Skip to content
SOS Informatique Computer repair in Lyon - Individuals and businesses

IT security audit in Lyon

A useful audit does not produce a forty-page report. It produces a list of things to do, ranked by importance.

Many security audits end in a document nobody reads, because it was written to prove the seriousness of its author rather than to be acted on. Our approach is the opposite: an understandable review, and an action plan you can carry out, including without us.

What we look at

The workstations. Systems still supported or abandoned, updates applied, antivirus active and up to date, encryption on laptops, user rights. We also note the machines whose hardware can no longer receive fixes - a point that has become decisive since Windows 10 support ended.

Accounts and access. Who can reach what, with which rights. Accounts shared between several people, former employees' accounts never disabled, too many administrators. Two-factor authentication, present or absent, and on which services.

Email. It is the main way in. Existing automatic forwarding rules, authorized third-party applications, a history of unusual sign-ins, and how strong the passwords are.

Backups. What is backed up, how often, where, and since when it has actually been working. We test a restore: it is the only check that has any value.

The network. Router, administration passwords left at their defaults, Wi-Fi and its encryption, a guest network separate or not, remote access open to the internet. See securing a business network.

Servers and NAS units, where there are any: rights on the shares, firmware updates, any exposure to the internet.

What we find most often

Three findings come up in almost every audit we run. A backup that stopped running weeks or months ago, without anyone noticing - the most frequent and the most serious. Former colleagues' access still active. And remote access open to the internet with a simple password, often set up in a hurry to help someone out, then forgotten.

What you receive

A short document, in plain language, in three parts.

What is fine. Yes, that is in there too. It is useful: it avoids redoing what is already in place, and gives you a realistic measure of where you stand.

What needs correcting quickly, with the concrete risk attached to each point - not a technical note, but what could happen and what it would cost. This part is short: generally three to six points.

What is worth improving, without urgency, in order of priority.

Each point states whether it is free or paid, and roughly how long it takes to put in place. You can hand the corrections to whoever you like, including your usual provider.

What we do not do

Let us be clear about the scope. We do not carry out penetration testing, which is a different specialty and aimed at organizations of another size. We do not issue certification. And we are not lawyers: we flag what falls under personal data protection, but we do not stand in for specialist advice.

What we do is identify the gaps that genuinely expose a small organization, and make them fixable.

How long it takes

For an organization of three to fifteen machines, allow half a day on site, plus writing time. We need access to the machines and a conversation with whoever usually looks after the IT - even if it is not their job, which is the case in most small businesses.

The findings are presented in person, not only in writing. It is the most useful moment of the exercise: the questions raised there often reveal practices no technical examination would have shown.

Et ensuite

You are under no obligation. Many of our customers handle the free points themselves and leave the rest to us. Others ask us to implement everything. Some do nothing in the first year, then call us back after an incident at a colleague's firm - which is common, and human.

An audit repeated after a year or two makes sense: setups change, people move on, and backups stop silently. See small business IT maintenance and small business security.

Frequently asked questions about this service

Is an audit worthwhile for a five-person business?

Yes, and it is often more revealing: in small organizations nobody has IT in their remit, and the weak points build up without anyone seeing them.

Does work have to stop during the audit?

No. Most of it is done by observation and by looking at configurations. Only the restore test needs a little availability, and it can be scheduled.

Is the report understandable without technical skills?

That is precisely the aim. Each point states the concrete risk and what the fix costs. A report you cannot use serves no purpose.

Can we then have you carry out the corrections?

Yes, but nothing obliges you to. The document is written to be usable by any provider, including the one already working with you.

Can't find your question? It may be in our full FAQ.

Going further

Everything worth knowing before you hand over your equipment.

Want to know where you really stand?

A short, usable review, with priorities ranked by real risk.

Contact Us