IT Security Consulting: Why an Audit Report Isn't Enough
An IT security audit takes two to four weeks. It produces an assessment, a list of vulnerabilities ranked by severity, and an action plan. And then, often, the firm that conducted the audit walks away. The question remains: who will fix the vulnerabilities, monitor the system on a daily basis, and verify in six months that nothing has regressed?
This is where IT security consulting takes on a different character depending on who is providing it. A consulting firm delivers a report. A managed services provider stays on after the report is issued because the infrastructure it audits is also the one it operates.
What the Threat Means for an SME or Mid-Sized Company Today
The numbers have changed—and not for the better. According to the 2025 Cyber Threat Overview published by ANSSI in March 2026, microbusinesses, small and medium-sized enterprises (SMEs), and mid-sized companies now account for 48% of identified ransomware victims in France, up from 37% the previous year. Another statistic from the agency, one that is even more concerning in substance: 74% of these organizations remain below the “Essential” security level recommended by the agency.
This isn't a random choice of targets. It's a cost-benefit analysis for the attacker: data that's worth targeting, defenses that aren't keeping up. The CESIN 2025–2026 Barometer, conducted among 397 CISOs and cybersecurity directors, ranks phishing as the top attack vector cited (55%), ahead of the exploitation of technical vulnerabilities (41%) and attacks via a third-party service provider (35%). And among companies affected in 2025, 81% report a direct impact on their business: production shutdowns, loss of revenue, and damage to their reputation.
An audit reveals where the vulnerabilities lie. It doesn't fix them, and it doesn't monitor anything after the results are reported. For that, you need someone to stay on—that's the whole point of a managed SOC, which extends the audit through continuous monitoring rather than a one-time snapshot.
The Human Factor: Always at the Forefront
According to the CESIN 2026 Barometer, 36% of reported data breaches stem from human error or misconfiguration: a clicked link, a reused password, or a former employee’s account that was never deactivated. Phishing campaigns are increasingly relying on AI-generated content to mimic credible internal communications, making them harder to spot than they were two years ago.
Two measures can reduce this risk without adding to the teams’ daily workload: regular phishing simulations and a periodic review of access rights. Nothing spectacular—it’s a matter of maintaining discipline over the long term, not requiring any additional tools.
The regulatory framework is having an increasing impact on decision-making
There are currently four pieces of legislation that outline companies' obligations, to varying degrees depending on the sector and company size:
- GDPR: Regulates the collection and retention of personal data; any breach must be reported to the CNIL within 72 hours.
- NIS2: Extends security obligations to a growing number of sectors—energy, healthcare, digital, and transportation—with strengthened notification requirements. Our NIS2 practical guide details the technical measures that need to be implemented.
- DORA: requires financial institutions to conduct regular operational resilience tests.
- ISO 27001: remains a benchmark for governance, useful for reassuring clients and partners during a request for proposals.
Noncompliance is no longer just an abstract legal risk. It can derail a contract or slow down a client audit, as major clients are increasingly requiring compliance as a business prerequisite before signing.
Why Separating Auditing and Oversight Is a False Good Idea
This is the point we come back to most often with our clients. Many arrive with an audit report already in hand—sometimes excellent, sometimes too generic—and a simple question: What now?
The problem with a one-off audit is that it captures a snapshot at a specific point in time. Three months later, a new workstation may have been deployed, access may have been granted to an external vendor, or an update may not have been applied. The report doesn’t account for that. At IT Systèmes, an audit is never a standalone service: it’s integrated into our managed services, which means that the same teams that identify a vulnerability are the ones who fix it and then monitor to ensure it doesn’t recur. Our audit methodology details the seven steps of this initial assessment.
Specifically, this support covers four areas:
Risk audit and mapping, using read-only tools and scheduled out-of-production tests to avoid disrupting operations during the analysis—infrastructure, networks, cloud, business processes, and, for critical applications, penetration tests and simulated phishing campaigns.
Continuous monitoring, powered by our SOC, to reduce the time between an alert and its resolution. A compromised account detected within minutes rarely costs more than a password reset. The same account detected three weeks later may have been used to exfiltrate customer data.
Access Management: Personal accounts, strict separation between standard user profiles and administrator accounts, two-factor authentication for remote access and email.
Encrypted, replicated, and off-site backups to ensure a quick recovery after an incident and to document compliance during an audit.
For an overview of this scope, our Cybersecurity and Compliance page provides details on our full range of services.
How to Evaluate IT Security Support
A service provider that offers solutions before auditing your information system deserves to be questioned. A serious approach always begins with an assessment, followed by a roadmap and operational follow-up—not a list of products to install simply because they’re in the catalog.
Frequency: every 12 to 18 months in sensitive sectors (healthcare, finance, manufacturing, legal), and every 24 to 36 months elsewhere, provided that ongoing oversight takes over between reviews; otherwise, the interval is too long to remain relevant. Certain events require an immediate audit: cloud migration, a merger, or the launch of a new website accessible via the Internet.
Frequently Asked Questions
Is IT security consulting the same thing as an audit? No. An audit is a one-time assessment—a snapshot at a specific point in time. IT security consulting, as we understand it, also covers what happens afterward: addressing identified vulnerabilities, ongoing monitoring, and updating the security posture as infrastructure changes.
What are the pillars of IT security consulting? Seven complementary areas: governance, risk analysis and compliance, security architecture, monitoring and SOC, business continuity, incident management, and employee awareness. A thorough consulting approach assesses the maturity level in each of these areas before establishing a roadmap.
How often should an information system be audited? Every 12 to 18 months in sensitive sectors, and every 24 to 36 months elsewhere if the audit is supplemented by continuous monitoring. A cloud migration, a merger, or a new Internet-facing service warrants an early audit, as it is precisely at these times that the attack surface expands.
How does IT Systèmes help an SME meet its regulatory obligations? First, we map out sensitive data, processing activities, and data flows; then we identify the applicable regulations—GDPR, NIS2, and DORA—depending on the business’s activities. This step reveals the most critical gaps. Next comes a concrete action plan, which is monitored over the long term by the same teams that manage the infrastructure on a daily basis, rather than being treated as a one-time exercise.



