Cybersecurity Privacy How-To Checklist

🔐 10-Minute Account Security Checkup

📅 August 12, 2026  |  ⏱ 10 min read (and do!)

Laptop with lock and security icons

A few simple steps can block 99% of hackers — and it only takes 10 minutes.

Let's be honest: most of us have dozens of online accounts — email, social media, banking, shopping, streaming, work apps. And most of us use the same password for way too many of them.

That's a problem. Because hackers don't target you personally — they target weak points. And if one account gets compromised, they can usually get into several others.

The good news? You don't need to be a tech expert to secure your accounts. In just 10 minutes, you can take five simple steps that will block 99% of common attacks.

Grab your phone and laptop — let's get started.


Step 1: Check If Your Accounts Have Been Breached

Person checking data breach alert on laptop
⏱ 2 minutes

Why this matters: If your email and password were exposed in a data breach (and billions have been), hackers already have your credentials. They just haven't used them yet.

What to do:

  1. Go to haveibeenpwned.com.
  2. Enter your email address and click "pwned?"
  3. If you see a red screen saying "Oh no — pwned!", that means your email was in a data breach.
  4. Don't panic. The next steps will fix this.

💡 Pro tip: Check all the email addresses you use (personal, work, old accounts). You might be surprised.


Step 2: Update Your Passwords — The Right Way

Three random words concept for strong passwords
⏱ 4 minutes

Why this matters: "Password123" and "iloveyou" are still among the most common passwords. Hackers crack them in seconds.

What to do:

For every account that was in a breach (and ideally for all your important accounts), change the password using the "3 Random Words" method:

  • Pick three unrelated words — e.g., BlueCupcakeTiger
  • Add a number and a symbol — e.g., BlueCupcakeTiger!7
  • That's it. Long, easy to remember, and very hard to crack.

⚠️ Critical: Never reuse the same password across multiple accounts. If one gets hacked, all of them get hacked.

💡 Pro tip: Use a password manager like Bitwarden, 1Password, or Dashlane. They generate and store strong, unique passwords for every account — so you only need to remember one master password.


Step 3: Turn On 2-Factor Authentication (2FA)

Smartphone receiving 2FA verification code
⏱ 2 minutes

Why this matters: A password alone is not enough. Even if a hacker gets your password, 2FA (Two-Factor Authentication) stops them because they'd also need a one-time code sent to your phone.

What to do:

  1. Go to the security settings of your most important accounts: Google, Apple, Facebook, Instagram, X (Twitter), banking apps, and work accounts.
  2. Look for "Two-Factor Authentication" or "2FA" or "Multi-Factor Authentication".
  3. Turn it on. Choose Authenticator App (like Google Authenticator or Microsoft Authenticator) instead of SMS if possible — it's more secure.

⚠️ Important: When you set up 2FA, you'll get backup codes. Save them somewhere safe (print them or store them in a secure place). If you lose your phone, these codes are the only way to get back into your account.


Step 4: Check Active Sessions — Log Out Unknown Devices

Multiple devices connected to a network
⏱ 1 minute

Why this matters: If you've ever logged into your email on a friend's phone or a public computer, you might still be logged in — and someone else could access your account.

What to do:

  1. Go to the security settings of your Google Account, Apple ID, Facebook, and other major accounts.
  2. Look for "Devices", "Sessions", or "Where you're logged in".
  3. Review the list. If you see any device or location you don't recognize, click "Sign Out" immediately.

💡 Pro tip: Do this regularly — at least once every few months. It's a quick way to spot unauthorized access early.


Step 5: Remove Unused Third-Party App Access

Connected apps and permissions on a smartphone
⏱ 1 minute

Why this matters: Over the years, you've probably given random apps access to your Google, Facebook, or Apple account — old games, quiz apps, trial services. Some of these apps have weak security or have been abandoned. They're a potential backdoor into your account.

What to do:

  1. Go to your Google AccountSecurityThird-party apps with account access.
  2. Go to FacebookSettingsApps and Websites.
  3. Go to Apple IDSign in with AppleApps Using Apple ID.
  4. Remove any app you don't recognize or don't use anymore.

💡 Pro tip: If you're not sure whether an app is safe, remove it. You can always add it back later if you need it.


✅ Your 10-Minute Security Checklist

Checklist on a clipboard

📋 Quick Reference

Go through this list one by one. Check off each item as you complete it.

    ☐ Step 1: Check haveibeenpwned.com for data breaches

    ☐ Step 2: Update passwords using the 3 Random Words method

    ☐ Step 3: Turn on 2FA (Two-Factor Authentication) for all important accounts

    ☐ Step 4: Check active sessions and log out unknown devices

    ☐ Step 5: Remove unused third-party app access

    ☐ Bonus: Consider using a password manager (Bitwarden, 1Password, Dashlane)

    ☐ Bonus: Save your 2FA backup codes in a safe place

✅ That's it! You're now more secure than 90% of internet users.


🌟 Bonus Tips for Extra Security

Lock icon with security best practices
  • Use a unique email for important accounts: Consider having one email address just for banking and government services.
  • Beware of phishing: Never click on links in suspicious emails. Always type the URL directly into your browser.
  • Keep your software updated: Those "annoying" update notifications often contain critical security patches.
  • Use a VPN on public Wi-Fi: Public networks are notoriously insecure. A VPN encrypts your data.
  • Freeze your credit: In some countries, you can freeze your credit report to prevent identity theft.

Final Thought: Security is a Habit, Not a One-Time Task

Person locking smartphone with secure digital shield

You've just done more for your digital security than most people do in a lifetime. That's something to be proud of.

But here's the secret: security isn't a one-time task. It's a habit.

Set a reminder to run through this checklist every 3–6 months. New apps, new accounts, and new breaches happen all the time. A quick check-in keeps you protected.

And remember: hackers don't target you personally. They target easy targets. By taking these five simple steps, you've made yourself a much harder target — and most hackers will simply move on to someone else.

Stay safe out there. 👊

🛡️ Did You Complete the Checkup?

How did it go? Were you surprised by any breaches or unknown devices?

Share your experience in the comments — and feel free to ask questions if you got stuck!

👇 Scroll down and leave a reply!


📬 Found this useful? Share it with a friend or family member who needs to secure their accounts.
Computer Educator — Making computer security simple for everyone.