Cybersecurity audit · 8 min · 29 Sep 2026

Cybersecurity audit: what does it look like and what should it cover?

A useful audit should not end with a list of technical findings. It should explain risk, priorities, dependencies and a realistic remediation plan for IT and management.

A cybersecurity audit is a structured assessment of how an organisation protects systems, data and operational continuity. The scope may be technical, organisational or combined. It is most useful when infrastructure findings are tied back to business processes.

1. Inventory and scope

First establish what is being protected: locations, networks, servers, endpoints, cloud systems, OT devices, internet-facing applications, backups and critical suppliers. Without that map, an audit can spend time on low-impact assets while overlooking a business-critical system.

2. Configuration and exposure

The audit should review areas such as patching, network segmentation, privileges, MFA, email security, endpoint protection, remote access, firewall rules, internet-facing services and privileged-account management.

3. Backup and recovery

Having backups does not prove that data can be restored. The review should cover backup isolation, retention, ransomware resilience, ownership of the recovery process and the results of actual restore tests.

4. Processes and accountability

Many weaknesses are not purely technical. They arise because nobody has a clear answer to questions such as who makes decisions during an incident, who contacts suppliers, who has emergency access and where current documentation is stored.

5. A report that can be acted on

Findings should be prioritised by risk and urgency. Management needs a concise view of business impact and priorities, while administrators need technical detail and remediation guidance.

A useful audit outcome: a 30-, 90- and 180-day action plan, named owners and a clear distinction between critical fixes, important improvements and longer-term development.

Audit vs penetration test

An audit evaluates the broader security system. A penetration test is a more focused attempt to exploit vulnerabilities within an agreed scope. The two activities complement each other, but they are not interchangeable.

Want to apply this to your own environment?

We can start with a short conversation and identify the areas worth checking first.

Book a call