Call NowFree Quote
Cybersecurity

What an IT Security Audit Covers - A Guide for Perth Businesses

Most Perth businesses discover their IT security gaps one of two ways: through a security audit, or through a breach. The audit is considerably less expensive. Here's what a thorough IT security audit covers - and what you should expect from the process.

What Is an IT Security Audit?

An IT security audit is a structured review of your technology environment to identify vulnerabilities, misconfigurations, and gaps in your security controls. Unlike a penetration test (which actively attempts to exploit weaknesses), a security audit is an assessment - it documents what exists, evaluates it against best practices, and produces a prioritised list of findings for remediation.

For most Perth SMBs, a security audit covers six main areas:

1. Identity and Access Management

Who has access to what - and do they still need it?

  • MFA coverage - is multi-factor authentication enforced for all users across Microsoft 365, email, VPN, and key business systems?
  • Admin account hygiene - do IT administrators use separate, dedicated admin accounts for privileged tasks, or do they use their everyday account?
  • Stale accounts - are there active accounts for former employees, contractors, or vendors who no longer work with the business?
  • Least privilege - do users have only the permissions they need for their role, or do most staff have admin rights?
  • Password policies - are strong passwords enforced, and is a business password manager in use?

Identity is the most common entry point for attackers. An audit almost always finds stale accounts and MFA gaps.

2. Endpoint Security

Every device that connects to your network is a potential entry point.

  • Endpoint protection coverage - does every device have up-to-date antivirus or EDR (endpoint detection and response) software?
  • Patch management - are Windows, macOS, and application updates being applied consistently and promptly?
  • Encryption - are laptop drives encrypted with BitLocker (Windows) or FileVault (macOS)? A stolen unencrypted laptop is a data breach.
  • BYOD controls - if staff use personal devices for work, are those devices managed or do they have uncontrolled access to business data?
  • Decommissioned devices - are old devices being wiped before disposal or reuse?

3. Network Security

Your network infrastructure controls what can communicate with what - and who can get in from outside.

  • Firewall configuration - is a business-grade firewall in place with appropriate rules? Is firmware up to date?
  • Network segmentation - are guest WiFi, staff WiFi, and management networks separated, or is everything on one flat network?
  • Remote access security - are VPN connections secured, and is RDP (Remote Desktop) exposed to the internet?
  • Open ports - are there unnecessary services exposed to the internet?
  • DNS filtering - is DNS-level filtering in place to block access to known malicious domains?

4. Data and Backup

What data do you hold, where is it, and can you recover it if lost?

  • Backup coverage - what data is backed up and what isn't? Most businesses are surprised to find gaps.
  • Backup testing - when was the last time a restore was actually tested? A backup that hasn't been tested may not work when needed.
  • Backup isolation - are backups stored separately from the primary environment? Ransomware routinely encrypts backup systems that are network-connected.
  • Retention - how many days or weeks of data can be recovered? For ransomware that sits dormant before activating, a 7-day backup window may not be enough.
  • Data classification - does the business know where sensitive data is stored, and is access to it appropriately restricted?

5. Email and Collaboration Security

Email remains the primary attack vector for phishing and business email compromise.

  • Email authentication - are SPF, DKIM, and DMARC records configured correctly? These prevent attackers from sending email that appears to come from your domain.
  • Anti-phishing controls - is Microsoft Defender for Office 365 (or equivalent) active with safe links and safe attachments enabled?
  • External email warnings - are emails from outside the organisation flagged so staff can identify potential phishing attempts?
  • Microsoft 365 security score - Microsoft provides a security score for your 365 tenant; an audit should include reviewing and improving it.

6. Policies and Awareness

Technology controls alone are not enough - humans remain the most targeted element.

  • Security awareness training - have staff received any training on phishing recognition and social engineering?
  • Acceptable use policy - is there a documented policy covering how staff should use business systems?
  • Incident response - does anyone know what to do if a breach is suspected? Is there a process for reporting and responding?
  • Vendor and third-party access - do external vendors or contractors have ongoing access to your systems that is not regularly reviewed?

What Happens After the Audit

A good security audit produces a findings report with each issue rated by severity - critical, high, medium, low. Critical and high findings should be addressed immediately; medium findings within 30–90 days; low findings as part of ongoing maintenance.

The audit should also produce a remediation plan that explains exactly what needs to be done to address each finding - not just a list of problems, but a clear path to fixing them.

For most Perth SMBs, a security audit takes one to two days of assessment work and produces actionable findings within a week. The cost is typically far less than the cost of a single incident.

Frequently Asked Questions

What is an IT security audit?

An IT security audit is a structured review of your technology environment to identify vulnerabilities, misconfigurations, and gaps in your security controls. Unlike a penetration test, which actively attempts to exploit weaknesses, an audit documents what exists, evaluates it against best practices, and produces a prioritised list of findings.

What does a security audit cover?

For most Perth SMBs, a security audit covers six main areas: identity and access management, endpoint security, network security, data and backup, email and collaboration security, and policies and staff awareness.

What happens after the audit?

A good audit produces a findings report rated by severity - critical, high, medium, low - along with a remediation plan explaining exactly what needs to be done to fix each issue, not just a list of problems.

How long does an IT security audit take?

For most Perth SMBs, a security audit takes one to two days of assessment work and produces actionable findings within a week.

We conduct IT security audits for Perth businesses - covering all six areas above, with a clear prioritised remediation plan.

IT Security Audit Service →

Book an IT security audit for your Perth business

Call 0433 087 091 - we'll assess your environment, identify vulnerabilities, and give you a prioritised remediation plan in plain English.

Book a Security Audit

For related reading, see our guides to Phishing & Staff Security Training for Perth Businesses, How Often Should Staff Cyber Security Training Happen?, and DNS Filtering for Perth Businesses.

Share this article