IT Security Audit: What Your Business Should Expect

What Is an IT Security Audit, and What Should Your Business Expect?

An IT security audit is a structured, evidence-based review of whether your security controls are actually in place and working, not just written down. Expect questions about access, devices, data, vendors and policies, and a written report of findings at the end.

Plenty of businesses have a security policy in a binder somewhere. An audit checks whether reality matches the binder. It compares your controls against a standard or framework, gathers evidence, and documents what is working, what isn't and what you plan to do about it.

Audit, risk assessment and pen test: how they differ

These three get mixed up often, and each answers a different question.

  • A risk assessment looks forward. It identifies your assets and threats, scores the risks and prioritizes fixes. See what a compliance risk assessment is.
  • A penetration test is adversarial. Testers try to exploit weaknesses the way a real attacker would, to see whether specific defenses hold.
  • A security audit reviews evidence. It examines your controls against a defined standard and produces a report showing whether you meet it.

A mature security program uses all three at different times. Which ones you need, and how often, depends on your regulations, your cyber insurance requirements and what your clients or business partners expect.

What an audit examines

Access controls

Who has access to what, and does it match their job? Are former employees' accounts still active? Are administrator accounts limited to the people who genuinely need them? Are access changes logged? A good reviewer looks at actual system settings, not just the policy.

Authentication

Is multi-factor authentication (MFA) enforced on every account or only some? Are password rules configured in the system or merely written down? Is single sign-on (SSO) used to manage identities centrally?

Endpoint security

Is endpoint detection and response running on every managed device? Are devices enrolled in mobile device management, encrypted and fully patched? Device inventory from the remote monitoring and management (RMM) platform is usually compared with the asset list to find gaps.

Network security

Is the firewall configured sensibly for your size and risk, with current firmware? Is the network segmented where it should be, such as guest Wi-Fi separated from business systems and payment systems isolated? Are logs captured and kept?

Data protection

Where does sensitive data live? Is it encrypted at rest and in transit? Is it backed up, are the backups isolated, and have restores been tested? Do retention periods match your regulatory requirements?

Vendor management

Is there a list of technology vendors with access to your systems or data? Have their security practices been reviewed? Are the right agreements in place, such as business associate agreements (BAAs) for healthcare? Are vendor logins controlled?

Policies and training

Do written security policies exist, and do they reflect what actually happens? Are they current? Has staff training happened, and is it documented?

Incident response

Is there a written incident response plan? Has it been tested? Do the right people know how to use it?

Who performs it and how often

Reviews can be internal (performed by your own staff or your IT provider) or external (performed by an independent third party). What your frameworks require varies:

  • HIPAA requires periodic technical and non-technical evaluations of your security safeguards. These can be performed internally or by an outside party; the rule doesn't require both.
  • SOC 2 is a voluntary attestation, usually driven by customer demand, and the report must come from an independent CPA firm.
  • PCI DSS validation depends on your merchant or service provider level. Some organizations complete a self-assessment questionnaire; others need an assessment by a Qualified Security Assessor (QSA).

An internal review is valuable for finding and fixing gaps, but it isn't independent. If your IT provider runs the systems being reviewed, its review shouldn't be presented as an independent audit. Where a framework, insurer, client or regulator expects independence, use an outside assessor.

Many small and midsize businesses do a security review at least once a year, plus an extra review after big changes: new systems, a new location, significant staff turnover or a security incident.

What the output looks like

A security review or audit typically produces a written report with findings grouped by category and severity, the evidence behind each finding, a comparison with the applicable framework, remediation recommendations, and a management response where you record what you plan to fix and when.

The findings don't have to be perfect for the exercise to be worthwhile. A report that identifies gaps and documents a remediation plan shows that your business takes a systematic approach to security, which is what examiners, auditors and insurers generally want to see.

How NerdSquad helps

For managed IT clients, NerdSquad performs security assessments and reviews of the environment we support: checking controls against the frameworks that apply to you, documenting findings and working through remediation with you. This is an internal review that prepares you for audits; it isn't an independent audit. When you need an independent audit or assessment, such as a SOC 2 report or a QSA assessment, we work alongside the firm you engage, providing evidence and fixing the findings. Penetration testing is delivered with our penetration-testing partner, with NerdSquad scoping it, coordinating it and handling the fixes.

For the bigger picture, see what digital compliance means and how we help with HIPAA, PCI and SOC 2 requirements. NerdSquad is not a law firm or an audit firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses