An IT security audit is a structured, evidence-based review of whether your security controls are actually in place and working, not just written down. Expect questions about access, devices, data, vendors and policies, and a written report of findings at the end.
Plenty of businesses have a security policy in a binder somewhere. An audit checks whether reality matches the binder. It compares your controls against a standard or framework, gathers evidence, and documents what is working, what isn't and what you plan to do about it.
These three get mixed up often, and each answers a different question.
A mature security program uses all three at different times. Which ones you need, and how often, depends on your regulations, your cyber insurance requirements and what your clients or business partners expect.
Who has access to what, and does it match their job? Are former employees' accounts still active? Are administrator accounts limited to the people who genuinely need them? Are access changes logged? A good reviewer looks at actual system settings, not just the policy.
Is multi-factor authentication (MFA) enforced on every account or only some? Are password rules configured in the system or merely written down? Is single sign-on (SSO) used to manage identities centrally?
Is endpoint detection and response running on every managed device? Are devices enrolled in mobile device management, encrypted and fully patched? Device inventory from the remote monitoring and management (RMM) platform is usually compared with the asset list to find gaps.
Is the firewall configured sensibly for your size and risk, with current firmware? Is the network segmented where it should be, such as guest Wi-Fi separated from business systems and payment systems isolated? Are logs captured and kept?
Where does sensitive data live? Is it encrypted at rest and in transit? Is it backed up, are the backups isolated, and have restores been tested? Do retention periods match your regulatory requirements?
Is there a list of technology vendors with access to your systems or data? Have their security practices been reviewed? Are the right agreements in place, such as business associate agreements (BAAs) for healthcare? Are vendor logins controlled?
Do written security policies exist, and do they reflect what actually happens? Are they current? Has staff training happened, and is it documented?
Is there a written incident response plan? Has it been tested? Do the right people know how to use it?
Reviews can be internal (performed by your own staff or your IT provider) or external (performed by an independent third party). What your frameworks require varies:
An internal review is valuable for finding and fixing gaps, but it isn't independent. If your IT provider runs the systems being reviewed, its review shouldn't be presented as an independent audit. Where a framework, insurer, client or regulator expects independence, use an outside assessor.
Many small and midsize businesses do a security review at least once a year, plus an extra review after big changes: new systems, a new location, significant staff turnover or a security incident.
A security review or audit typically produces a written report with findings grouped by category and severity, the evidence behind each finding, a comparison with the applicable framework, remediation recommendations, and a management response where you record what you plan to fix and when.
The findings don't have to be perfect for the exercise to be worthwhile. A report that identifies gaps and documents a remediation plan shows that your business takes a systematic approach to security, which is what examiners, auditors and insurers generally want to see.
For managed IT clients, NerdSquad performs security assessments and reviews of the environment we support: checking controls against the frameworks that apply to you, documenting findings and working through remediation with you. This is an internal review that prepares you for audits; it isn't an independent audit. When you need an independent audit or assessment, such as a SOC 2 report or a QSA assessment, we work alongside the firm you engage, providing evidence and fixing the findings. Penetration testing is delivered with our penetration-testing partner, with NerdSquad scoping it, coordinating it and handling the fixes.
For the bigger picture, see what digital compliance means and how we help with HIPAA, PCI and SOC 2 requirements. NerdSquad is not a law firm or an audit firm; confirm your obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.