Personal Security Audit: 4 Essential Fixes From an Analyst

Last Update: August 15, 2026

I’ve been in IT for nearly two decades. Nearly half of that has been spent in the realm of security, compliance, and auditing. I’ve helped billion dollar companies pass ISO Audits and on multiple occasions brought thousands of servers across multiple divisions from compliance levels in the low 30% range to 99% compliance across a multitude of different measures. For all that time and experience, I  never performed a personal security audit where I applied that same logic to my home network.

Now let’s make something clear here, that isn’t unusual. In fact, among the other security professionals and really IT professionals in general, it’s actually the norm.

Let me tell you a short story about why I use all Apple products at home. It all ties in to my previous point about the IT and security professionals rarely applying the same thinking from work to their home networks…I promise.

I used to be a Mac hater. I was all about building your own custom computers and I was Windows all the way and I was very good at it. About 30 minutes after I got in to work that morning, a critical Windows server went offline and I got assigned to fix it. Fortunately I was able to get service restored quickly by failing it over to a new server, but I still needed to get the original one fixed. I spent the better part of 10 hours that day working on it and trying every trick I knew for Windows and quite a few I’d learned on the fly before I finally got it up and running again.

OK, so that’s just typical IT stuff and remember, this was before the days of ChatGPT, so you had to actually know how to research. I got home that night and I just wanted to relax and play a simple game on my laptop. I booted up my laptop and I was presented with the Blue Screen of Death. I nearly threw my laptop across the room I was so annoyed. The last thing I wanted to do after troubleshooting Windows all day was come home and troubleshoot Windows.

So I went nuclear and I ordered a MacBook Air. I hadn’t used a Mac in 8 years and I had no idea how to work one, but if it meant not having to troubleshoot Windows, then I was going to try it. Now my house is all Apple. All because I got annoyed with having to troubleshoot Windows one day.

So let’s bring this back to why IT and security professionals rarely apply what they do at work to their home networks. At the end of the day, the last thing we want to do after working on corporate networks is go home and do a personal security audit because  realistically that is just going home to do more work. We want to separate our lives from that so we don’t get burned out.

That’s why it’s not uncommon that you will find that people like myself who spend all day trying to bring work systems into compliance and preaching multi-factor authentication go home and reuse the same password that we set in 2007.

Yes, it’s hypocritical and I’ll be the first to admit that I’m guilty of doing just that. I have two passwords from 2006 and 2007 that I’ve been systematically removing from my accounts for years now.

There is this strange blind spot that happens when you work in information security professionally. It’s always something that happens at work, on someone else’s budget, with someone else’s compliance deadline hanging over it.

Your own home network just sort of exists in the background. You don’t examine it because nobody is paying you to do so and there is no auditor coming to check it. Plus, quite frankly at the end of the day it’s taking your work home, which is something I’m very against because it takes away from the time that needs to be spent decompressing.

A few months ago, I decided that I wanted to take my skills for compliance and auditing to the next level and I started studying for an exam called the CISA, which is a Systems Auditing certification. In short, this exam is all about taking what I’ve already been doing professionally for the last 10 years and and putting a certification behind it to back up that knowledge.

As part of that, I needed something to practice on and I realized that my own personal network was the perfect target for an actual structured audit. So I took everything that I’d been doing professionally for years, combined it with some new things from the CISA study guides, and then tailored it towards a home network.

This made it into an actual structured audit that included an inventory, exposure mapping, risk prioritization, and recommended remediations. Mind you, I haven’t actually implemented every remediation because quite honestly, there was a lot more exposure points than I had anticipated. But it got me pointed in the right direction.

More importantly it made me realize, if someone like me who is in the industry and knows about these things has this many exposure points, how many people who are far less knowledgeable  about this type of thing could use my help?

Everyone deserves to have a safe and secure digital life. So I decided to write out the framework I used and to break it out into pieces that you can actually apply to your digital life. My goal was to make it so even if you don’t know what a firewall or a password manager is, that you can have a more secure and private digital life.

While I love digital minimalism, when I did this audit of my home network I realized that this was a missing component of the entire philosophy.

So much of the advice tells you to delete apps and turn off notifications. That’s fine. I’ve written extensively about doing just that because it’s a critical part of digital minimalism and advice I personally follow. However, digital minimalism without digital privacy is like building a house and then not installing a lock on the door.

Who This Is Actually For

Before we go much further down this path, let me be completely up front about who I am writing this for. This isn’t for those of you who want to disappear off the internet. If I knew how to do that, I’d be all over it and I’d be sharing that information with the world.

Instead, I imagine a person with a smartphone, a laptop, probably a tablet and a smart watch. Maybe even a handful of smart home devices like cameras, speakers, or an Amazon Echo. If this sounds a bit more like you then you are my audience.

I’m going to go out on a limb here and guess you’ve probably never sat down to think about how any of those things add up from a security standpoint. Don’t worry, up until a few months ago I didn’t either so you definitely aren’t alone. However, coming from a security background, I have the knowledge of how to analyze those things and see how they come together and I feel that everyone should have access to that knowledge.

Just don’t become paranoid about it. That doesn’t help anyone. What I’ve put together is a process so that you know exactly where you stand. Once you’ve got that in place, you can start to  make real changes towards your privacy and security.

 Notebook checklist representing the four-step audit framework

What a Personal Security Audit Actually Is

To understand where I am coming from, you need a baseline understand of what a security audit is in the enterprise world. It’s simply a structured look at what you have, what could go wrong, and what you are going to do about it in order of priority.

This can just as easily be applied to your home network as any enterprise network, just without all the corporate speak and politics. There are four core pieces that are always exactly the same no matter if it’s your home network with 5 devices or an enterprise network with 200,000 devices:

  • Asset Inventory: This is a listing of what devices, accounts, and data actually exist.
  • Exposure mapping: This is what is actually reachable and by whom.
  • Risk prioritization: This is figuring out what gaps matter the most given your actual situation.
  • Remediation: This is fixing the gaps based on the risk prioritization.

That’s not so bad is it? It actually sounds a lot more difficult than it actually is. It’s easy to get really intimated when people start throwing around words like audit. Don’t let the terminology discourage you. An audit is simply an honest look at your situation.

This is your home network. Nobody is going to grade you or hand you a compliance score at the end of this. In fact, let’s just be completely honest about this. Nobody cares about your security audit except for you. You are doing this for yourself. For your own peace of mind. For your own sense of security and privacy. You are doing this because even if nobody else around you realizes it, this is important.

Why This Matters More Than the Usual Digital Minimalism Advice

I got into digital minimalism because I felt that my phone was consuming too much of my time and I was missing out on my kids growing up. For most people who find digital minimalism, their journey is pretty similar. Technology consumes their life, they need to find a way to cut back, and they find digital minimalism.

What few people realize is that the relationship between your attention and your phone is only one side of the coin. The other side involves privacy, hackers, and people who are determined to make as much money as possible from your personal data.

Another short story. During an interview for a position I had applied to, the hiring manager posed the scenario (which I am paraphrasing for a wider audience): “We have 3 networks and you’ve just been granted full access to all three of them. What security precautions do you take?”

My answer was “Start by asking if I actually need that level of access on the network and if not, have them reduce my access to only what I actually need.”

Yes I did get the job, but that’s not the point here. This demonstrates a very important point. Every account you have is something that can be breached. I didn’t want more access than was required because I didn’t want my account to be the one that brought down the company.

At the end of the day, all your apps have code that contain some level of access to your devices. Any subscriptions and accounts are holding some slice of your personal data that is subject to their security practices not yours. I can’t count the amount of times I’ve gotten notices from various organizations letting me know that my personal data was involved in a security breach.

So when I think about decluttering my digital life, I’m not just thinking about focus and distraction. Yes, that is absolutely an important part of it, but I am also thinking about my attack surface. Fewer accounts means fewer places that can be breached.

So yes, I’ve been talking a lot about security and audits and you might be thinking at this point, man this guy lost the plot. So let’s tie this all back to digital minimalism because I assure you this all ties together.

Every time I close an old account rather than ignoring it, I’m doing two things at once. First, I am reducing digital clutter. Hey! We are back the digital minimalism side of the equation again. I told you it all tied together! The second thing I’m doing is closing the door on potential security and privacy issues. This is the personal security audit portion.

While these used to feel like separate chores and yes, I do use the word chores because realistically nobody wants to spend their time cleaning out old accounts. Nothing about it is fun. Once I realized that these were the same chore it made the whole project a bit easier to follow up on because suddenly I had two reasons to finish rather than just one.

A Tale of Two Audits

So before you go digging into your own personal security audit, it helps to see this process from a lens of contrast. I find this is helpful because two people running through the same process can come out with two very different results.

Let’s start with our first person. She’s a retired school teacher living in Bend, Oregon. She’s got a tablet that she uses for email, FaceTime, pictures of her grandkids, and the occasional online order.

Our second person is a small business owner based out of Seattle, Washington. She handles client payment information and logs into a half a dozen vendor portals every day just to keep her business running.

These are two very different people who both could benefit from a personal security audit. They are going to have very different results. Our school teacher’s biggest exposure is most likely going to be that she’s got a handful of forgotten accounts and she is probably using a password that she uses everywhere stored in a plain text file and she hasn’t changed it since 2016 when her daughter set it up for her.

If this sounds oddly specific, welcome to pretty much every interaction I’ve had trying to help one of my parents, my in-laws, or the parents of my friends with their phones or tablets in the last 10 years. Her fix list is going to be pretty short and once she is through it, she’s going to be in good shape for years to come.

The business owner on the other hand is going to have a much longer list. This is because her livelihood and her life in general is riding on more systems. So any breach is going to have real financial consequences and it will be far more than just an annoyance.

A big problem that frequently comes up is that people either have the business owner’s anxiety level about security while only having the school teacher’s level of exposure. It’s even worse if the reverse is true. If that business owner assumes they are fine because they are “just a regular person.” Regular people are exactly who most attackers target. Regular people are much easier targets than a hardened business network. The personal security audit will tell you exactly what situation you are on rather than leaving you guessing.

Threat Modeling for Dummies

I don’t know if they are still a thing, but the ‘For Dummies’ books were some of my favorite books as a young adult because back before YouTube could teach you anything, you just had to find a way to figure things out. These books were masters at breaking things down to make them easy to understand. So I wanted to take that exact same concept and apply it to Threat Modeling.

Threat Modeling sounds incredibly complex but in reality it is really easy. It’s actually just answering three questions:

  1. What am I trying to protect?
  2. Who would realistically want it and why?
  3. What am I willing to do or give up to protect it?

That third question is the one that really requires the most thought because it’s going to vary wildly depending on your personal situation. Let’s go back to our retired school teacher and our business owner. The school teacher doesn’t have much in the way of things she is actively trying to protect. Her biggest concern might be that she doesn’t lose her master passwords for her phone’s account. So the most she is willing to do to protect it is to stop storing the password on a sticky note on her fridge and actually put it in her safe.

On the other side, our small business owner’s livelihood depends on protecting her data. So she might be willing to start changing all of her passwords to become far more complex, storing them in a password manager, and then turning on multi-factor authentication.

Both answers are completely valid. Where people start to run into issues is when they start borrowing someone else’s threat model wholesale, usually from some viral post about mass surveillance, without ever asking if it actually applied to their own lives.

The Four Domains I Actually Audit

When I ran through my own audit, I organized it into four areas. This mirrors how I structure enterprise audits, but scaled down to a household.

1. Devices

Flat-lay illustration of everyday connected devices reviewed in a home network audit

I didn’t realize how many devices I had on my network until I ran through the audit of my house. When all was said and done, I had over 80 devices on my network. Now for a lot of you, you probably won’t have that many. In our case, I tried and failed to setup a cohesive smart home a few years back so we have more than the average person.

So what falls into the category of devices? Phones, laptops, tablets, smart watches, smart speakers, smart light bulbs, and so much more. Every single one of these devices has some level of access on your network and to your data.

Now I have an Excel spreadsheet that contains a complete list of all the devices, the IP addresses, the MAC address, and a bunch of additional information. Now I’m a data junkie you probably don’t need all that extra information like the IP or MAC address. If you don’t know what those things are, you absolutely don’t need to know for an audit.

I was genuinely surprised at how many devices were on my network. I had expected around 30 or 40, not 83. I had items on there that I had absolutely no idea what they were until I started digging around. That’s how I learned that my mattress has an IP address. Fun fact, once I figured that out, I was able to get sleep data from my mattress fed into my Apple Health app.

Also as part of the device audit, I looked into what was actually talking to each other on the network. Depending on what type of router you have, this might be easy or difficult. If you’ve got a router from your ISP then trying to track down this information might prove to be more effortless than it’s actually worth. If you’ve got a higher end router such as one from Unifi, this information is really easy to get a hold of and worth looking into.

I bring this up because I none of my smart bulbs or smart light switches need to speak to my file server. The best practice is to isolate devices that don’t need to talk to each other on separate networks. In the enterprise world we call this network segmentation. It’s standard practice in any corporate network.

At home, pretty much nobody does it because when you just take it at face value it seems like complete overkill. I’ve got a fun story about why I segmented my home network. It started out as a very simple segmentation where I added on a guest network. Now network segmentation could easily fall into auditing category of network exposure, but I opted for putting it under devices because…well you’ll understand.

Way back in 2015 my home network was very simple. Like simple enough that all my devices on the network had fun names that were named after characters in Alice in Wonderland, something that started clear back in 2006 when I setup my first home network.

Fun fact, my core 3 devices (iPhone, iPad, and MacBook) still use this old naming scheme. However, as a general rule I don’t recommend using a naming scheme like this because once you get above about 10 devices it gets really hard to keep track of what each thing is.

At that time I got my first Sonos speaker. If you aren’t familiar with Sonos, it’s a wireless speaker that sits on your network and you can control it from your phone. At the time it was pretty mind blowing that technology like that had become so easily accessible.

My sister would frequently come over to visit and her phone service was notoriously bad at our house, so we let her onto our wireless network. Not a problem. She lived about an hour away and one night our Sonos started playing random music. It would pop on and off playing the most random off the wall music. It switched from Beyonce to Jazz to Polka. I thought our system had been hacked.

Nope. Turns out my sister hadn’t told us she was in the area and was hanging out in her car around the corner switching the songs on our Sonos. Needless to say, that little prank marked the end of me allowing people directly onto our network. The next day, everyone got kicked off our main network, the password was reset, and our guest network was born.

As you can see, when you let friends and family onto your main network, they have access to every device on your network. If their devices get compromised, so does your network.

This is why I recommend network segmentation, even if you only do the absolute minimum of setting up a guest network. That simple change can increase your security quite a bit if you’ve got other people who may have access to your network.

Now I actually have three networks. I have my main network, my guest network, and then I have a third one that is for my smart devices. If you have a router that supports it and the knowledge of how to set it up, then I highly recommend dropping all of your smart home devices onto their own network. Smart home devices are the most likely to be compromised because they have the worst security of anything on your network. So putting them on their own network ensures that anything that is compromised doesn’t spread to the rest of your network.

I’m going to be up front, doing this isn’t for everyone. I currently only have a handful of devices that I’ve moved over to my smart home network because depending on the device, trying to get them to work properly can either be really easy or they can be a monumental effort.

For example, moving my garage door opener to the smart home network was super easy. It took me maybe 2 minutes. My Sonos is still on my main network because for some reason that I haven’t had time to troubleshoot yet, it doesn’t want to talk to my NAS where my music lives, making it completely useless unless it’s on my main network.

Now in a pinch if you are one of those people who never gives out your wireless access to anyone, you could always setup your smart home devices on your guest network. This is supported by most home routers. It’s not a great solution, but you don’t need to be particular tech savvy to do it and it’s an easy solution that can reduce your exposure if a device is compromised.

2. Accounts and Credentials

Illustration of a key and stacked account cards representing old, forgotten logins

Most people have some level of awareness about accounts and credentials, but don’t follow through on this. Almost everyone has old accounts they forgot existed, accounts that don’t have multi-factor authentication turned on, or accounts with passwords that have been reused over and over again (I’m guilty of this!).

I’m going to be completely up front with you, auditing accounts and credentials is tedious, boring, and time consuming. Don’t expect to go through it in a night. Depending on how long you’ve been online, don’t even expect to go through it in a month. I’ve been auditing my accounts for several years and I still randomly find things that I’m like “Wait, that’s still a thing?”

Going into the exact stack I landed on, including password managers is beyond the scope of this particular article. If you take away nothing else from this entire article, do this: get a password manager and then stop reusing passwords across accounts that actually matter. There are a lot of options out there and my password manager of choice is Bitwarden. No, I’m not endorsed by them, I just like their product.

Now of these accounts that you are auditing, there is one particular type worth calling out. These are accounts you signed up for years ago on things you no longer use. When I was auditing mine I found that I had accounts for random forums that apparently still exist from 2008, an account that I used to pay for the cover charge for a night club on a random trip to Las Vegas in 2011, a random website I used to buy a gift for someone in 2010, and a whole bunch of other random things.

Each one of these accounts is a data breach waiting to happen. Creating these accounts wasn’t wrong, but they are exposing you to security issues that just aren’t worth it. Closing them is boring and tedious. However, when it comes to protecting your privacy and security, this is some of the highest return on investment work you can do.

3. Network Exposure

Illustration of a home router and Wi-Fi signal representing network exposure

I learned how to do networking on Windows 98. I was teaching myself in middle school how to network machines together. So I’ll let you do the math on how long I’ve been doing networking and working with computers in general. So I’m just going to go out on a limb here and guess that you are probably part of the greater part of the population that has never opened up their router’s admin panel, checked what ports are open, or thought about network segmentation.

If you haven’t, don’t worry. I mentioned earlier that the ease of doing this is very much dependent on your router. Trying to extrapolate this data from my friend’s router that he got from his ISP was enough to make me want to throw his router through the window. Because I hand selected my router, it takes about 30 seconds to pull up that same information.

Now I mentioned earlier that I have three different networks running, so my network is probably more involved than most of yours. Part of that is because of my smart devices and partially because I do various tests to stay on top of various technologies in the market that require me to segment out my network. With that said, there is one underlying question that applies no matter what: What is reachable from outside your home and does anything need to be?

If you do nothing else, just log into your router’s admin panel once just to see what is there. I have a checklist of things I go over, but the big ones you want to look for are to see what devices are connected (just in case there are things you don’t recognize, check whether remote administration is turned on (this should be turned off for almost everyone unless there is a specific need), and confirm whether or not the admin password is still the factory default printed on the bottom of the router.

Since most routers have a unique password printed on the bottom of them, unless you are worried about someone coming in and getting into your network by flipping your router over you can probably leave it as the factory default and you’ll be fine. At least if you need someone to come in and take a look at the network you won’t be hunting all over for the password you’ve long forgotten.

My disclaimer here is that best security practices would dictate that you should change your password from the default. Case in point, there are still a lot of people out there with older equipment that I honestly have no idea how it’s still functioning at this point where the password is so generic that you can easily find it on the Internet. Don’t be that person. In fact, you should probably upgrade your router. It would be $40 well spent to make your internet experience significantly better.

4. Data and Backups

Illustration of a home NAS device representing self-hosted data and backups

This section of the audit is all about where does your data actually live and who else has a copy of it. I do a lot of self hosting off my NAS. A NAS if you aren’t familiar with it is Network Attached Storage. Which is basically a fancy way of saying ‘A hard drive on the network’. The NAS was a hard sell to my wife, but few things have given me a greater return on investment when it comes to technology than my NAS. It gets used absolutely every single day.

The reason I self host so many things is because from a security and privacy standpoint, it reduces the amount of companies that have copies of things I’d rather control myself. This is really a bigger topic that deserves its own article, but it needs to be called out as part of the audit process. Where your data lives is more than just a convenience decision, it’s a security decision.

Backups are a big part of the audit. A lot of people do not have any backups at all. The most common argument I hear is “My data is all on the cloud, it’s backed up.”

No. No it is not. My calendar was all done through Google. It’s on the cloud so I shouldn’t lose my data right? Wrong! Twice I had Google completely obliterate my Google Calendar and I lost 10+ months of appointments and calendar events that had been scheduled out and Google could do nothing to help me. This is why I don’t use Google Calendar anymore.

To that end, Cloud storage is only as good as the provider hosting it. This is why when it comes to backups, I ask the following questions:

  1. Is there a copy of this data somewhere besides the device in front of me?
  2. Is that copy current?
  3. Have I ever tried restoring from it?

That third question is the most important one of the three and the one most people skip. I’ve been guilty of that and it bit me hard. A backup that is not tested is attempting to restore from hopes and prayers, it’s not an actual backup.

I learned this the hard way many years ago in my personal life where I had what I thought was a pretty sweet backup setup going, but I didn’t routinely test it to make sure it continued working. Then the drive on my computer failed and I learned the hard way that an update had occurred several months earlier that caused a write failure on my backup. So my most recent backup was 8 months old rather than a week old like I thought. I lost a lot of data.

Learn from my mistake. Backup your critical data.

Debunking Security Myths

Alright, it’s time to debunk some security myths. These are assumptions that I always hear and they will get in the way of actually completing your audit.

I’m not important enough to be targeted.

When it comes to attacks, most of them aren’t targeted. They are automated, opportunistic, and running at a massive scale looking for anyone with a weak spot. Hackers don’t care if you are interesting. They just care if you are reachable and unpatched. Security through obscurity is an absolutely terrible security policy.

Fortunately this means that the fixes are generally pretty simple. Running patches and doing simple security changes will generally protect you from most attacks. You don’t need the most advanced security ever. Security by not being the easiest house on the block to attack is often good enough.

I have nothing to hide, so it doesn’t matter.

Privacy and secrecy are not the same thing. Why do you close your blinds at night? It’s not because you’re doing anything wrong. That same logic applies online. Protecting your data online isn’t an admission of guilt about anything. It’s maintaining a reasonable boundary around your own life.

Security is all or nothing.

This is one of the biggest misconceptions out there and it’s the justification a lot of people use to never take any action to protect their privacy. You don’t need to become a security expert to protect your privacy online.

Simple things like closing a handful of old accounts or turning on multi-factor authentication for your email or your bank can have a huge impact on your privacy and security. Is it going to make you invulnerable to attacks? Absolutely not. What it will do is reduce the amount of realistic risk you are likely to be exposed to online. Once you hit a certain point for enacting data privacy solutions, you start to get diminishing returns. Don’t let perfect be the enemy of good.

How to Prioritize What to Fix

Illustration of three sorting trays representing high, medium, and low priority security fixes

Now there are a few of trains of thought on how to prioritize what to fix. Logically there is the system of ‘fix the most critical things first’ which on the onset makes sense. If it’s the most critical thing, it carries the most risk and should be fixed first right? The problem with this approach is that sometimes the most critical things can take a lot of effort or time to fix. Then what ends up happening is you never actually fix anything because you are focused on this one critical item.

The second train of thought is ‘fix the low hanging fruit first.’ This approach also makes a lot of sense because easy fixes can often account for a the majority of your security issues. However, focusing on the easy fixes can be time consuming if you have a lot of them and they can leave the most critical issues unresolved. Spending a lot of time on easy fixes is a good way to burn yourself out.

Then there is a third train of thought, which is ranking things. This is a bit more abstract so it can be a bit harder to do, but ultimately it’s the best approach of three. Reused passwords directly tied to your identity or finances is going to be a much higher priority than deleting an account on a random forum that you signed up for 15 years ago and forgot about.

While I’m not going to cover the full process I use to rank things in this post, I will give you the rough breakdown. Basically, I sort everything into buckets of High, Medium, and Low.

Anything that touches your identity or finances goes into the ‘High’ category. Anything that is old and low stakes like the old forum account I mentioned earlier goes into the ‘Low’ category. Everything else goes into ‘Medium’. As you are doing this, write it down.

Sticky notes work fine. I personally like simple spreadsheets that I can sort or color code, but I’m an Excel junkie. For most people, physical paper or notebooks is going to be the best bet because it’s a physical reminder that you can have in front of you and cross things off.

What I Found Auditing My Own Life

So for the record, I actually did go through this process and the results were definitely eye opening. It brought to my attention some things that I had completely forgotten about and others that I never would have caught if I hadn’t been using a structured professional approach. As a general rule, hopes and prayers that you are paying enough attention to catch things is not a very good approach to security, though it seems to be the approach most people use. This is exactly why process matters more than good intentions.

At the end of the day, it wasn’t the amount of vulnerabilities that really surprised me. I’ve been on the Internet since the mid 90s. My two primary email accounts are from 1998 and 2004. So I expected a lot of vulnerabilities.

What surprised me was the sheer accumulation of stuff over the last almost 30 years from my digital life. I found a report I had written in middle school, chat logs from AOL Instant Messenger, and passwords for accounts that I honestly couldn’t tell you what they are for.

None of these things were major, they were just years and years of accumulation without any real cleanup. Most of these items were just the result of “I replaced my computer, lets just move everything to the new one’. Then repeat that process every few years. I’d guess a lot of people have a lot messier set of data and accounts floating around their digital world than they might expect, but very rarely does anyone take the time and effort to sit down and look.

How Often to Actually Do This

A full audit isn’t a one and done project. It’s also not something you need to completely obsesses over every month. As I mentioned earlier, I did it for the first time a few months ago and I’ve been pretty happy with the results.

My professional recommendation is to plan on doing a full audit annually. It should be easier every year because after the first year, you’ve hopefully fixed a majority of the issues.

Then you should periodically do lighter reviews, generally on accounts and passwords. For me, the main triggers of those lighter reviews tends to come from me listening to the news. If I hear about a major breach on a service I use or find out about a major vulnerability on a device I use, that is my cue to review that service or device and probably run some updates.

Life changes should also trigger audits as well. I recommend doing light audits any time that there is a new job, a move, a new device, or a new family member who is old enough to have their own accounts. Your exposure will often shift along with your life events, even if your habits haven’t changed.

A Brief List of Useful Tools

Illustration of a shield and toggle switch representing password manager and two-factor authentication tools

If you’re hoping for a product roundup you’ve come to the wrong place. Instead I’m going to give you the general categories of tools I use so you can make the best decision for yourself on what to use. That’s because what is best for me is not necessarily best for you.

The first tool I want to bring up is a Password Manager. In this day and age, there is zero reason to not use one. If you don’t add any other tools into your security arsenal, get a password manager.

I am so adamant that you need one that this is the only tool I will actually make a recommendation on. Go download Bitwarden. It works on pretty much every platform and it’s free for personal use. As I mentioned earlier, I don’t get paid to endorse them, I am just very impressed with their product.

The second tool is multi-factor authentication. Use it whenever it’s offered and it should be turned on for anything that is tied to money, identity, and your primary email address. Why your primary email address? Because that is basically a master key into most of the things you own and do online, so you want to make sure you protect it. Multi-factor authentication has saved me multiple times, even on things I wouldn’t normally think about. That’s how I learned that my password for one of my favorite games had been compromised.

That’s it, just two tools. Everything else is less about dedicated security software and more about deliberate choices about which services I trust with my data. Also, it’s increasingly becoming about choices of what services can I host myself rather than farming out my privacy and security to a random company who can do whatever they want with my data.

Where Does this Fit In with the Rest of Digital Minimalism?

Now you’ll probably note that I didn’t lead off this site with a whole page on a personal security audit. In my other posts I covered a lot of ground on what digital minimalism is and the broader efforts that are part of digital minimalism.

That’s because none of this page is designed to replace that digital minimalism work, it’s designed to complement it. Decluttering your apps and being intentional about screen time is really good for your focus and amazing for your mental health.

Running a personal security audit is good for making sure that the smaller and more intentional digital life you are building is also safer and more private.

When I look at all the ways that corporations are harvesting our data and personal information, that makes me want to become more of a digital minimalist. It’s great that so many of you are interested in minimizing your devices and going with minimalist setups. I genuinely applaud. But, a minimalist setup with unpatched devices, reused passwords, and easily compromised security isn’t more secure just because it’s smaller. To use a the analogy of a door, putting a lock on a door doesn’t make it more secure if you never lock the door. Your devices are the same way.

The personal security audit is less about what you are using and more about how exposed you are.

Where to Start

If this is your first time thinking about your digital life in this way, then I’d start with making a list of all of your most used accounts and passwords and get them into a password manager. This is going to give you the highest return on investment when it comes to your privacy and security. Once you’ve done that, go through them and see which of your most critical accounts are reusing the same passwords and updates them to be unique.

Next, start writing down every account you can remember having. Start with anything that is tied to your money, your identity, or your primary email and work your way down from there. Don’t fix any of these yet, you should have fixed your critical ones already and you don’t want to burn yourself out. Just listing things out will give you a really good view of your actual exposure.

In the coming weeks I’ll be publishing several more articles around the processes that I used, adapted to a home network. You can work through them in whatever order works best for you, but this list above should be enough to get you started. Good luck and happy auditing!