Cybersecurity audit: what to check first in an SME
Most incidents that hit SMEs do not come from sophisticated attacks. They come from a shared password, a former employee’s account still active, or a backup that was never tested. A useful audit starts there. Here are the five checks to do first, in order.
1. Accounts and passwords
Who has access to what? Are there shared generic accounts (“admin”, “accounting”)? Are former employees disabled? Is two-factor authentication on for e-mail and remote access? This single point closes the most used entry door.
2. Backups, and above all restores
A backup that has never been restored is not a backup. The audit checks frequency, location (an off-site or offline copy) and runs a real restore test. It is the difference between a bad day and a company at a standstill.
3. Updates
Workstations, servers, firewall, business software: what is not up to date is exploitable. The audit lists what is late and what can no longer be updated (and must therefore be isolated or replaced).
4. Remote access
Remote work, contractors, ERP access from outside: every open door must be known, protected (VPN, two factors) and logged. “Temporary” accesses that have lasted two years are common.
5. People
A short awareness session (spotting a fraud e-mail, reporting a doubt, not plugging in an unknown USB stick) reduces risk more than many tools. The audit measures the current level and proposes a short, repeated format.
And after the audit?
A good audit does not deliver an 80-page report. It delivers a list of actions ranked by impact and effort, with what can be done this week, this month and this quarter. The first actions often cost very little.
See our cybersecurity service for SMEs or request a first diagnosis.