Table of Contents
The Family Cybersecurity Audit You Can Do in One Weekend
A practical, step-by-step family cybersecurity audit: passwords, 2FA, app permissions, router settings, and minor credit freeze — done in one weekend.
Nobody audits their home cybersecurity until after something goes wrong. Then they find out the same password was used on seven accounts, their router is still running firmware from 2019, and their 11-year-old’s email address has been in four separate data breaches. The Identity Theft Resource Center reported 3,205 data compromises in 2023 — a 72% increase from 2022. The chances that someone in your household has exposed credentials sitting somewhere on the dark web right now are, statistically, quite high.
This isn’t about becoming a security expert. This is about one structured weekend that covers the fundamentals — the things that matter most, done in a logical order — so you’re not starting from zero when something actually goes wrong.
Key Takeaways
- HaveIBeenPwned.com is free and takes two minutes per email address to show all known data breaches involving that address
- Password managers (Bitwarden, 1Password, Apple Keychain) eliminate the root cause of most family account compromises
- Two-factor authentication on email, banking, and school accounts is the single highest-ROI security action any family can take
- Router firmware is almost never updated automatically and often runs vulnerabilities that are years old
- Every minor child is eligible for a free credit freeze at all three bureaus — and setting one takes about 20 minutes per child
Saturday Morning: Account Inventory and Breach Check
Start here, before anything else: you can’t protect accounts you don’t know exist.
Step 1: Build the account list. Sit down with your partner and your kids (separately if that’s more appropriate). Make a list of every account that matters: email addresses (all of them), banking and investment accounts, school portals, social media, streaming services, gaming accounts, and any accounts tied to your home address or Social Security Number. Don’t skip kids’ accounts — their Roblox, Minecraft, Discord, and school Google accounts all count.
A spreadsheet works fine. You’re not putting passwords in it — just account names, the email address used to sign up, and whether 2FA is active. This list will be your audit baseline.
Step 2: Run every email through HaveIBeenPwned. Go to haveibeenpwned.com (free, run by security researcher Troy Hunt, cited by the FBI’s InfraGard program). Enter each email address on your list. The site returns a list of every data breach in its database that included that email address. Common findings: LinkedIn 2021, Adobe 2013, Canva 2019, various game breaches.
What to do when you find a breach: change the password on any account that used the same password as the breached service. This is why password reuse is the biggest vulnerability for most families.
Step 3: Set up a password manager. This is the single most protective action the average family can take. A password manager generates long, unique, random passwords for every account and remembers them. You only need to remember one master password.
Options:
- Bitwarden: Free, open-source, works across all devices and browsers. Strong choice for families who want zero cost and maximum transparency.
- 1Password: $3/month for families, includes a travel mode and excellent sharing features.
- Apple Passwords (built into iOS 18+ and macOS Sequoia): Free, excellent if your family is all-Apple. Less convenient for cross-platform households.
Import your existing passwords, let the manager flag duplicates and weak ones, and spend the rest of the morning changing the worst offenders — prioritize: email accounts first, then banking, then school portals.
Saturday Afternoon: Two-Factor Authentication Sweep
Two-factor authentication (2FA) means that even if a scammer has your password, they can’t log in without a second confirmation — usually a code from an app or a text message.
For a deep dive on setting up 2FA across family accounts, see our complete guide to two-factor authentication for families. The short version for the audit:
Priority 1 accounts — set up 2FA now:
- All email accounts (a compromised email is a master key to everything else)
- Banking and credit cards
- School district parent portals
- Apple ID / Google Account
- Any account tied to your credit card
Priority 2 accounts — set up 2FA this weekend:
- Social media (Instagram, TikTok, Snapchat, YouTube)
- Gaming accounts (Steam, PlayStation, Xbox, Nintendo) — see our guide to protecting gaming accounts
- Shopping accounts with saved payment info (Amazon, Target, etc.)
- Discord — see our Discord safety guide for parents
Authenticator app vs. SMS: SMS codes (texts) are better than nothing but can be intercepted through SIM-swapping attacks. An authenticator app (Google Authenticator, Authy, Apple’s built-in authenticator) generates codes locally and cannot be intercepted remotely. Where the option exists, use an app over SMS.
Save your backup codes. When you enable 2FA on any account, you’ll be given a set of backup codes for emergencies. Print these and store them with your important documents — not in a text file on your computer.
| Account Type | 2FA Priority | Recommended Method | Risk If Skipped |
|---|---|---|---|
| Email (primary) | Critical | Authenticator app | Complete account takeover; all other resets compromised |
| Banking | Critical | App or SMS (if app unavailable) | Direct financial loss |
| School portal | High | SMS or app | Grade manipulation, contact info exposure |
| Social media | High | Authenticator app | Identity theft, reputation damage |
| Gaming accounts | Medium | Authenticator app | Virtual currency theft, account theft |
| Streaming services | Low | SMS | Unauthorized charges |
Sunday Morning: App Permissions Audit
Over time, every phone and tablet accumulates apps that have permissions they don’t need and accounts that are no longer used. This half of the audit addresses that.
On every family iOS device: Go to Settings > Privacy & Security. Review each category: Location, Contacts, Camera, Microphone, Photos. For each app listed, ask: does this app need this permission to do its job? A flashlight app with microphone access doesn’t need that. A game with contacts access doesn’t need that.
Specific red flags: any app with “Always On” location access that isn’t a navigation or family-tracking app. Any app that has Contacts access that you didn’t specifically grant for a messaging purpose. Any app with Microphone access that isn’t a voice app.
On every family Android device: Settings > Apps > [App Name] > Permissions. Android 12+ also has a Privacy Dashboard (Settings > Privacy > Privacy Dashboard) that shows a 24-hour timeline of which apps accessed which sensors. This is a powerful audit tool — review it for each device.
On kids’ tablets and phones: Use Apple Screen Time or Google Family Link to review installed apps and permissions centrally. Delete any app the child can’t explain a current use for.
Review connected apps on accounts: Go to your Google account (myaccount.google.com > Security > Third-party apps with account access). Do the same for Apple (appleid.apple.com > Sign In with Apple). Revoke access for any app you don’t recognize or no longer use. These connected apps can read data from your account without your password — an old connected app from a service that was later breached becomes a back door.
Sunday Afternoon: Router Security and Minor Credit Freeze
Router Security Check:
Your home router is the gateway for every internet-connected device in your house. Most routers are never updated after the initial install.
- Log into your router. Usually by typing 192.168.1.1 or 192.168.0.1 in a browser. Check your router’s label or manual for the default address.
- Update the firmware. Look for a “Firmware Update” or “Software Update” section. If an update is available, install it. Some routers from the last two years update automatically — check whether yours does.
- Change the admin password. The default admin username/password (often “admin/admin” or “admin/password”) for most router models is publicly documented. Change it.
- Change your Wi-Fi network name. Default names that include the router model (e.g., “NETGEAR_37A4”) reveal your hardware to anyone scanning networks. Use a name that doesn’t identify you.
- Disable WPS. Wi-Fi Protected Setup (WPS) was designed for easy device connection but has known security vulnerabilities. Disable it in your router settings — you don’t need it.
- Enable WPA3 encryption. If your router supports it, switch to WPA3 in the wireless security settings. If it only supports WPA2, that’s acceptable but plan to upgrade your router if it’s more than 5 years old.
- Create a guest network for kids’ devices. Many routers let you run a guest network. Putting kids’ devices on a separate network segment means a compromised kids’ device can’t see or attack the devices on your main network.
CISA’s home network security guidelines (available at cisa.gov/secure-our-world) recommend router firmware updates as a top-three home security action.
Minor Credit Freeze:
This is the most underutilized protection available to families. Every child is eligible for a credit freeze at all three major credit bureaus — and it’s free. A frozen credit file cannot have new credit lines opened against it, which means identity thieves who obtain your child’s Social Security Number cannot open fraudulent credit accounts.
Children don’t have active credit files yet, which is exactly why their SSNs are valuable to thieves — the fraud can go undetected for years until the child tries to open their first account or apply for college aid.
How to freeze a minor’s credit:
Equifax: equifax.com/personal/credit-report-services/child-identity-theft — mail or online with identity documents Experian: experian.com/help/child-fraud-victim — requires mailed documentation TransUnion: transunion.com/credit-freeze/child-identity-protection — online submission available
You’ll need a copy of the child’s birth certificate, your ID, and proof of address. Process each bureau separately. The freeze stays in place until you lift it — before your child applies for a student loan, first credit card, or apartment. The FTC recommends this step specifically for families whose child’s SSN may have been exposed in a data breach.
Bonus: The Things You’ll Probably Skip (and Shouldn’t)
Old accounts that still exist. Go to justdeleteme.xyz to find deletion instructions for hundreds of services. Old accounts with old email addresses are sitting targets.
Email forwarding rules. Hackers who briefly access an email account often set up forwarding rules before they’re locked out, so they continue to receive copies of messages. Check your email settings > Filters and Forwarding Rules and make sure nothing is there that you didn’t create.
Strong password review for kids’ accounts. Run your kids’ current passwords (the ones you know) through the “Check Passwords” feature in your password manager or Apple Passwords. If any are weak or reused, change them now. See our age-by-age guide to teaching kids strong passwords.
What to Watch For Over the Next 3 Months
Month 1: Enable breach notifications. HaveIBeenPwned has a free notification service — subscribe your email addresses so you’re alerted to new breaches automatically. Google accounts with “Enhanced Safe Browsing” will also alert you to password compromise in real time.
Month 2: Check whether your kids’ social media accounts are actually private. Don’t ask them — sit with them and look at the settings together. Platforms change default privacy settings regularly after policy updates. What was private six months ago may not be now.
Month 3: Do a quick pass on the app permissions audit again. New apps get installed constantly. Ten minutes per device per quarter keeps permissions from creeping back up.
Watch for red flags: Any email notification about a new sign-in from an unrecognized location. An account that seems logged out when your kid didn’t log out. Email from a bank or school about account changes you didn’t make. Unfamiliar apps appearing on devices.
Frequently Asked Questions
How long does this whole weekend audit actually take?
Realistic time estimate: 4–5 hours total across the weekend. The longest part is the password manager setup and initial password changes — plan 2 hours for that. The router and credit freeze steps together run about 90 minutes. App permissions are 15–20 minutes per device.
Do I have to do this with my kids present?
For the account inventory and the conversation about what monitoring tools are on school devices, yes — do it together. For router firmware and credit freeze, that’s parent-only work. The goal is for kids to understand what’s being protected and why, not to do the technical work themselves.
What if I find my email in a breach from 2018? Is that still dangerous?
Yes. Breached password lists from any year circulate permanently and are used in “credential stuffing” attacks — automated tools that try old passwords against current accounts. Change any password that matches a breached one, regardless of how old the breach is.
Should I use my bank’s built-in password tools or a third-party manager?
Third-party password managers (Bitwarden, 1Password) are generally more secure and more flexible than bank-specific tools because they work across all your accounts, not just one institution’s. Banks’ built-in tools are better than nothing but create fragmentation.
How do I unfreeze a minor’s credit when they actually need it?
Contact each bureau with the PIN you created during the freeze setup — that’s why it’s critical to save those PINs. Unfreezes can typically be done online within minutes. The process is designed to be quick when you legitimately need to open new credit.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- Identity Theft Resource Center. (2024). “2023 Annual Data Breach Report.” ITRC. https://www.idtheftcenter.org/post/2023-annual-data-breach-report/
- Federal Trade Commission. (2024). “Child Identity Theft.” Consumer Information. https://consumer.ftc.gov/articles/child-identity-theft
- CISA. (2025). “Secure Our World: Home Network Security.” Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/secure-our-world
- Hunt, T. (2024). “Have I Been Pwned: About.” haveibeenpwned.com. https://haveibeenpwned.com/About
- National Institute of Standards and Technology. (2024). “Digital Identity Guidelines.” NIST SP 800-63. https://pages.nist.gov/800-63-4/
- FBI InfraGard. (2023). “Cybersecurity Best Practices for Home Networks.” FBI. https://www.fbi.gov/investigate/cyber