Monthly Security Audit
Set a monthly reminder to run through this checklist. It takes 15-20 minutes and catches problems before they become disasters.
Schedule It
Set a recurring calendar reminder for the 1st of each month. Treat it like a health checkup for your digital life.
Quick Audit (5 minutes)
Section titled “Quick Audit (5 minutes)”Check for Unauthorized Access
Section titled “Check for Unauthorized Access”- Gmail: myaccount.google.com/security > Recent security activity
- Facebook: Settings > Security and Login > Where You’re Logged In
- WhatsApp: Settings > Linked Devices (remove unknown devices)
- Instagram: Settings > Security > Login Activity
Look for:
- Logins from unknown locations
- Devices you don’t recognize
- Logins at times you weren’t active
Check Financial Statements
Section titled “Check Financial Statements”- Review last month’s bank statements
- Review credit card statements
- Check UPI transaction history
- Look for small test charges (scammers often test with ₹1-10 first)
Device Security (5 minutes)
Section titled “Device Security (5 minutes)”Software Updates
Section titled “Software Updates”- Phone: Check for system updates (Settings > Software Update)
- Apps: Update all apps from Play Store/App Store
- Computer: Install all pending updates
- Browser: Ensure Chrome/Firefox is up to date
Don't Skip Updates
Security updates often fix vulnerabilities that hackers are actively exploiting. An unpatched device is an easy target.
App Audit
Section titled “App Audit”- Delete apps you haven’t used in 3+ months
- Review apps for any you don’t recognize
- Check app permissions (especially SMS, Camera, Location)
- Remove apps from unknown developers
Storage Cleanup
Section titled “Storage Cleanup”- Clear downloads folder of old files
- Delete old screenshots that contain sensitive info
- Remove documents with personal information you no longer need
Account Security (5 minutes)
Section titled “Account Security (5 minutes)”Password Check
Section titled “Password Check”- Open your password manager
- Check for reused passwords (most managers flag these)
- Update any passwords that are weak or reused
- Check if any passwords were exposed in breaches
Two-Factor Authentication
Section titled “Two-Factor Authentication”Verify 2FA is enabled on:
- Email (Gmail, Outlook)
- Banking apps
- UPI apps
- Social media (WhatsApp, Facebook, Instagram)
- Shopping accounts (Amazon, Flipkart)
Recovery Options
Section titled “Recovery Options”- Verify recovery email is current
- Verify recovery phone number is current
- Ensure you have backup codes saved (for 2FA accounts)
Privacy Check (5 minutes)
Section titled “Privacy Check (5 minutes)”Social Media Privacy
Section titled “Social Media Privacy”- Review who can see your posts (friends only recommended)
- Check tagged photos and remove any you don’t want public
- Review and clean up old posts that share personal info
- Check your profile’s public view
Google Privacy
Section titled “Google Privacy”Visit myactivity.google.com:
- Review what Google is tracking
- Delete old activity if desired
- Review ad personalization settings
Location History
Section titled “Location History”- Review apps with location access
- Clear location history if you don’t need it
- Set apps to “Only while using” instead of “Always”
Breach Check
Section titled “Breach Check”Check If Your Data Was Leaked
Section titled “Check If Your Data Was Leaked”- Visit haveibeenpwned.com
- Enter your email addresses
- If breached, change password for that site immediately
- If password was reused, change it everywhere
Credit Monitoring (Quarterly)
Section titled “Credit Monitoring (Quarterly)”- Check your CIBIL score for unexpected changes
- Look for credit inquiries you didn’t make
- Verify no new accounts were opened in your name
Quick Wins This Month
Section titled “Quick Wins This Month”Pick one security improvement to make each month:
January: Password Hygiene
Section titled “January: Password Hygiene”- Set up a password manager if you haven’t
- Change 5 important passwords to strong, unique ones
February: 2FA Everywhere
Section titled “February: 2FA Everywhere”- Enable 2FA on 5 important accounts
- Set up an authenticator app
March: Device Security
Section titled “March: Device Security”- Review all app permissions
- Enable device encryption
April: Financial Security
Section titled “April: Financial Security”- Set up transaction alerts on all accounts
- Review and lower transaction limits
May: Privacy Cleanup
Section titled “May: Privacy Cleanup”- Do a social media privacy audit
- Google yourself and remove unwanted results
June: Backup Check
Section titled “June: Backup Check”- Verify phone backup is working
- Back up important documents to secure cloud storage
July: Family Security
Section titled “July: Family Security”- Help one family member set up 2FA
- Share one security tip with family
August: Physical Security
Section titled “August: Physical Security”- Review who has access to your devices
- Set up Find My Device
September: Email Security
Section titled “September: Email Security”- Unsubscribe from unnecessary newsletters
- Review email forwarding rules
October: Account Cleanup
Section titled “October: Account Cleanup”- Delete accounts you no longer use
- Remove connected apps you don’t recognize
November: Network Security
Section titled “November: Network Security”- Change your WiFi password
- Review devices connected to your network
December: Year-End Review
Section titled “December: Year-End Review”- Do a comprehensive security review
- Plan security goals for next year
Monthly Log
Section titled “Monthly Log”Keep track of your audits:
| Date | Findings | Actions Taken |
|---|---|---|
If You Find Something Wrong
Section titled “If You Find Something Wrong”Suspicious Login:
Section titled “Suspicious Login:”- Change password immediately
- Log out all other sessions
- Enable 2FA if not already
- Check for unauthorized changes to account
Unknown Transaction:
Section titled “Unknown Transaction:”- Call bank immediately
- Block card if needed
- File complaint with bank
- Monitor for more transactions
Data Breach:
Section titled “Data Breach:”- Change password on breached site
- Change same password anywhere else you used it
- Enable 2FA
- Monitor accounts for suspicious activity