Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Cybersecurity

Cybersecurity audit: what is examined, what you receive, what you do with it

A cybersecurity audit answers one simple question: what, today, could stop your organization or expose your data. This page describes exactly what is examined, the document you receive at the end, and what happens next.

An audit is not a software report exported to PDF. It is a review carried out by a person, covering your identities, your devices, your remote accesses, your backups and your practices, that leads to a report naming the risks and a list of fixes ranked by what would hurt your organization most.

Presenting the cybersecurity audit plan to a client in a meeting room

In brief

The essentials of a cybersecurity audit in three points

An audit is not a software report exported to PDF. It is a review carried out by a person, that leads to a list of fixes ranked by what would hurt you most.

What it is

A review of your identities, your devices, your remote accesses, your backups and your practices, followed by a report that names the risks and fixes them in a defined order.

Who it is for

A small business that has never had its environment reviewed, that is changing IT providers, that has to answer a security questionnaire from a client or insurer, or that has just been through an incident.

What it changes

You stop guessing. You know what is in place, what is missing, what doing nothing would cost, and where to start Monday morning.

Understanding

What a cybersecurity audit is really for

Most small businesses know they have weaknesses, but do not know which ones matter. The audit settles that question with facts rather than impressions. It answers three things: what actually exists in your environment, what is exposed, and what would keep you from getting back up after an incident.

There is a real difference between an audit and a penetration test. A penetration test looks for a specific flaw to get in. The audit paints the complete picture and ranks it: it uncovers the account of a former employee still active, the backup that has never been restored, the forgotten remote access on an old server. For a small business, it is almost always the audit that delivers the most value first.

An audit is also what lets you answer honestly when a client, an insurer or a customer asks you to demonstrate your practices. Without a document, the answer relies on the memory of whoever manages the IT.

Cybersecurity advisory, presenting the remediation plan to a client

The scope

What is examined during the audit

The review covers six areas. They are verified in your actual environment, not from a questionnaire the client filled out.

Identities and accesses

What is checked. Active accounts and orphan accounts, admin rights, multi-factor authentication, service accounts, shared accounts, password policy, external supplier accesses.

What we find most often. Former employees’ accounts still active, and admin rights granted once to help someone out, never removed.

Workstations and servers

What is checked. Real inventory of the fleet, systems still supported by their vendor, patch status, disk encryption, protection installed and actually running, unauthorized software.

What we find most often. Machines missing from the official inventory, and patches behind on third-party software rather than on Windows.

Network and remote access

What is checked. What is published on the Internet, firewall rules, remote accesses, Wi-Fi and guest network, segmentation, network gear whose firmware is no longer updated.

What we find most often. A remote access left open for a project that ended long ago.

Data and backups

What is checked. Where the data lives, who can read it, what is backed up, how often, where the copies are kept, whether one copy is out of an attacker’s reach, and when a restore was last rehearsed.

What we find most often. Backups that have been running for years without a single restore ever being tested.

Email and collaboration

What is checked. Microsoft 365 or Google Workspace configuration, SPF, DKIM and DMARC, mailbox rules, external file shares, third-party apps allowed to read your data.

What we find most often. Public sharing links created long ago and never expired, and a DMARC that is missing or ineffective.

Practices and documentation

What is checked. Onboarding and offboarding procedure, password management, incident plan, the register required by Law 25, employee awareness, dependence on a single person.

What we find most often. No written procedure, and one person who holds the critical accesses in their head.

How it unfolds

How an audit is carried out, step by step

The audit unfolds in four steps. Your operations are not interrupted: the collection is done in read mode, with no change to your environment.

  1. ScopingA short meeting to understand what your organization does, what cannot go down, your compliance obligations and your concerns. This is what defines what counts as a serious risk for you, because an accounting firm and a manufacturing shop do not have the same weak spots.
  2. CollectionA technical read of your environment, in read-only mode: inventory, configurations, logs, cloud portal, network equipment. Part is done remotely, part on site when equipment or off-network devices need to be seen.
  3. Analysis and rankingEach finding is scored along two axes: the likelihood it is exploited and the effect on your organization if it is. It is that combination that sets the order, not the theoretical severity a tool displays.
  4. Presentation and planA meeting where we go through the findings with you, in plain language, and you leave with an action plan spread over time: what to fix right away, what needs a project, what needs a budget.

The deliverable

What you receive at the end of the audit

The report is written to be read by leadership, not only by a technical person. It contains the following.

  • A one-page executive summary, with the major risks stated as consequences for the organization
  • The real inventory of what was found: workstations, servers, accounts, remote accesses, backups, cloud services
  • Each finding with its evidence, its risk level and what would happen if it were exploited
  • A remediation plan ranked in three horizons: immediate, to schedule, to budget
  • What is already done well, named explicitly, so nothing that works is undone
  • The evidence needed to answer a security questionnaire from a client or insurer
  • A baseline for measuring progress at the next review

What comes next

Where this service sits

The audit is a starting point. The next step is our cybersecurity services managed year-round, ransomware protection and Law 25 compliance. Findings that turn into projects belong in a three-year IT plan.

This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it. See Trois-Rivières, the Mauricie, Montreal and Quebec City.

Further reading: vulnerability management and CVEs, your data on the dark web and choosing a firewall.

The report is yours. The audit is a standalone mandate. You can hand the remediation to your internal team or to another provider: the document stays usable. An audit whose conclusions serve only to sell next quarter’s service is worth nothing.

Questions and answers

Frequently asked questions about the cybersecurity audit

How long does a cybersecurity audit take?
It depends on the number of workstations, servers and sites, and on how much documentation already exists. The collection disturbs your team very little: what takes time on your side are the scoping meeting and the presentation meeting. We give you a duration after we have seen the size of your environment.
Do we have to stop the systems during the audit?
No. The collection is done in read mode, with no configuration change and no test that could take a service down. If a more intrusive test is desirable, it is proposed separately, scheduled and authorized in writing.
Do we have to be an OKTO client to have an audit done?
No. The audit is a standalone mandate. The report belongs to you and remains usable even if you entrust the remediation to someone else or to your internal team. This is a deliberate choice: an audit whose conclusions only serve to sell the next quarter’s service is worth nothing. If you are comparing providers, our guide on how to choose a managed IT provider lists the criteria to weigh.
What framework does the audit rely on?
Our audits rely on the baseline cybersecurity controls from the Canadian Centre for Cyber Security, together with the requirements of Law 25. The review covers the six areas described above, which map to those controls.
How often should the audit be redone?
An environment changes: employees come and go, applications are added, equipment ages. Repeating the review confirms that the fixes have held and measures progress since last time. For our managed clients, part of that check is continuous rather than one-off, through the monitoring and reviews included in the plan.
Does the audit cover Law 25?
It covers the technical and organizational side that supports it: where the personal information sits, who accesses it, how an incident would be identified and logged, and which security measures are in place. It does not replace legal advice on your policies and contracts. See our Law 25 compliance page.
And after the audit, what happens?
You leave with a plan in three horizons. Many findings are corrected quickly and without a purchase, such as closing a forgotten remote access or putting email protection in place. The others become projects to be added to a three-year IT master plan, such as Microsoft 365 backup or Copilot governance, or handed to our managed IT services if you want it kept up to date continuously.

Have your environment audited

We agree on the scope together, we collect, we analyze, and we present the findings to you in person. The report belongs to you. Write to us to schedule a scoping meeting.