IT Audit
for SMEs
A comprehensive assessment of your IT infrastructure in 1 to 2 days. Network, security, backups, compliance — we identify vulnerabilities and deliver a prioritised remediation plan.
An IT audit can review backups, firewall rules, accounts, workstations, servers and compliance evidence. The selected perimeter, tests, deliverables and price are confirmed in writing.
Why audit your SME's IT infrastructure?
Most SMEs have no real visibility into the actual state of their IT infrastructure. The server "works" but nobody has verified its backups in months. The firewall is installed but still running default rules. Active Directory accounts for employees who left two years ago are still active.
An IT audit exposes these blind spots before they become incidents. It is also the mandatory first step if you are considering managed services, a cloud migration, or NIS2/GDPR compliance.
ANSSI recommends an IT security audit at least once a year for every organisation, regardless of size. For regulated sectors (healthcare, finance), it is a legal requirement.

The 30 points we verify
Network infrastructure
- —Network mapping (switches, routers, Wi-Fi)
- —VLAN segmentation
- —Firewall: rules, firmware, logs
- —Bandwidth and latency
- —Remote access (VPN, RDP)
Workstations
- —Hardware and software inventory
- —OS versions and security patches
- —Antivirus / EDR active and up to date
- —Disk encryption (BitLocker)
- —Software licence compliance
Servers
- —Hardware health (RAID, power supply, cooling)
- —OS versions and patches
- —Active Directory: GPOs, stale accounts
- —Performance (CPU, RAM, disk)
- —SSL/TLS certificates
Backup
- —3-2-1 strategy in place
- —Frequency and retention policy
- —Backup encryption
- —Recent restore test
- —Off-site / cloud backup
Security
- —Password policy
- —MFA enabled on critical accounts
- —Access rights: least privilege principle
- —User awareness training
- —Incident response plan
Compliance
- —GDPR: processing register
- —Sub-processor contracts (DPA)
- —NIS2: eligibility verified
- —DPO documentation up to date
- —Access logging
How does an ECLAUD IT audit work?
Initial contact
A phone call to understand your context, your priorities and to schedule the on-site visit.
On-site visit
Half a day to a full day: automated inventory, network analysis, backup verification, security tests. Non-intrusive, no service interruption.
Analysis and report
Report writing including network mapping, identified vulnerabilities and a remediation plan prioritised by criticality.
Debrief
Presentation of the report in person or via video call. Discussion of priorities, budget and remediation timeline.
What the audit report contains
Network map
Diagram of your infrastructure: equipment, IP addresses, VLANs, Wi-Fi access points, internet connections.
Hardware & software inventory
Complete list of workstations, servers, printers, installed software, versions and licences.
Identified vulnerabilities
Each finding rated by criticality (critical, high, medium, low) with a description of the potential impact.
Remediation plan
Prioritised corrective actions with budget estimates and a recommended timeline. Quick wins identified.
How much does an IT audit cost?
| Type | Duration | Price |
|---|---|---|
| ECLAUD IT initial audit | Defined after scope review | Written proposal |
| In-depth audit | Defined after scope review | Written proposal |
| Penetration test (pentest) | Defined after scope review | Written proposal |
FAQ — IT Audit for SMEs
How much does an IT audit cost for an SME?
Audit scope, duration, deliverables and price depend on the infrastructure and requested depth. The proposal states whether mapping, backup review, security review, penetration testing or compliance work is included.
How long does an IT audit take?
Duration depends on the number of sites and assets, access, testing method and report depth. The schedule and any production constraints are confirmed before the audit.
What does the ECLAUD IT audit report include?
A report may include mapping, inventory, backup status, identified vulnerabilities, compliance observations and a prioritised remediation plan. Exact deliverables and rating method are listed in the proposal.
How often should an IT infrastructure be audited?
Frequency depends on risk, changes and applicable obligations. At ECLAUD IT, monitoring and audits are included only when they appear in the relevant contract.
Is the audit disruptive to business operations?
The method and operational impact depend on the agreed tests. Passive checks, authenticated scans and penetration tests have different risks; access, maintenance windows and safeguards are documented before work begins.
Do you really know
where your IT stands?
Discuss the assessment perimeter, method, deliverables, schedule and price before the audit begins.