A complete IT security audit in 2026 covers six domains: governance and access, workstations and mobility, network and infrastructure, applications and data, backups and continuity, and finally the human factor and procedures. The checklist below enables an honest first self-assessment: every item without a clear answer is a potential workstream, to be prioritized afterwards by the actual risk it poses to your business. Run through it honestly, involve the people who operate each domain, and write down every answer you are not sure about.
1. Governance and access
- Is there an up-to-date inventory of user accounts, with a process that disables access the day an employee or contractor leaves?
- Is least privilege applied — everyone holds only the rights their role requires, and are administrator accounts separated from day-to-day accounts?
- Is MFA enabled everywhere possible, starting with email, VPN, administration tools and financial services?
- Are external providers' accesses nominative, time-limited and logged?
- Does your password policy rely on a company password manager rather than memory and sticky notes?
2. Workstations and mobility
- Do all workstations receive security updates automatically, operating system and applications included?
- Is an EDR, or at minimum a centrally managed antivirus, deployed and supervised?
- Are laptop disks encrypted, and do screens lock automatically?
- Can you remotely wipe or lock a lost or stolen device, including phones accessing company email?
- Are personal and professional uses compartmentalized on devices that access company data?
3. Network and infrastructure
- Do you have an up-to-date map of your servers, network equipment and cloud services, with their versions?
- Are Internet-facing devices (firewall, VPN, email) up to date, with administration interfaces unreachable from outside?
- Is the network segmented: separate guest Wi-Fi, sensitive servers isolated from office workstations?
- Have all default passwords on equipment been changed?
- Are logs from critical systems centralized and retained long enough to investigate an incident that occurred weeks ago?
4. Applications and data
- Do you have an inventory of business applications, their hosting and their owners, including tolerated shadow IT?
- Are the dependencies and frameworks of your custom-built applications maintained and audited regularly?
- Is sensitive data identified, encrypted in transit and at rest, and is access to it traced?
- Do test environments use anonymized data rather than copies of production?
- Are your GDPR obligations covered: processing register, retention periods, breach notification procedure?
5. Backups and continuity
- Do you apply the 3-2-1 rule: three copies of the data, on two different media, one of them off-site and offline or immutable?
- Are backups tested through real restorations, rather than merely assumed to work?
- Do you know your maximum tolerable downtime and maximum tolerable data loss, service by service?
- Does a written continuity plan exist, with emergency contacts reachable even if the information system is down?
- Are backups protected against an attacker who has compromised your administrator accounts — the classic ransomware scenario?
6. People and procedures
- Are your teams trained regularly, with practical exercises such as phishing simulations?
- Does everyone know whom to report a suspicious email or unusual behavior to, and is reporting rewarded rather than punished?
- Does a written incident management procedure state who decides, who communicates and who acts?
- Do payments and bank detail changes follow systematic dual approval?
- Do arrivals, departures and role changes trigger an access review?
Prioritizing fixes by risk
A checklist often reveals dozens of gaps; fixing everything at once is unrealistic. Cross two criteria for each gap: the likelihood of exploitation (an unpatched Internet-facing service will be scanned within hours, not months) and the business impact (production stoppage, customer data loss, financial fraud). Address the high-likelihood, high-impact quadrant first — typically missing MFA on email, outdated exposed equipment and untested backups. Cheap, fast measures such as dual approval of payments deserve immediate implementation regardless of their ranking. Document each decision, including the risks you consciously accept: a written, assumed risk is a managed risk, while an unspoken one is a future incident.
How often should you audit, and with whom?
The right rhythm for an SMB: a quarterly internal review of the fundamentals (accounts, updates, backups), a full annual audit, and a targeted audit after any major change — cloud migration, merger, new critical application, security incident. Internal self-assessment has real value: it is frequent, inexpensive and builds a security culture. But it suffers from structural blind spots: you never test your own choices well, and some verifications (penetration testing, advanced configuration review, code analysis) require specific tooling and experience. An external audit brings that fresh perspective, a comparison with the state of the art, and a well-argued prioritization you can present to your board or your cyber insurer. Between audits, keep a simple dashboard of the fundamentals — patch status, MFA coverage, dates of the last backup restoration tests — so that drift becomes visible before it becomes dangerous.
The hardest part is not ticking the list, but turning its results into an action plan sustained over time. Relying on a technical partner who audits, prioritizes and then supports remediation is what turns findings into a security posture that genuinely improves quarter after quarter, at a pace your teams and your budget can actually sustain.
