The Safety Check-In I Run on My Own Accounts Every Few Months

Sep 01, 2026By Jay Kells
Jay Kells

The Safety Check-In I Run on My Own Accounts Every Few Months

I don't believe in a one-time cybersecurity setup that you configure once and then forget about forever. Threats change, apps you signed up for years ago quietly keep access you forgot you gave them, and breach databases grow every week whether you're paying attention or not. So every few months I sit down and run the same short check-in on my own accounts, not because I think something's wrong, but because catching a small problem early is a lot less painful than discovering it after it's already caused damage. Here's exactly what that check-in looks like.

Checking Have I Been Pwned and Other Breach Trackers

The first thing I do is run my main email addresses through Have I Been Pwned, a free service that tracks which known data breaches have exposed which email addresses. It takes about thirty seconds per address and tells me immediately if any account tied to that email showed up in a breach I might not have heard about. Most of the time nothing new comes up, and that's fine, the point isn't to expect bad news every time, it's to make sure I'd actually know if there was any. When something does show up, I immediately change the password on whichever account was breached, and I check whether I reused that password anywhere else, which is exactly the kind of thing a periodic check catches that you'd otherwise miss for months. I'd rather spend thirty seconds finding out on my own schedule than find out because something's already gone wrong.

Reviewing Which Apps Still Have Access to My Accounts

Every time you click "Sign in with Google" or "Continue with Facebook" on some app or website, you're granting that third party ongoing access to parts of your account, and most people never look at that list again after the day they granted it. I go into my Google, Microsoft, and social media account settings every few months and look specifically at the connected apps and third-party access lists. It's genuinely surprising how many things accumulate there, a fitness app from three years ago, a one-time event registration tool, a browser extension I installed for a single project and never uninstalled. I revoke access for anything I don't actively recognise or use, because every one of those connections is a potential way into my account that has nothing to do with how strong my actual password is. This is one of the parts of digital housekeeping that genuinely nobody thinks to do until they're specifically prompted to, which is exactly why I've built it into a recurring check rather than relying on remembering.

Making Sure My Recovery Details Are Actually Up to Date

Recovery phone numbers and backup email addresses are the thing that saves you when you're locked out of an account, and they're also the thing people update least often, because you only think about them in the moment you desperately need them to already be correct. I check that the phone number and backup email on my most important accounts, email, banking, password manager, are still ones I actually have access to, not an old number tied to a contract I cancelled two years ago or an email address I stopped checking. I've heard from more than one person who got locked out of an account permanently because their recovery phone number belonged to someone else by the time they needed it, since old numbers get recycled and reassigned. This is a boring five-minute check that has an outsized effect on how bad a worst-case scenario actually turns out to be.

World map with colored pins marking multiple curated destinations across continents on a marble surface with plant shadows.

Looking at What's Logged Into My Accounts From Where

Most major platforms, email providers, banking apps, social media, have a section showing active sessions or logged-in devices, and I make a point of actually looking at it during my check-in rather than assuming it would look normal if I glanced at it. What I'm looking for is anything I don't recognise, a login location I've never been to, a device type I don't own, a session that's been active for far longer than makes sense. Finding nothing unusual is the expected and hoped-for outcome, but the value of the check is that if something IS there, I catch it during a routine look rather than by accident weeks later. I sign out of anything I don't recognise immediately and change the password on that account as a precaution, treating an unfamiliar session as a real signal rather than something to shrug off.

Deciding What's Worth Fixing Now vs Later

Not everything this check-in surfaces needs to be fixed immediately, and I've learned to actually triage rather than either ignoring everything or panicking about all of it equally. An old app with account access I don't recognise gets revoked straight away, it costs nothing to remove and there's no reason to leave it. A password that showed up in a breach gets changed immediately, no exceptions. But something like updating my recovery phone number on a low-priority account I barely use might genuinely wait until my next check-in a few months later, because not every finding carries the same urgency, and treating minor housekeeping with the same alarm as an active breach just trains you to tune the whole process out over time. The goal of this check-in isn't perfection, it's making sure nothing sits unnoticed indefinitely.

None of this takes more than about twenty minutes every few months, and it's genuinely one of the habits I'd recommend most, precisely because it catches the kind of slow, quiet problems that never announce themselves, an old app with access you forgot about, a breached password you never changed, a recovery number that's gone stale. I've written separately about the order I'd actually work through fixing your wider digital security in if you're starting from scratch, which pairs well with this as an ongoing maintenance habit once the initial setup is done. If you want a reliable way to make sure your passwords are also getting checked against new breaches automatically rather than only when you remember to look, NordPass has built-in breach monitoring that does a version of this first step continuously in the background, and my free Safety Toolkit covers the rest of what I'd recommend if you want to build the whole habit properly. The NCSC publishes its own guidance on keeping accounts secure that's worth reading alongside whatever check-in routine you settle on.