What it is
A review of your identities, your devices, your remote accesses, your backups and your practices, followed by a report that names the risks and fixes them in a defined order.
Cybersecurity
A cybersecurity audit answers one simple question: what, today, could stop your organization or expose your data. This page describes exactly what is examined, the document you receive at the end, and what happens next.
An audit is not a software report exported to PDF. It is a review carried out by a person, covering your identities, your devices, your remote accesses, your backups and your practices, that leads to a report naming the risks and a list of fixes ranked by what would hurt your organization most.
In brief
An audit is not a software report exported to PDF. It is a review carried out by a person, that leads to a list of fixes ranked by what would hurt you most.
A review of your identities, your devices, your remote accesses, your backups and your practices, followed by a report that names the risks and fixes them in a defined order.
A small business that has never had its environment reviewed, that is changing IT providers, that has to answer a security questionnaire from a client or insurer, or that has just been through an incident.
You stop guessing. You know what is in place, what is missing, what doing nothing would cost, and where to start Monday morning.
Understanding
Most small businesses know they have weaknesses, but do not know which ones matter. The audit settles that question with facts rather than impressions. It answers three things: what actually exists in your environment, what is exposed, and what would keep you from getting back up after an incident.
There is a real difference between an audit and a penetration test. A penetration test looks for a specific flaw to get in. The audit paints the complete picture and ranks it: it uncovers the account of a former employee still active, the backup that has never been restored, the forgotten remote access on an old server. For a small business, it is almost always the audit that delivers the most value first.
An audit is also what lets you answer honestly when a client, an insurer or a customer asks you to demonstrate your practices. Without a document, the answer relies on the memory of whoever manages the IT.
The scope
The review covers six areas. They are verified in your actual environment, not from a questionnaire the client filled out.
What is checked. Active accounts and orphan accounts, admin rights, multi-factor authentication, service accounts, shared accounts, password policy, external supplier accesses.
What we find most often. Former employees’ accounts still active, and admin rights granted once to help someone out, never removed.
What is checked. Real inventory of the fleet, systems still supported by their vendor, patch status, disk encryption, protection installed and actually running, unauthorized software.
What we find most often. Machines missing from the official inventory, and patches behind on third-party software rather than on Windows.
What is checked. What is published on the Internet, firewall rules, remote accesses, Wi-Fi and guest network, segmentation, network gear whose firmware is no longer updated.
What we find most often. A remote access left open for a project that ended long ago.
What is checked. Where the data lives, who can read it, what is backed up, how often, where the copies are kept, whether one copy is out of an attacker’s reach, and when a restore was last rehearsed.
What we find most often. Backups that have been running for years without a single restore ever being tested.
What is checked. Microsoft 365 or Google Workspace configuration, SPF, DKIM and DMARC, mailbox rules, external file shares, third-party apps allowed to read your data.
What we find most often. Public sharing links created long ago and never expired, and a DMARC that is missing or ineffective.
What is checked. Onboarding and offboarding procedure, password management, incident plan, the register required by Law 25, employee awareness, dependence on a single person.
What we find most often. No written procedure, and one person who holds the critical accesses in their head.
How it unfolds
The audit unfolds in four steps. Your operations are not interrupted: the collection is done in read mode, with no change to your environment.
The deliverable
The report is written to be read by leadership, not only by a technical person. It contains the following.
What comes next
The audit is a starting point. The next step is our cybersecurity services managed year-round, ransomware protection and Law 25 compliance. Findings that turn into projects belong in a three-year IT plan.
This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it. See Trois-Rivières, the Mauricie, Montreal and Quebec City.
Further reading: vulnerability management and CVEs, your data on the dark web and choosing a firewall.
Questions and answers
We agree on the scope together, we collect, we analyze, and we present the findings to you in person. The report belongs to you. Write to us to schedule a scoping meeting.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.