Skip to main content
Decision guide

IT audit checklist: what to check and what it tells you

Most IT audits produce a long list where three items matter. Those three are almost always the same: whether backups have ever been restored, whether departing staff still have access, and whether anybody would notice a compromise. Start there, and treat the rest as housekeeping.

What is actually being compared

Self-audit
Work through the checklist yourself. Free, and limited by what you already know to look for.
Provider audit
An external audit as part of onboarding or a review. More thorough, and not independent if that provider wants the work.
Independent assessment
A third party with no stake in the remediation. Most objective, and the most expensive.
Side by side

How they differ in practice

Feature
Feature
Self-audit
Provider audit
Independent assessment
Cost
NoneUsually free with a proposalPaid
Objectivity
Limited by knowledgeCompromised by commercial interestHigh
Depth
SurfaceGoodDeep
Good for
Getting orientedScoping a change of providerCompliance and board reporting

The three that actually matter

  • Backup: not whether it runs, but when a restore was last tested and by whom. A backup that has never been restored is a hypothesis.
  • Access: list everyone who left in the last twelve months and check every system. Email, VPN, cloud consoles, SaaS, shared accounts. This is where audits most often find something live.
  • Detection: if an account were compromised tonight, what would notice? If the answer is nobody, that is the gap, and no amount of policy documentation closes it.

The rest of the checklist

  • Asset register with age, warranty and assigned user. Missing entirely in most first audits.
  • Multi-factor authentication coverage. Check the exceptions list, because that is where it fails.
  • Patch status across servers, endpoints and network devices, including the firewall firmware nobody has touched.
  • Admin accounts: how many, who has them, are any shared.
  • Documentation: network diagram, addressing, firewall rules, vendor contacts, renewal dates.
  • Licence reconciliation against actual staff.
  • End-of-support software still in use, and what depends on it.
  • Physical: comms room access, ventilation, power protection, cable labelling.

How to read the results

  • Urgent means exploitable now or recoverable never: live access for leavers, untested backup, no MFA, unsupported internet-facing software.
  • Important means it will cause an outage or a finding within the year: ageing hardware, missing documentation, unmanaged patching.
  • Housekeeping is everything else. Real, worth doing, and not worth delaying the first two for.

When the other option is right

A free audit from a provider hoping to win your business is not independent, and that includes ours. It is still worth having, because the findings are usually real, but treat the recommended remediation as a proposal rather than a diagnosis, and get a second view on anything expensive.

Running your first audit this month

  1. Start with the leaver list. Take everyone who left in the last twelve months and check every system for live access. This takes an afternoon and reliably finds something.
  2. Test a restore. Pick a real file and a real mailbox, bring them back somewhere isolated, and time it. Record who did it and how long it took.
  3. Check MFA coverage and, more importantly, the exception list. Exceptions are where it fails.
  4. List every system that holds company data, including SaaS applications bought by individual departments. Most first audits find several nobody in IT knew about.
  5. Sort findings by exploitable-now and recoverable-never, fix those, and schedule the rest. An unprioritised audit report gets filed rather than acted on.
Questions

Common questions

Still deciding?

Talk it through with an engineer, not a salesperson

Tell us your situation and we will tell you which option fits, including when that is not us. Initial reply within 4 business hours.