We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

+33 1 70 83 20 91
Phone
Security audit

IT Security Audit for Small and Medium-Sized Businesses

You know that your information system has weaknesses. You don't know what they are, or where to start. An audit answers both of these questions, in this order: a dated assessment of the current state of affairs, followed by a prioritized action plan.

The 30-minute assessment is free and requires no commitment.

Technical and OrganizationalReport and Action PlanIncludes NIS2 componentOn-site or remotely
The Scope

What the Audit Covers

Two scopes addressed together, plus the compliance component when the NIS2 Directive applies to your business.

Scope
Technical
Workstations, servers, network, directory

Asset and flow mapping, vulnerability scanning, workstation configuration and hardening, Active Directory and Entra ID audits, backups and restore testing, external exposure, and network segmentation.

Compliance
NIS2
When the directive applies

What the text requires, what you already have, and what is missing. The action plan then distinguishes between security measures and compliance measures, which are not funded at the same rate.

The exact scope is determined with you during the scoping phase: we focus on the most critical assets rather than skimming over everything. The price then depends on five factors: the number of workstations and servers, whether there is a directory service to audit, whether penetration testing is included, whether the audit is conducted on-site or remotely, and whether the NIS2 component is added. For details on the steps involved and the checklist we use, read about our IT security audit methodology.

Our cybersecurity expertise in the broadest sense, from hardening to monitoring: cybersecurity and compliance.

The Diagnosis

Thirty minutes to find out where you stand

Before planning a comprehensive audit, we review four key points with you. These are usually sufficient to determine whether your situation requires urgent corrective action or a thorough audit.

01

We're looking at four points

Your CIS compliance score, the presence of the SMBv1 protocol, the number of accounts with administrator privileges, and the actual status of your backups.

02

You can see your actual level

In thirty minutes, with no obligation. You'll walk away with an answer, even if you decide not to proceed.

03

You decide what happens next

Either the assessment is sufficient, and you can address the identified issues, or it warrants a full audit, in which case we’ll define the scope together. We’ll provide a quote within 48 hours.

The Method

How Does an Audit Work?

1

Scope and Boundaries

What we audit, what we don't audit, and why. We work with you to define the scope before any work begins, based on your most critical assets.

2

Mapping of Assets and Flows

You can't secure what you don't know you have. Workstations, servers, network equipment, exposed applications, accounts, and directories.

3

Vulnerability Scans and Testing

Vulnerability analysis across the entire scope, and penetration testing when warranted by the scope, conducted during a time window agreed upon in advance so as not to disrupt your operations.

4

Policy and Access Audit

Organizational aspects: privileged accounts, passwords and multi-factor authentication, onboarding and offboarding procedures, access granted to contractors, and a disaster recovery plan. User vigilance can be assessed through a simulated phishing campaign at any time.

5

Analysis, Prioritization, and Reporting

A cross-reference of technical criticality and business impact, a risk matrix, followed by the report and the prioritized action plan. The report is yours.

What You Get

What You'll Receive

  • A dated assessment of your current security status.
  • The list of discovered vulnerabilities, along with their severity ratings.
  • The risk matrix, which plots probability against impact.
  • The prioritized action plan, item by item, ready for implementation by your teams, ours, or a third party.
  • NIS2 Compliance: When Your Company Falls Within the Scope of the Directive.
The Comparison

An audit is not a penetration test

Confusion is common and costly, because people buy one thing thinking they're getting the other.

CriterionPenetration TestSecurity audit
Question askedCan we go in that specific way?Where are my weaknesses, and which one should I address first?
ScopeA Targeted ApproachTechnical and Organizational
ResultEvidence of ExploitationAn order of priority
Covers backups and proceduresNoYes
Recommended frequencyAfter each major changeOnce a year
What He Doesn't SayNothing about your organizationNo real resistance to an attack

The two complement each other. The audit tells you where to look; the penetration test checks to see if the door gives way. Starting with a penetration test when you've never done an audit is like testing a lock without knowing how many doors you have.

For the penetration test itself, see our page on penetration testing, phishing campaigns, and code audits.

Key Points

IT Systems by the Numbers

Since 2010
16 years in business
44 employees
in-house teams in France
300 active customers
Small and Medium-Sized Enterprises (SMEs), Mid-Sized Companies, and Large Corporations
33 Microsoft certifications
active as of September 4, 2026
On-site or Remote Audits
throughout France
ISO 27001
certification process underway
FAQ

Frequently asked questions

How long does an IT security audit take?

The duration depends on the scope defined during the initial assessment: the number of workstations and servers, whether there is a directory to be audited, and whether penetration tests are included. The 30-minute assessment, on the other hand, is conducted immediately and with no obligation.

Should operations be suspended during the audit?

No. The data collection and analysis phases are conducted alongside your business operations. Only certain internal penetration tests require a time window agreed upon in advance.

Do you provide services outside the Île-de-France region?

Yes. Our teams are based in the Île-de-France region, and we conduct on-site or remote audits throughout France. We have four locations: Paris (Malakoff), Lyon, Annecy, and Bordeaux.

What happens after the audit?

You have a prioritized action plan. You can implement it with your teams, entrust all or part of it to us, or have it carried out by a third party. The choice is yours.

How often should an audit be conducted?

One audit per year, to be conducted after any major change: migration, merger, opening of a new site, or change in IT service provider.

Does the audit cover NIS2 compliance?

Yes, when your company falls within the scope of the directive. The compliance component is included in the report and highlighted in the action plan. To understand the text before taking any action, read our practical guide to NIS2 compliance.