Security isn't a state you reach, it's a thing that drifts. Passwords get reused under pressure, apps get connected and forgotten, recovery phone numbers go out of date, and accounts accumulate at services you no longer use.
Ninety minutes, once a year, catches all of it. Put it in the calendar on a date you'll remember — a birthday, the start of a quarter, whenever your tax filing is done.
1. Password audit (20 minutes)
Open your password manager and run its security check.
Reused passwords — fix these first, starting with anything financial or with your email. Reuse is what turns one breach into ten.
Weak passwords — anything short or predictable.
Breached credentials — the manager will flag accounts whose passwords have appeared in known breaches. Change these immediately, and anywhere else you used them.
Old passwords on important accounts — email, banking, cloud storage, domain registrar. Rotating these annually is reasonable practice even without a specific reason.
If you don't have a password manager yet, this is where the year's work starts. It's the highest-return item on the list by a wide margin.
2. Two-factor coverage (10 minutes)
Check that two-factor is on for, at minimum:
- Primary email
- Password manager
- Banking and financial accounts
- Platform accounts (Apple, Google, Microsoft)
- Cloud storage
- Domain registrar and web host
- Social media
- Anything with saved payment details
Then check the quality of it. Anywhere still using SMS, see whether the service now supports an authenticator app, a hardware key, or passkeys — support expands constantly and the account you set up three years ago may have better options now.
Verify your recovery codes exist and that you know where they are.
3. Recovery information (10 minutes)
The most commonly out-of-date thing in any account, and the thing that determines whether you can get back in.
For each important account, check:
- Recovery email — is it an address you still control and still read?
- Recovery phone — is it your current number? Old numbers get reassigned to other people.
- Security questions, where they still exist — the answers should be stored in your password manager, not be real facts about your life. Real answers are researchable.
- Trusted contacts or devices — still accurate?
A dead recovery email or a reassigned phone number is how people get permanently locked out of accounts they still own.
4. Active sessions and devices (10 minutes)
Every major service has a page showing where you're signed in — devices, locations, and last activity.
Review it and sign out of anything you don't recognize, anything on a device you no longer own, and anything at a location that doesn't make sense.
This is worth doing carefully. An attacker with an active session doesn't need your password, and stale sessions on sold or lost devices are a common quiet exposure. If you find something genuinely unexpected, change that account's password and sign out of everything.
Do this at least for: email, cloud storage, social media, banking, and your platform account.
5. Connected apps and permissions (15 minutes)
The most under-audited item in personal security.
Every service has a page listing third-party applications with access to your account — look for "connected apps," "third-party access," "apps with account access," or similar in security settings.
You'll find things you granted access to years ago: a scanning app, a photo editor, a productivity integration, a game, a service that no longer exists. Many of these have broad, ongoing access, and it persists after you delete the app and after the company is sold.
Revoke everything you don't currently use and trust. Be aggressive — reconnecting something you actually need takes thirty seconds.
Do this for: your email and platform accounts, cloud storage, social media, and anything you've used "sign in with" for.
Also check browser extensions while you're here. Extensions often have permission to read everything on every page you visit. Remove anything you don't actively use, and be aware that extensions change hands and can become malicious after acquisition.
6. The abandoned account sweep (15 minutes)
Search your email for "welcome," "verify your email," and "your account" to surface services you've signed up for and forgotten.
For each one you no longer use:
Delete the account if the service supports it. An account you don't need is a breach you don't need, and every dormant account holds some personal data about you.
If deletion isn't offered, remove what you can — payment details, address, phone number — and change the password to something unique.
Pay particular attention to anything holding payment details or identity documents.
This is also where you find subscriptions you're still paying for. The security sweep and the wasted-money sweep are the same exercise.
7. Financial and identity checks (10 minutes)
Review card statements for the past few months for anything unfamiliar. Small recurring charges are the ones that go unnoticed.
Check your credit report, where free access is available in your country. Unexpected accounts or searches are the earliest indicator of identity fraud.
Consider a credit freeze if that's available where you live and you're not planning to apply for credit. It's free in many jurisdictions and it's the strongest single protection against identity fraud.
Check which services have your card on file and remove the ones you don't use.
8. Device and software check (10 minutes)
- Operating system updates installed on every device, including the ones you use rarely
- Full disk encryption on everywhere — computers, phones, tablets, backup drives
- Screen locks set on all devices
- Find-my-device enabled
- Old devices in drawers: wiped, signed out, and removed from your account device lists
- Router firmware updated, and the admin password changed from the default
- Wifi password — still strong, and consider whether it's been shared widely enough to warrant changing
The router is the most commonly neglected item here. It's the front door to your network and most people have never logged into it since installation.
9. Backup verification (10 minutes)
Security and backup overlap, and this is where they meet.
- Restore one file from your backup and open it
- Check the last successful backup date for every system
- Confirm the off-site copy is current
- Verify encryption keys and recovery keys for backup drives are stored and accessible
- Check your phone backup is running and recent
Ransomware makes backup a security control, not just a disaster control. A tested, offline backup is the thing that turns an infection into an inconvenience.
Write it down
Keep a file — Security Checkup Log.md — with a few lines per year:
## 2025 checkup — 2025-04-08
Fixed: 14 reused passwords, revoked 23 connected apps
Found: recovery phone on bank account was my old number — updated
Found: backup drive hadn't run since January — reconfigured, restore tested
Deferred: hardware keys, again
Two purposes. It shows what keeps recurring, and it means next year's checkup starts from a known position rather than from scratch.
If you only have twenty minutes
The risk-weighted core:
- Turn on two-factor for your email, if it isn't on. Everything resets through email.
- Change any reused password on a financial account.
- Revoke connected apps on your email and cloud storage.
- Check your recovery phone and email are current.
- Restore one file from your backup.
Those five cover most of the actual risk. The rest of the list is refinement, and it's worth doing — but if the ninety minutes never materializes, the twenty is far better than nothing.
Next in this series: Offsite Backups for People Who Don't Trust the Cloud