Costs

Part of Account security: requirements and practical steps for 2027

Account security guide: what matters in 2027

A social account security audit run in the intruder's order: sessions, recovery routes, connected apps, and the settings that would be changed first.

A privacy audit asks who can see you. A security audit asks a different question: if someone else got into this account tonight, what would they be able to do, and how long could they stay?

Those are separate jobs and they touch different screens. This one is organized the way an intruder's work is organized, because the settings that matter most are the ones that would be changed first. The sign-in baseline it assumes throughout is CISA's guidance on multi-factor authentication, and the account recovery route, if the audit finds you are already too late, is the FTC's guidance on a hacked social media account.

What to take away

  • Getting in and staying in are two different problems. Most accounts are configured against the first and not at all against the second.
  • The account's blast radius is the real risk: what else it can reset, publish, or pay for.
  • An audit is finished when you know what normal looks like, so an alert means something.

Work in reverse order

Start where the damage would be, not where the login is.

1. Blast radius. Before touching a setting, write down what this account controls. Which other services use it to sign in. What it can publish, and to how many people. Whether it holds a payment method, a payout destination, or an ad account. Whether it is the recovery contact for anything else. A personal account with an attached business page and a saved card is a different object from a personal account with neither, and it deserves different effort.

2. Persistence. The things that survive a password change: active sessions, remembered devices, connected apps and integrations, delegated users, page and business roles, and any scheduled or automated posting. Every item here is access that does not go through your login. Remove what you do not currently use. Reauthorising something later costs a minute.

3. Recovery. The recovery email address, the recovery phone number, any trusted contacts, and the backup codes. Confirm you still control each one. An old address or a number you gave up is a live route into the account held by somebody else, and it is the first thing an intruder replaces.

4. Authentication. Whether the password is used anywhere else, what kind of second factor is on, and whether a stronger kind is available. A code you can read and type can be typed somewhere else, whatever sent it. A passkey or a hardware key cannot be used on a copied page, which is the property that matters. The comparison of factor types is in account security.

5. Ownership. The email address and phone number on file, and what you could show a support agent to prove the account is yours: when it was created, a linked payment record, a domain you control, an original device. Support decisions turn on this and nobody thinks about it until the account is gone.

6. Alerting. Login alerts, new-device alerts, email-change alerts, and whether they reach an address you actually read. An alert that lands in an inbox you check twice a year is not an alert.

The tests that produce evidence

Ticking a box is not an audit. Each of these produces a result you can act on.

  • Sign yourself out of everything, then sign back in. You learn how long it takes, which devices you actually use, and whether your backup codes work.
  • Trigger a password reset deliberately on an account that is not critical, and watch where it goes. That is your recovery route, in practice rather than in theory.
  • Read the connected apps list out loud. Anything you cannot explain in one sentence goes.
  • Check the alert address by causing one. A sign-in from a browser you do not normally use should produce a message. If it does not, alerting is off or misdirected.
  • Look at the account from a signed-out window. What is visible is what a stranger uses to make a convincing approach, and that is the overlap with the social media privacy audit.

Shared accounts, roles, and the people problem

Most business social accounts fail on people rather than on technology.

A shared password known by five people is known by everyone those five have told, and it cannot be revoked for one person. Where the platform supports individual roles, use them, and give each person the lowest role that lets them do their job. Where it does not, that account needs its own password nobody reuses and a documented change on the day anybody leaves.

Two more items that get missed. Agencies and contractors keep access long after a project ends, because nobody owns the offboarding. And a personal account with an admin role on a business page means the business page inherits the security of that person's private life.

What you are looking for that is not a setting

While you are in there, look for signs of an existing problem rather than only for weak configuration.

Forwarding rules and filters on the linked email account. Alternate email addresses added to the account. A changed display name or handle. Messages in the sent folder you did not send. Posts deleted that you did not delete. An unfamiliar device that appears occasionally rather than constantly, which is what a careful intruder looks like.

If any of those turn up, stop auditing and start responding: change the password from a device you trust, sign out all sessions, then recheck recovery settings, in that order. Before you clean anything up, note what you found and when, because that record is what makes the rest of scam reporting and recovery possible.

Finishing, and the state to leave behind

A finished audit leaves four things true. Every account has a password used nowhere else. The second factor is the strongest kind the service offers, on the accounts that matter. Backup codes exist somewhere physical. And nothing holds access that you cannot name.

Then write down what normal is: the devices you use, the apps that are connected, the locations you sign in from. That note is what turns a future alert from a shrug into a decision.

Repeat after any redesign, any device change, any staff change, and immediately after any incident anywhere near you. The account most likely to be attacked next is one whose owner has just been in the news, been in a dispute, or received a first approach they ignored. There is more on why public detail feeds targeting in impersonation scams.

Common questions

How long should this take?

About an hour for the first account, much less afterwards. Do the account that could reset the most other things first, which for most people is the email address behind everything.

Is two-factor authentication enough on its own?

It closes the front door and leaves the side ones. Recovery routes, existing sessions, and connected apps all work without it, which is why they occupy most of this page.

Should I remove old connected apps even if they seem harmless?

Yes. The risk is not that the app is malicious, it is that the company may no longer exist and its access still does. Anything you are not currently using goes.

My account was fine last time I checked. Do I need to check again?

Platforms add settings, reset some during redesigns, and change what a role can do. A check after any major change to the app is worth twenty minutes, and the reasons are set out in privacy setting changes.

What about an account I only use to log into other things?

That is the highest-value account you have, not the lowest. Audit it first, give it the strongest second factor available, and move anything important onto its own credentials.

More in Costs

Features

Account security: requirements and practical steps for 2027

Account security ordered by the way accounts are actually lost: the email account, the recovery route, second factors, sessions and connected apps.

Costs

Account security case studies: findings and lessons

Account security case studies for arrangements rather than individuals: shared logins, client access, a departure, and helping an older relative.

Guides

Account security changes 2027: facts and context

Account security decays on its own: the drift list, how to handle an announced change without being caught by a fake version, and what ages worst.

Reviews

Account security examples: what the cases show

Account security incidents written from inside them: the code, the stale recovery address, the reused session, and the moment each one turned.