The moments when a company asks for an IT audit are surprisingly similar: the person who “knew everything” has left and nobody has the passwords; a big client has sent a security questionnaire that must be completed by Friday; there has been an incident — a virus, an invoice paid into the wrong account, a vanished file; or, quite simply, the owner realises they are paying monthly for things they cannot name. All have the same root: nobody knows any more exactly what exists and what state it is in.
An IT audit solves exactly that: a complete and honest photograph of the real state of affairs — equipment, software, security, backup — with the risks ranked by importance. This article shows you what it checks point by point, how it runs, how long it usually takes and, perhaps most usefully, how to tell a serious report from a sales offer in disguise.
What an IT audit is — and what it is not
An IT audit is a systematic assessment, done for you, not against you: it is not an inspection, it does not look for culprits and it does not end in fines. Its result is information you then use as you wish — with your current provider, with another one or with your own in-house people.
What it is not: a one-hour visit followed by a product offer. If the free “audit” ends with a shopping list from the same company that carried it out, you have received a sale, not an assessment. The independence of the conclusions is precisely the product you are paying for.
What it checks, point by point
The inventory: what actually exists
All the equipment (computers, servers, network equipment, printers), with age, condition and warranties, plus all the software in use — including what employees installed on their own initiative, which management knows nothing about. In 2026, the inventory also has a hot deadline: machines still on Windows 10 show up as a dated risk, because the Extended Security Updates (ESU) end firmly on 13 October 2026, with no continuation.
Licences: what you use and what you pay
The legal face: software used without a valid licence — a risk at any inspection. And the financial face: subscriptions paid for people who have left, duplicate tools, oversized licences. It is not unusual for the savings found here to cover a serious part of the audit's cost.
Security: open doors
Shared or weak passwords, no two-step authentication on the important accounts, uninstalled security updates, access rights left over from departed employees, network equipment on factory settings. You do not need a sophisticated attack to get hurt — as a rule, one of these doors is enough. The answers to the usual questions in this area are gathered in the frequently asked questions about IT security.
Backup: the restore test
The question is not “do you have backups?” — almost everyone says yes — but “when did you last restore something from them?”. An untested backup is a hope, not a protective measure. The audit checks what gets copied, where, how often and whether the restore actually works.
The network and compliance
How the network is organised, who has access to what, whether visitors join the same wifi as the accounts department. Plus the obligations that come from outside: 2026 is the year the NIS2 adjustment period ended and inspections begin — and a small company, although directly exempt from the law's obligations, can be bound contractually if it is a supplier to a company that falls under it. The security questionnaire from the big client comes from exactly there, and the audit prepares you to answer it with facts.
How long it takes
For a company of 10–100 employees, with one or two sites, we are as a rule talking about days, not months: a few days of collection and checks, then the writing of the report — as a guide, one to two weeks from start to the presentation of the conclusions, confirmed at quotation, once the assessor learns how many locations, servers and applications you have. What stretches things out is almost always the same factor: missing documentation and access — unknown passwords, contracts that can no longer be found, the former administrator nowhere to be reached. Which, in itself, is already an audit finding. As an internal planning reference: your people will spend only a few hours in total — the interviews are short, and the rest of the work does not touch them.
How it runs, step by step
- The initial discussion. What hurts, what contracts and obligations you have, how the company is organised. Access is also agreed — usually an administration account and your written consent.
- Collection. Automated tools inventory the equipment and software, and a few short interviews with the key people clarify how work actually gets done — not how the procedures say it does.
- The manual checks. The backup restore test, the review of access rights, the check of settings on the important equipment.
- The report and the presentation. The findings, in language management understands, with a question-and-answer session. The company's activity does not stop during any of this — the audit is done alongside the work, not instead of it.
What you get at the end
A good report has four parts: the complete inventory — the first true list of what the company owns, valuable for accounting and insurance too; the prioritised risk register — each problem with its severity, split into “urgent”, “important” and “to plan”; recommendations with estimated effort — what you can fix yourself, at low cost, and what needs outside help; and a 6–12 month plan, in the order that removes the most risk per leu spent.
The signs of a quality report: it is written in your language, not in jargon; every risk has its consequence explained in business terms (“if X breaks, you cannot invoice until Thursday”); and it honestly separates the critical from the cosmetic. The bad sign you have already guessed: every “risk” is solved by a product sold by the report's author.
The report often also answers a question you did not ask: who should look after all this from now on? If the volume uncovered exceeds what the company can carry right now, you have the exact figures for the calculation between an in-house IT employee and outsourcing.
The next step
If the text above ticked even one symptom for you — passwords held by a single person, an untested backup, a client questionnaire with no answer — do not wait for the incident that turns the audit from an option into an emergency. Ask for an assessment discussion and a sample report, so you can see exactly what you would receive; Neoxis carries out such audits as part of its IT consulting services.