available information like your hometown. Should
Download and store backup recovery codes for accounts that use 2FA, keeping them somewhere offline and secure. Should
Remove outdated recovery options, such as old phone numbers or email addresses you no longer control. Must

App Permissions and Connected Accounts

Review which apps have access to your location, microphone, camera, and contacts on each device, and revoke access that seems unnecessary. Must
Check third-party app connections on your major accounts (Google, Apple, Facebook) and remove any you no longer use or recognize. Must
Review which apps have permission to send you notifications and disable those from apps you rarely open. Nice to have
On mobile devices, check for apps you downloaded but no longer use, and uninstall them to reduce your permission footprint. Should

Privacy Settings

Review your social media profile visibility settings and confirm that only intended audiences can see your posts and personal details. Must
Check ad personalization and data-sharing settings on your primary email, browser, and social accounts. Should
Review location history settings on your phone and in apps like maps or fitness trackers, and clear stored history if appropriate. Should
Verify that your browser is not storing passwords or payment card details you did not intentionally save there. Should

Dormant and Forgotten Accounts

Search your primary email inbox for old sign-up confirmation emails and identify accounts you no longer use. Should
Close or delete accounts you no longer need — inactive accounts holding your personal data can still be breached. Should
Request data deletion from any service you close, where the platform offers that option. Nice to have

Device and Software Hygiene

Confirm that the operating system and all major apps on each device are running current, supported versions. Must
Review and update your device lock screen settings — use a PIN, password, or biometric that you have not shared with others. Must

Breach Exposure Requires Immediate Action

If a breach notification service shows that your email address has appeared in a known data breach, treat it as urgent — change the password on the affected account immediately, then check whether you reused that password anywhere else. Do not wait until your next annual audit. A compromised password that remains active is an open door.

If you have recently purchased or set up a new phone, tablet, or computer, the foundational steps in our guide to locking down a new device should be completed before you run through this annual audit. The two work together — the device guide covers one-time setup steps while this audit covers ongoing review habits.

If you have children or teenagers in your household, consider pairing this audit with a review of children's screen safety and privacy risks — their accounts and devices deserve their own dedicated review.

Don't Lock Yourself Out During the Audit

Before changing recovery options or revoking 2FA methods, make sure you have your backup codes downloaded and stored somewhere accessible. Changing a recovery phone number or email without first saving your backup codes can lock you out of your own account. Proceed methodically, one account at a time.

Tech Editorial Team

Tech Editorial Team

Tech Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View author profile
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.