PasswordCrunch.com
Password Security

How to Audit Your Passwords in Under an Hour

PasswordCrunch.com  ·  6 min read

Most people's password hygiene decays slowly over years — a reused password here, a weak one there, all invisible until something goes wrong. A proper audit surfaces the problems in one sitting. Here's how to do it in under an hour.

Step 1: Get everything in one place (10 minutes)

If you're not already using a password manager, this is the moment to start. Most browsers have a built-in password manager that can export your saved logins as a starting point, though a dedicated manager is worth switching to for the long term. The goal here is simply visibility — you can't fix what you can't see.

Step 2: Flag the reused passwords (10 minutes)

This is usually the single biggest risk most people are carrying. Most password managers have a built-in "reused passwords" report that does this automatically. If yours doesn't, sort your list and manually scan for duplicates. Reused passwords should be treated as top priority, regardless of how strong the password itself looks — strength doesn't matter if one breach exposes it everywhere else it's used.

Step 3: Flag the weak and old passwords (10 minutes)

Look for anything short, anything using an obvious pattern (see our piece on the most common passwords), and anything you know hasn't been changed in years, particularly on accounts created before you were using a password manager consistently.

Step 4: Check for breach exposure (10 minutes)

Run your email address, and any old reused passwords you're unsure about, through a breach-checking service such as Have I Been Pwned. This tells you which of your accounts have already appeared in known breach data, so you know exactly where to prioritise.

Step 5: Fix in priority order (remaining time)

  1. Anything flagged in a known breach
  2. Anything reused across multiple accounts
  3. Your email account and password manager master password, regardless of whether they were flagged — these guard everything else
  4. Banking and financial accounts
  5. Everything else, as time allows

For each one: generate a new, unique password, save it, and enable two-factor authentication if it isn't already on.

Make it a habit, not a one-off

A full audit like this is worth repeating roughly once a year, or immediately after any breach notification you receive. Between audits, the habit that keeps you safe by default is simple: never reuse a password, and let a generator create every new one.

Put this into practice right now.

Generate a strong password →