Your Antivirus Is Not the Checkup: Audit the Accounts Attackers Can Reuse

A personal security checkup should begin with your accounts, recovery routes and signed-in devices—not with a green antivirus status or a VPN subscription. The most consequential weaknesses are often reusable credentials, an old session, missing multifactor authentication or software that has stopped receiving security fixes.
The practical shift is from asking whether a security product is installed to verifying whether each layer still works. The audit below covers the accounts that control your digital identity, the devices that hold their sessions, and the router through which many of those devices connect.
Start with the accounts that can reset everything else
Audit your primary email account first. Email commonly receives password-reset messages for shopping, social, cloud-storage and financial services, so losing it can give an intruder a route into otherwise unrelated accounts. Then check your password manager, mobile carrier account, Apple or Google account, banking services and any work account you administer.
For each critical account, verify the recovery email address and phone number rather than assuming they are current. Remove an address you no longer control, replace an obsolete number and store any one-time recovery codes somewhere separate from the device used for everyday sign-in. Do not deliberately trigger an account-recovery process merely to test it; changing or exhausting recovery options can create a lockout.
Next, inspect recent sign-ins and active sessions. Account dashboards may show several sessions for one physical device, so an unfamiliar-looking entry is not automatically evidence of compromise. For example, Google’s device-access instructions explain that background synchronization can produce a more recent timestamp than the user remembers and recommend signing out sessions that cannot be confidently identified.
If you find a genuinely unknown device, preserve any useful details, terminate its sessions and follow the provider’s compromised-account procedure. Change a reused password everywhere it appears, but do so from a trusted, updated device; changing credentials on a device you suspect is compromised may expose the replacement too.
Replace password reuse before polishing password complexity
A unique credential for every service matters more than inventing elaborate variations of one familiar password. A password manager can generate and store separate credentials, making it possible to replace reused passwords without relying on a personal pattern that carries across accounts.
Current advice also puts less weight on forced mixtures of symbols and more on length, uniqueness and stronger authentication. NIST’s updated consumer guidance recommends multifactor authentication, passkeys where available and a password manager; when a person must create a password manually, it recommends at least 15 characters and says mandatory special-character rules are no longer the priority.
Protect the password manager itself with multifactor authentication and a strong master password that is not used elsewhere. Before changing dozens of credentials, make sure you can recover the vault and access it from a second trusted device; otherwise, a lost phone could turn a security improvement into a broad lockout.
Upgrade authentication, starting with the highest-impact accounts
Turn on multifactor authentication for email, password management, banking, cloud storage and administrative accounts before lower-value services. Prefer a passkey, hardware security key or authenticator option when the provider supports it. Text messages are still an additional factor, but they should not be treated as equivalent to phishing-resistant methods.
Check what happens when the primary factor is unavailable. Register a second passkey or security key when supported, retain recovery codes, and remove authentication methods tied to discarded devices. A second factor that exists only on one lost phone is protection against account intrusion but also a potential availability problem.
Review connected applications at the same time. Remove integrations you no longer use, especially those with permission to read email, access cloud files or act on your behalf. Revoking an app’s access does not necessarily delete information it previously copied, so consult the app’s own account and deletion controls when sensitive data was involved.
Audit every device as a maintained system
List the phones, tablets, computers, smartwatches and shared machines on which important accounts remain signed in. Include older devices in drawers: a phone that is no longer used may still contain messages, authentication codes, cached files and active tokens.
For each device, complete the following sequence:
- Install pending operating-system, browser, application and security updates, then enable automatic updates where appropriate.
- Confirm that the operating system is still supported. If it no longer receives security fixes, retire it from sensitive account access or replace it.
- Enable a screen lock and use a short automatic-lock interval. Confirm that storage encryption and device-location or remote-erasure features are active where available.
- Remove software, browser extensions and device-management profiles you do not recognize or no longer need.
- Verify that backups contain the files you would actually need after theft, hardware failure or ransomware, and that you can restore them.
Built-in malware protection should be enabled and current, but do not expose a machine to live malware to “prove” it works. A clean scan is a useful signal, not proof that the device or its accounts are uncompromised. Unexpected administrative users, security tools that cannot be enabled, unexplained browser redirects or repeated sign-in alerts justify a deeper investigation.
Check the router instead of assuming the VPN secures it
A VPN can protect traffic within the scope of its connection, but it does not correct weak router administration, obsolete firmware or an unknown device already connected to the local network. Open the router or internet provider’s management interface from a trusted device and inventory connected clients, investigating names or hardware addresses you cannot place.
The FTC’s home Wi-Fi guidance recommends WPA3 Personal or WPA2 Personal encryption, unique Wi-Fi and administrator passwords, current router software, and disabling remote management, WPS and UPnP when they are not needed. It also notes that WPA and WEP are outdated; if updating the router does not expose WPA2 or WPA3, replacement is the safer course.
Separate guests and less-trusted connected products from computers that hold sensitive work or financial data when the router supports a guest network. Confirm that the router firewall is enabled, then log out of the administrator interface. If the internet provider manages firmware, verify its update policy rather than assuming patches arrive automatically.
Finish with a record you can repeat
Record only what helps the next audit: the date checked, unresolved devices, accounts still lacking stronger authentication, unsupported hardware and the location of recovery codes. Do not put passwords, passkeys or full recovery codes in the checklist.
A workable order is email and password manager first, then financial and cloud accounts, everyday devices, and finally the router and connected products. Repeat the review after losing a device, changing a phone number, receiving a credible sign-in alert or learning that a service you use suffered a breach. Between full reviews, install updates promptly and investigate security notifications through the provider’s app or a known address rather than through links in unsolicited messages.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.