Skip to content

Monthly Security Audit

Set a monthly reminder to run through this checklist. It takes 15-20 minutes and catches problems before they become disasters.

💡 Schedule It

Set a recurring calendar reminder for the 1st of each month. Treat it like a health checkup for your digital life.


  • Gmail: myaccount.google.com/security > Recent security activity
  • Facebook: Settings > Security and Login > Where You’re Logged In
  • WhatsApp: Settings > Linked Devices (remove unknown devices)
  • Instagram: Settings > Security > Login Activity

Look for:

  • Logins from unknown locations
  • Devices you don’t recognize
  • Logins at times you weren’t active
  • Review last month’s bank statements
  • Review credit card statements
  • Check UPI transaction history
  • Look for small test charges (scammers often test with ₹1-10 first)

  • Phone: Check for system updates (Settings > Software Update)
  • Apps: Update all apps from Play Store/App Store
  • Computer: Install all pending updates
  • Browser: Ensure Chrome/Firefox is up to date
⚠️ Don't Skip Updates

Security updates often fix vulnerabilities that hackers are actively exploiting. An unpatched device is an easy target.

  • Delete apps you haven’t used in 3+ months
  • Review apps for any you don’t recognize
  • Check app permissions (especially SMS, Camera, Location)
  • Remove apps from unknown developers
  • Clear downloads folder of old files
  • Delete old screenshots that contain sensitive info
  • Remove documents with personal information you no longer need

  • Open your password manager
  • Check for reused passwords (most managers flag these)
  • Update any passwords that are weak or reused
  • Check if any passwords were exposed in breaches

Verify 2FA is enabled on:

  • Email (Gmail, Outlook)
  • Banking apps
  • UPI apps
  • Social media (WhatsApp, Facebook, Instagram)
  • Shopping accounts (Amazon, Flipkart)
  • Verify recovery email is current
  • Verify recovery phone number is current
  • Ensure you have backup codes saved (for 2FA accounts)

  • Review who can see your posts (friends only recommended)
  • Check tagged photos and remove any you don’t want public
  • Review and clean up old posts that share personal info
  • Check your profile’s public view

Visit myactivity.google.com:

  • Review what Google is tracking
  • Delete old activity if desired
  • Review ad personalization settings
  • Review apps with location access
  • Clear location history if you don’t need it
  • Set apps to “Only while using” instead of “Always”

  • Visit haveibeenpwned.com
  • Enter your email addresses
  • If breached, change password for that site immediately
  • If password was reused, change it everywhere
  • Check your CIBIL score for unexpected changes
  • Look for credit inquiries you didn’t make
  • Verify no new accounts were opened in your name

Pick one security improvement to make each month:

  • Set up a password manager if you haven’t
  • Change 5 important passwords to strong, unique ones
  • Enable 2FA on 5 important accounts
  • Set up an authenticator app
  • Review all app permissions
  • Enable device encryption
  • Set up transaction alerts on all accounts
  • Review and lower transaction limits
  • Do a social media privacy audit
  • Google yourself and remove unwanted results
  • Verify phone backup is working
  • Back up important documents to secure cloud storage
  • Help one family member set up 2FA
  • Share one security tip with family
  • Review who has access to your devices
  • Set up Find My Device
  • Unsubscribe from unnecessary newsletters
  • Review email forwarding rules
  • Delete accounts you no longer use
  • Remove connected apps you don’t recognize
  • Change your WiFi password
  • Review devices connected to your network
  • Do a comprehensive security review
  • Plan security goals for next year

Keep track of your audits:

DateFindingsActions Taken

  1. Change password immediately
  2. Log out all other sessions
  3. Enable 2FA if not already
  4. Check for unauthorized changes to account
  1. Call bank immediately
  2. Block card if needed
  3. File complaint with bank
  4. Monitor for more transactions
  1. Change password on breached site
  2. Change same password anywhere else you used it
  3. Enable 2FA
  4. Monitor accounts for suspicious activity