Decision guide
IT audit checklist: what to check and what it tells you
Most IT audits produce a long list where three items matter. Those three are almost always the same: whether backups have ever been restored, whether departing staff still have access, and whether anybody would notice a compromise. Start there, and treat the rest as housekeeping.
What is actually being compared
- Self-audit
- Work through the checklist yourself. Free, and limited by what you already know to look for.
- Provider audit
- An external audit as part of onboarding or a review. More thorough, and not independent if that provider wants the work.
- Independent assessment
- A third party with no stake in the remediation. Most objective, and the most expensive.
Side by side
How they differ in practice
| Feature | Feature | Self-audit | Provider audit | Independent assessment |
|---|---|---|---|---|
Cost | None | Usually free with a proposal | Paid | |
Objectivity | Limited by knowledge | Compromised by commercial interest | High | |
Depth | Surface | Good | Deep | |
Good for | Getting oriented | Scoping a change of provider | Compliance and board reporting |
The three that actually matter
- Backup: not whether it runs, but when a restore was last tested and by whom. A backup that has never been restored is a hypothesis.
- Access: list everyone who left in the last twelve months and check every system. Email, VPN, cloud consoles, SaaS, shared accounts. This is where audits most often find something live.
- Detection: if an account were compromised tonight, what would notice? If the answer is nobody, that is the gap, and no amount of policy documentation closes it.
The rest of the checklist
- Asset register with age, warranty and assigned user. Missing entirely in most first audits.
- Multi-factor authentication coverage. Check the exceptions list, because that is where it fails.
- Patch status across servers, endpoints and network devices, including the firewall firmware nobody has touched.
- Admin accounts: how many, who has them, are any shared.
- Documentation: network diagram, addressing, firewall rules, vendor contacts, renewal dates.
- Licence reconciliation against actual staff.
- End-of-support software still in use, and what depends on it.
- Physical: comms room access, ventilation, power protection, cable labelling.
How to read the results
- Urgent means exploitable now or recoverable never: live access for leavers, untested backup, no MFA, unsupported internet-facing software.
- Important means it will cause an outage or a finding within the year: ageing hardware, missing documentation, unmanaged patching.
- Housekeeping is everything else. Real, worth doing, and not worth delaying the first two for.
When the other option is right
A free audit from a provider hoping to win your business is not independent, and that includes ours. It is still worth having, because the findings are usually real, but treat the recommended remediation as a proposal rather than a diagnosis, and get a second view on anything expensive.
Running your first audit this month
- Start with the leaver list. Take everyone who left in the last twelve months and check every system for live access. This takes an afternoon and reliably finds something.
- Test a restore. Pick a real file and a real mailbox, bring them back somewhere isolated, and time it. Record who did it and how long it took.
- Check MFA coverage and, more importantly, the exception list. Exceptions are where it fails.
- List every system that holds company data, including SaaS applications bought by individual departments. Most first audits find several nobody in IT knew about.
- Sort findings by exploitable-now and recoverable-never, fix those, and schedule the rest. An unprioritised audit report gets filed rather than acted on.
Questions
Common questions
Still deciding?
Talk it through with an engineer, not a salesperson
Tell us your situation and we will tell you which option fits, including when that is not us. Initial reply within 4 business hours.