You do not need a free afternoon to meaningfully improve your security. A password health check that actually changes something takes about fifteen minutes and your password manager open in front of you.
It is five passes through your vault, in order, shortest first. Work down the list and stop when the timer runs out – the checks are arranged so the ones that matter most are already done by then.
Open mSecure on whichever device you actually use most. Start the clock.

Minutes 1-3: Where every password health check should start
Open Security Center. It flags weak, reused, and aging passwords before they become a problem, which means the first three minutes are not spent hunting – they are spent reading a list someone else already made.
Do not fix anything yet. Read the list, and notice which category is longest. For most people it is reuse, and that is the one worth your remaining twelve minutes.
Minutes 4-8: Fix the reused ones, highest stakes first
Reuse is the failure that turns one company’s bad night into your problem. When a site is breached and you used that password in four other places, the attacker does not need to break anything else – they just try it.
Do not work alphabetically. Work in this order:
- The email address you use to reset other passwords
- Anything holding money – bank, payment apps, anywhere a card is stored
- Anything holding your identity – your phone carrier, your cloud storage
Change three of them, not thirty.
Do it in this order, because the order matters: go to the account itself and start its change-password flow, generate the new password with mSecure’s password generator, paste it in, confirm the site accepted it, and then save it to your vault.
Changing a password in mSecure does not change it on the account. Your vault holds a record of the password, not the password itself – editing the record on its own just means your vault and the site now disagree. The change has to happen where the account lives.
If you do get the order wrong, it is recoverable. Password History keeps previous versions of stored passwords, so the old one is still there. It is not an obvious feature to find. Open the record and look at the password field for a small clock icon with the arrow curling backwards. On iPhone and iPad it is always visible; on desktop it only appears once you hover over the field. Click it and you get the previous versions.
Minutes 9-12: Turn on two-factor where it is offered
A second factor is the cheapest security upgrade available, because it breaks the attack above completely. Even a stolen, correct password does not get someone in.
You do not have to guess which accounts support it. Two-Factor Awareness flags which of your logins support two-factor authentication, so this becomes a filtered list rather than a research project. Turn it on for your email first, then money, then anything else you would not want posted publicly.
mSecure’s built-in One-Time Passwords mean the codes live alongside the logins, so this does not cost you a second app.
If a site offers a passkey instead, take it – it is phishing-resistant by design. We wrote about how passkeys and OTPs work together if you want the longer version.
Minutes 13-14: Find out what has already leaked
Your vault can tell you a password is weak. It cannot tell you a company lost it two years ago.
Put your main email address into Have I Been Pwned. It is free, it is the reference the industry itself uses, and it takes about forty seconds. Anything it surfaces goes straight to the top of the list from minutes 4-8.
mSecure does not do breach monitoring, and we would rather point you at the tool that does it properly than pretend otherwise.
Minute 15: Check your locks
The last minute is the one people skip, and it is the only one that protects everything else.
- Biometric Unlock on, so a strong master password is not a reason to get lazy
- Auto-lock and timed logout set to something short enough to matter on a device you leave on a desk
- Sync set the way you actually want it – mSecure gives you cloud or Wi-Fi sync, and that is a deliberate choice rather than a default you inherited
What not to do in a password health check
Change your passwords on a schedule.
This used to be standard advice and it is now the opposite of best practice. NIST’s guidance is explicit: verifiers “SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically),” and should force a change only where there is evidence of compromise. Scheduled rotation reliably produces weaker passwords, because people cope with it by making small predictable edits to the one they already had.
Change a password because it is reused, weak, or exposed. Those are reasons. The calendar is not one.
If you only have five minutes
A five-minute password health check is still worth doing. Run Security Center, fix the reuse on your email account, and turn on two-factor for it. Email is the reset route to everything else, so securing it first does more than any other single change.
The rest keeps. Come back to it.
Want the ongoing version rather than the one-sitting version? Seven habits that keep hackers out covers what to do the rest of the year. And if your passwords are weak rather than reused, start with what actually makes a password strong.
