Scale Me NowSCALE ME NOW
Scale Me Now / Guides / IT audit: where to start in an SME
Guide

IT audit: where to start in an SME

A full IT audit is useful, but it is not the first step. Four simple checks will already tell you whether your situation holds, and they cost nothing.

The four checks to run first

Restore a backup. Not verify that it exists: actually restore it, onto a test environment, and measure how long it takes. A backup never restored is an assumption. This is the test that fails most often.

List who has access to what. Especially former employees' accounts, provider access still open, and shared accounts whose password several people know.

Identify what is no longer supported. Operating systems, database engines, language versions. A component past end of support receives no security patches, including for published vulnerabilities.

Look for single-person dependencies. The server only one person knows how to restart, the script nobody else understands. It is a real operational risk and appears on no dashboard.

What a serious audit should contain

Beyond those four points, a formal audit should cover the real inventory of what runs, network exposure, data processing compliance, the consolidated cost of IT, and the state of provider contracts.

Above all it must produce a ranking. A list of fifty gaps with no priority order is not actionable and ends up in a drawer. What is useful is knowing which three things to start this quarter.

Spotting an audit that sells

Some signals are reliable.

The report concludes a full rebuild is needed, whatever the existing estate. Recommendations are generic and could apply to any company. No gap is classified as acceptable as-is, when in any organisation some are. And the provider running the audit is also the one who would do the recommended work, without that being stated.

An honest audit also tells you what is fine and what is not worth fixing.

Frequently asked questions

Is an IT audit paid?

It depends on scope. The four basic checks only require internal time. A formal audit covering inventory, security, cost and contracts is an engagement, and its price depends on the size of the estate.

How often should you audit?

A full review every two to three years is enough in a stable organisation. Restoring a backup and reviewing access, however, deserve at least an annual cadence, and after any departure.

Can the auditor also do the work?

It is possible, but it must be stated before the audit, and the report must remain usable by a third party. An audit whose conclusions cannot be put out to tender has little value.

Go further

This maps to our Fractional CIO offer, or talk it through with the founder.

/ Contact

Let's talk about your situation.

A 30-minute call with the founder, no strings attached. Reply within 24 business hours.

No data is shared with third parties.

/ Scale Me Now

A question about your IT?

Book 30 minutes

An expert replies within 24 business hours.