Technicien Informatique ParisRepair · IT Support · Web — Paris 16e
Blog

IT Security Audit for Small Business: Full Guide

IT Security Audit for Small Business: Full Guide

Two questions land in my inbox constantly: "what actually is an IT audit?" and "how do I get a security audit done for my company?". I'm answering both here, because they're really the same thing seen from two angles. A proper audit isn't a sales pitch dressed up as a diagnosis, and it isn't a twenty-page report full of jargon nobody will ever reread. It's a precise inventory of what's actually running, an assessment of real risk — not hypothetical risk — and a report with priorities ranked from most urgent to least. Nothing more, nothing less. If a technician's audit ends with mostly a contract to sign rather than a clear set of findings, be wary: the audit and the sales pitch should stay two separate steps.

Illustration of a technician checking a tablet in front of a server rack in a data center
Illustration: an IT audit always starts with a precise inventory of what actually exists, not a list of generic recommendations.

Light IT audit vs. security audit: the real difference

A "light" IT audit is a general stocktake: how many machines, how old, which operating system, the state of backups, the internet connection, printers, software licences. I run this one often before a maintenance contract starts, just to know what we're working with. It answers the question "where does my equipment actually stand?"

A security audit goes further and focuses on what could be used against you: too many admin accounts, or ones that aren't protected properly, passwords shared on a sticky note on the monitor, a router nobody has touched since it was installed, personal devices connected to the company network without anyone signing off — the classic shadow IT problem. For a business with 5 to 20 people in Paris, I nearly always recommend doing both together: either one on its own leaves a blind spot, whether on the state of the hardware or on the open doors.

What I actually check

On-site or remote, I run through the same list every time, adjusted to the size of the business and whatever's already in place.

The inventory first: how many machines, laptops and desktops, and how old each one is. A computer over six years old often costs more in breakdowns and slowdowns than a replacement would — a calculation I break down in my article on repairing or replacing an old computer. I also note printers, the NAS or backup drive if one exists, and any work phones tied to the mailbox.

Next, Windows or macOS versions and the patch level actually installed: a machine that hasn't taken an update in eight months no longer has the fixes for vulnerabilities discovered since, even if the antivirus is running fine. I also check that automatic updates are genuinely turned on, and not just sitting "pending" for months with nobody noticing — something I cover in my guide on keeping a computer properly updated.

Admin accounts come next: how many people have day-to-day admin access on their own machine, and do they actually need it for their job? An admin account used just to check email or browse the web is a wide-open door the moment a bad link gets clicked by mistake.

Two-factor authentication coverage: which accounts have it, which don't — starting with the work mailbox, because that's the one account that protects everything else once an attacker gets into it, which I cover in my article on a hacked account and the first-hour checklist.

Backups next, and not just whether they exist but whether they can actually be restored: I run a real restore test on a file or folder during the audit, because a backup that's never been restored is still just a theory — the subject of my full guide to backing up important data.

Wifi and router settings: a default password that was never changed, no separate guest network — or one that's mixed in with the business network — router firmware that's never been updated since install day. I go through the exact settings in my article on securing a business wifi network.

Antivirus status: installed everywhere, up to date, not just "installed once and forgotten" — I've found licences that had expired two years earlier on machines everyone assumed were protected.

Shadow IT: cloud accounts a staff member opened without asking anyone — a personal Dropbox, a free Trello board with client data sitting in it — invisible to management but a real leak all the same.

And finally, licences: Windows, Office or Microsoft 365, line-of-business software. I check they're actually valid and that nobody's still paying for seats tied to machines that no longer exist.

The report — not a sales brochure

The report I hand over runs a few pages, not fifty. It lists what I found machine by machine, sorts each finding into three tiers — urgent, fix within the week; important, within the month; nice-to-have, whenever there's time — and explains the reasoning in a sentence or two, without unnecessary jargon. No overall "security score out of 100" that doesn't mean much in practice: what matters is the concrete list and the order to work through it. I also hand over a simple inventory table, useful even if you bring in someone else afterward to fix what the audit found.

Illustration of two hands clasped over a desk with two laptops showing data dashboards, a magnifying glass and printed reports
Illustration: the most useful part of the report isn't the list of problems, it's the order to work through them in.

How long it takes for a 5-to-20-person business

For a business with 5 to 10 machines, I budget half a day on-site or on a call to collect everything, plus two to three hours to write the report — expect 48 hours to get the finished document. Between 10 and 20 machines, that becomes a full day on-site, with the report delivered within 3 to 5 working days. What actually stretches the timeline isn't the number of machines but the number of different line-of-business apps I need to understand: an accounting office running a single piece of software takes less time than a workshop running five different tools with nobody around who can explain how they talk to each other. If a machine breaks down while you're still weighing up whether to book an audit, IT troubleshooting is still available the same day without waiting for the audit slot.

Realistic Paris pricing in 2026

For a light audit on 5 to 10 machines, expect €250 to €450. A deeper security audit on the same size of business runs closer to €450 to €750, because it needs longer checks: a real backup restore, going through accounts one by one, testing the wifi setup device by device. Past 15-20 machines I quote case by case rather than a fixed price, because the variety of software matters more to the time involved than the machine count does. These prices cover the collection work and the report; they don't include fixing what's found, which is billed separately afterward, often as part of ongoing small business IT maintenance if you'd rather have regular follow-up than a one-off visit. I work with established small businesses and solo freelancers alike — see my freelance IT services if you're after an audit sized for a single person.

What to do with the findings

Once you've got the report, the logical order is to tackle the urgent items first — usually unnecessary admin accounts and missing two-factor authentication, both cheap to fix and closing the most exposed doors. For the actual implementation of the protections themselves — firewall, automated backups, password policy — I cover the full approach in my article on protecting a business from cyberattacks, so I won't repeat all of it here. A standalone audit has an expiry date: in six months a new laptop will have arrived, an update will have been postponed, someone will have left the company without their access being revoked. Many of the small businesses I work with sign an IT maintenance contract right after the audit, specifically so those urgent items don't quietly become invisible again.

A free self-audit checklist, before you call anyone

If you want to check things yourself before paying for a full audit, here are the ten things I look at first, in order:

Illustration of a handwritten checklist on a clipboard, with a pen resting on it and a laptop beside it
Illustration: ten minutes with this list is often enough to spot the most urgent gaps.
  • Is every machine under six years old, and if not, is it still under warranty or worth repairing?
  • Is Windows or macOS on the latest supported major version, with automatic updates turned on?
  • How many accounts have permanent admin access on their own machine?
  • Is two-factor authentication turned on for the work mailbox?
  • Have you ever actually tested restoring a backup, or just confirmed that it "runs"?
  • Is the wifi router still using its factory-set password, printed on the underside?
  • Is there a separate guest wifi network, kept apart from the business network?
  • Is antivirus active and up to date on 100% of machines, licences included?
  • Do any personal cloud accounts — Dropbox, Trello, Gmail — hold company data?
  • Do all paid software licences still map to machines that are actually in use?

My free tools page also has a few utilities that can help you dig into some of these yourself, if you'd rather start alone before calling anyone in.

Frequently asked questions

Do I really need an IT audit if I've never had a problem?
Most small businesses call me after an incident rather than before, which almost always costs more than a preventive audit would have. No visible incident doesn't mean no risk: an account without two-factor authentication or a backup that's never been tested can sit fine for years, right up until it doesn't.

Does an audit replace a maintenance contract?
No, they're two different things. An audit is a snapshot at one point in time; maintenance is the ongoing follow-up that stops that snapshot going stale within a few months. Most small businesses end up doing both, one after the other, rather than choosing.

How long does a security audit stay valid?
I'd suggest redoing or updating it every 12 to 18 months, or sooner if you move offices, hire several people at once, or switch internet providers — those are the moments when the setup changes the most.

Do I need to be present during the audit?
Not for the whole visit, but someone needs to be reachable to answer questions about existing accounts and access. Without that, some checks — like real admin-account counts or paid licences — can't be verified properly.

Need a clear audit?

Get your setup checked by a technician in Paris

Inventory, access review, a real backup restore test, and a report with priorities: I can help by phone, WhatsApp, remote support, or on-site in Paris.

More articles

Back to the blog listing

See the latest published guides and blog posts.