Most people's password collection is an archaeological site. The bottom layer: a teenage password still guarding a forum you forgot. The middle strata: the one "good" password of your twenties, reused across forty sites. The surface: whatever your browser suggested last week. Nobody designed this; it accumulated.
An audit is how you excavate - And it's smaller than it sounds. One afternoon, four phases, and by dinner you know exactly what you own, what's compromised and what's fixed. Grab a drink, put on music, and block out roughly four hours. Here's the schedule.
Hour 1: build the inventory
You can't secure accounts you've forgotten exist, so the audit starts as a census. Pull from every hoard:
- Your password manager or browser vaults - Chrome, Safari, Edge and Firefox each keep saved-login lists; export or just open them side by side.
- Your email archive - Search for "welcome," "verify your email" and "your account" to resurrect signups you've long forgotten. This is reliably the humbling step: NordPass research puts the average person's login count around 168, and most audits surface accounts their owner would have sworn they never made.
- SSO trails - The "apps with access" pages of your Google, Apple and Facebook accounts list every service you joined with a social login.
- Your phone - Installed apps you haven't opened this year all have accounts behind them.
Tag each account into three tiers as you go. Tier 1: email, banking, anything with money or the power to reset other accounts. Tier 2: social, shopping with saved cards, cloud storage, work. Tier 3: everything else. This tiering is the whole strategy - The afternoon's remaining hours are spent top-down, so even if you stall, the damage-heavy accounts got fixed first.
Hour 2: find out what's burned
Now interrogate the list with three questions.
Which passwords have leaked? Enter your email addresses at haveibeenpwned.com - Troy Hunt's breach index spans hundreds of sites and billions of records - And note every breach that included passwords. Any password you used on a breached service is in circulation and gets replayed against other sites automatically; that replay economy is documented in our explainer on credential stuffing.
Which are reused? Password managers and browsers now do this mechanically: Google's Password Checkup, Safari's security recommendations and every major manager's audit dashboard flag duplicate passwords across sites, and most cross-check known-breach corpora too. Every duplicate is a fuse connecting accounts that shouldn't share a fate.
Which are weak? The same dashboards flag the short and formulaic. For borderline cases, test the pattern in our password strength checker - And be honest about recipes: if yours is word-plus-year-plus-exclamation, it fails regardless of length, for reasons cataloged in what makes a password weak.
Audit maxim: a password is guilty until proven unique. If you can't say for certain it exists nowhere else, schedule it for rotation - Memory is exactly the tool that got the collection into this state.
Hour 3: rotate by tier, not by alphabet
Fix in priority order, and let tools do the typing.
Tier 1 first, all of them today. Email before everything - It's the reset path for the rest. New passwords should be manager-generated random strings of 16+ characters; for the two or three you must type from memory (master password, computer login), build a five-word phrase with our passphrase generator instead. While you're inside each account, hit "sign out of all other sessions" - Rotation doesn't evict an intruder whose session cookie still works, a lesson the infostealer economy teaches expensively.
Tier 2 this week. Ten minutes a day finishes them; perfection this afternoon is not required.
Tier 3 gets triaged, not rotated. Which brings us to the most satisfying part of any audit:
| Audit finding | Action | When |
|---|---|---|
| Breached or reused Tier 1 password | Rotate now + end other sessions | Today |
| Breached or reused Tier 2 password | Rotate | This week |
| Weak but unique Tier 3 password | Rotate lazily (next login) | Rolling |
| Account unused for 1+ years | Delete the account | This month |
| Unrecognized "app with access" | Revoke access | Today |
Delete the dead. Every abandoned account is stored personal data plus (usually) a reused old password, offering you nothing in return. Deleting it removes you from that service's future breaches permanently - The only security move that works retroactively on companies' mistakes. Where deletion is buried or impossible, overwrite the password with random junk and remove saved cards and addresses.
Hour 4: raise the floor with 2FA
Rotation fixes the past; the last hour hardens the future. Go down your Tier 1 and Tier 2 lists enabling two-factor authentication, preferring authenticator apps over SMS - The codes are derived on-device from a shared secret and the clock, as our TOTP tool demonstrates live, leaving nothing for a SIM-swapper to intercept. Microsoft's long-cited figure is that MFA blocks over 99.9% of automated account-takeover attempts; no other hour of the afternoon buys as much.
Two closing chores. Download and file the backup codes each 2FA setup offers - Future-you, holding a dead phone, will be grateful. And check each Tier 1 account's recovery settings: an old phone number or defunct email in a recovery slot is a hijacking route you're leaving propped open.
FAQ
How long does a personal password audit really take?
Budget an afternoon - About four hours - For a first audit of a typical 100–200 account collection, with Tier 2 rotation spilling into ten-minute sessions across the following week. Subsequent annual audits run much shorter because the inventory, the manager and 2FA are already in place. The commonly skipped step that costs the most later is the email-archive search that finds forgotten accounts.
Do I need special software to audit my passwords?
No - The tools are already in your pockets: Chrome and Safari ship password checkups, every major password manager has an audit or "watchtower" dashboard, and haveibeenpwned.com covers breach exposure free. What software can't supply is the tiering judgment (which accounts could hurt you) and the decision to delete dead accounts. The afternoon is mostly triage, not tooling.
Should I change every password I own during the audit?
No, and trying is the classic way audits get abandoned midway. Rotate what's breached, reused or weak - Starting from email and money - And leave strong, unique passwords alone regardless of age, in line with NIST SP 800-63B's move away from calendar-based rotation. A strong unique password on a Tier 3 forum is simply not a problem worth your afternoon.
What's the single most important finding an audit can surface?
A reused password connecting your email account to anything else, because email is the recovery master key for the rest of your accounts. Second place: an important account whose password appeared in a breach, since those credentials are actively replayed by bots. Both are invisible without an audit and fixable in minutes once seen.
How often should I repeat the audit?
Annually is the sweet spot for a full pass, with event-driven spot checks in between: after any breach notification, after malware on a device, after a phishing close call, and when someone with shared access leaves your life. If your manager's audit dashboard stays green between annual passes, you're maintaining rather than excavating - Which is the goal.