We optimize capacity, drive infrastructure growth, and ensure its stable support.

UKR ENG

IT Audit

An independent review of servers, network, backups and cybersecurity against 50+ checkpoints. In 5 business days: a report with risks, a plan and costs.

Frequently asked questions
to the finished report
5 days
checkpoints reviewed
50+
signed before any access
NDA
downtime during the audit
0

When a company needs an IT audit

  • One specialist has run the infrastructure for years β€” and is now leaving, off sick or on holiday
  • You are changing IT provider and want an independent view of what you are taking on
  • Failures keep recurring and nobody names a cause β€” "we rebooted it and it went away"
  • Nobody remembers when a restore from backup was last actually tested
  • The company has doubled in size while the servers, network and access rights stayed the same
  • A certification, a tender or a software licensing inspection is coming up
  • You are planning the IT budget and need defensible numbers rather than guesswork
  • IT spend grows every quarter with no clear answer as to what exactly you are paying for

What the IT audit covers: 50+ checkpoints across six areas

Servers and virtualisation

  • Hardware health: disk SMART data, RAID arrays, power, cooling, remaining warranty
  • Windows Server and Linux: versions, vendor support status, missing critical updates
  • Virtualisation platforms: resource allocation, forgotten snapshots, headroom for growth

Network and remote access

  • The real network topology, segmentation, link bottlenecks and Wi-Fi coverage
  • Router and switch configuration: firmware versions, factory passwords, needlessly open ports
  • Firewall rules, port forwards, VPNs and contractor access β€” who can reach what

Cybersecurity and access control

  • External perimeter: public services, certificate expiry, entry points an attacker would use
  • The directory service: privileged accounts, password policies, live accounts of former employees
  • Antivirus protection, multi-factor authentication, laptop encryption, patching routine

Backup and recovery

  • What is backed up, where and how often β€” matched against your list of business-critical systems
  • Compliance with the 3-2-1 rule and whether an immutable copy exists that ransomware cannot encrypt
  • A restore test: how many hours it takes to bring a server back (RTO) and how much data you lose (RPO)

Cloud services and licences

  • Corporate mail and file storage: access rights and links shared publicly outside the company
  • Subscription and licence inventory β€” what you pay for monthly and what nobody uses
  • Software licensing compliance and the risks it creates during inspections

Processes, documentation and IT spend

  • Where passwords, credentials and diagrams live β€” or whether it all sits in one person's head
  • Asset records: age, warranty, end-of-support dates from the manufacturer
  • How the IT budget breaks down: where you overpay and what has to be replaced this year

Express audit or full audit?

Express audit or full audit?
Parameter Express audit Full audit
Turnaround 1-2 business days 5 business days; up to 2 weeks for 100+ workstations
Scope Servers, backups, external perimeter 50+ checkpoints: infrastructure, security, cloud, processes, spend
On-site work Remote only On-site review of the server room, equipment and workstations
Test restore from backup Not performed Performed, with real RTO and RPO recorded
Report A 5-7 page list of critical findings Full report, risk register, remediation plan and cost estimate
When to choose it To quickly find out whether critical gaps exist Budget planning, changing provider, preparing for certification

How the audit runs: 5 steps

  1. 1

    Scope agreed, NDA signed

    Day 0

    We agree what the review covers and what it leaves alone. The non-disclosure agreement is signed before we receive any access.

  2. 2

    Data collection

    Days 1-2

    Network inventory, config and log exports, interviews with your IT specialist and department heads.

  3. 3

    On-site review

    Day 3

    We walk the server room, the equipment and the workstations, then run a test restore from backup and time how long it really takes.

  4. 4

    Analysis and reporting

    Days 4-5

    Findings go into a risk register, remediation is costed, and the PDF and a separate management summary are prepared.

  5. 5

    Results walkthrough

    After the report

    We go through the report together: the technical part with your IT specialist, the business conclusions with management.

What is inside the report

Infrastructure map

  • Network diagram and an inventory of servers, workstations and network equipment
  • OS and software versions, flagged where the vendor no longer supports them
  • Who has access to what β€” including the accounts everyone has forgotten about

Risk register

  • Every finding scored for likelihood and for impact on your business specifically
  • Evidence under each entry: the configuration, the log line or the test result
  • Ordered by severity rather than by chapter β€” so it is clear where to start

Remediation plan

  • Three horizons: critical now, important within 1-3 months, planned into next year's budget
  • Marked up by who can do it β€” your own administrator, or work that needs a contractor
  • An indicative cost per line: hardware, licences and labour kept separate

Summary for management

  • A page and a half with no jargon β€” written for whoever signs off the budget
  • A straight answer to what happens to the business if nothing is done
  • Three or four priorities instead of a list of forty items

Why clients choose our IT audit

  1. 01 A report a director can read

    The technical part for your IT specialist, a separate business-language summary for whoever signs off the budget

  2. 02 Every finding backed by evidence

    Not "we recommend upgrading", but the specific config, log entry or test result that proves the point

  3. 03 10+ years, 170+ clients

    We know the typical problems of small and mid-sized businesses β€” and which of them actually cause downtime

  4. 04 An audit with no downtime

    We work around your normal operations, remotely or on site at a time that suits you

  5. 05 NDA before any access

    The non-disclosure agreement is signed before we start; collected data is used only to produce the report

  6. 06 No obligations afterwards

    The report is yours β€” act on it in-house, with us, or with any other provider

Frequently asked questions

How much does an IT audit cost?

It depends on the number of workstations and servers and the scope you choose. An express audit of a small office costs considerably less than a full one. Tell us your workstation and server count and we will price it and fix that price in the contract before work starts β€” no "extra hours" appearing along the way.

How long does an IT audit take?

A standard audit for a company with up to 50 workstations takes 2-3 business days of data collection plus 2 days to prepare the report β€” 5 business days in total. For 100+ workstations or several sites, up to 2 weeks. An express audit of critical systems takes 1-2 days.

How do we know whether we need an audit right now?

A four-question test: do you know how many hours it takes to bring the main server back after a failure; when a restore from backup was last tested; which former employees still have access to your systems; and what exactly the monthly IT invoices pay for. If there is no confident answer to even one of them, the audit pays for itself on the first finding.

What do you need from us to start?

A point of contact on your side, read access to servers, network equipment and management consoles, two or three short interviews with your IT specialist and department heads, and access to the server room. You do not need to create administrator accounts for us: read-only rights are enough for the vast majority of the checks.

Will there be downtime, or any risk to our systems?

Neither. The audit runs during normal business operations: we connect remotely or visit at a convenient time, and nothing has to be stopped. The review itself is reading configurations and collecting data β€” we change nothing in production without separate written approval. The only active step is the test restore from backup, and it runs in an isolated environment rather than over your live data.

Can you review just one area β€” backups or security only?

Yes. The scope is fixed at the start, so a single area β€” backups, the external perimeter, access rights or licensing β€” can be reviewed on its own, with a short report covering just that. Companies choose this when they have a specific suspicion. The full audit is what you need for a complete picture and a defensible annual IT budget.

How is an IT audit different from a penetration test?

An audit looks at the infrastructure from the inside and broadly: servers, network, backups, access, processes, spend. A penetration test is a narrow simulation of an outside attack. The audit shows where you are generally weak; the pentest proves a specific vulnerability is exploitable. For most companies the audit is the right place to start.

Will our sysadmin see this as an inspection of their work?

We assess the infrastructure, not people: there is no "who is to blame" section in the report, only the state of the systems and what to do about it. In practice in-house admins often use the report themselves as the argument that finally unlocks the budget they have been asking for.

Do you help fix what the audit finds?

Yes, under a separate agreement β€” but it is not a condition of the audit. The report and the plan are yours: act on them in-house, with us, or with any other provider. Costs in the report are calculated as though an external contractor were doing the work, so they are usable as a benchmark when comparing quotes.

Will you keep our data confidential?

Yes. The non-disclosure agreement is signed before we receive any access. All collected data is used solely to prepare the report, is never shared with third parties, and is deleted on our side at your request.

Get a free consultation!

Book a free initial consultation: in a 20-minute call we will outline the scope, timeline and cost of the audit β€” with no obligation.