SME Cybersecurity · Updated

IT security audit
in Reunion Island — assess your risks

Is your SME sufficiently protected? An audit can examine an agreed scope, evidence and authorised tests. Method, frameworks, service area and deliverables must be confirmed in the proposal.

Summary

An IT security audit can identify vulnerabilities, assess risks and produce a prioritised action plan. Its scope, duration and deliverables are confirmed in the proposal; the methodology can draw on the ANSSI IT hygiene measures.

01 — The reality

Why an IT security audit is essential

The figures are unambiguous. In 2023, 58% of ransomware victims in France were micro-businesses and SMEs (ANSSI). In 2025, ANSSI recorded a further 128 ransomware compromises, with increasingly sophisticated strains: Qilin (21% of cases), Akira (9%), LockBit 3.0 (5%).

And yet, 48% of French SMEs have no formalised cybersecurity strategy (Konica Minolta 2025). Most business owners think "it only happens to large corporations". The opposite is true: attackers target SMEs precisely because they are less protected, not less interesting.

The problem is not that SMEs are negligent — it is that they do not know where their vulnerabilities lie. An admin password shared for 3 years. A server that has not been patched for 14 months. A firewall whose rules have never been reviewed. These vulnerabilities exist in almost every SME we audit.

"60% of SMEs that suffer a major cyberattack close within 6 months. The average cost of an incident for an SME: €50,000 to €100,000."ANSSI / RESCO

An IT security audit is the first step. Not the most spectacular, but the most important: you cannot protect what you do not know. Before deploying a Fortinet firewall or an EDR, you need to know what is vulnerable in your IT estate.

For a complete view of our cybersecurity approach, visit our SME cybersecurity in Reunion Island page.

02 — Methodology

Our 5-step audit methodology

Our approach is based on the ANSSI IT hygiene guide (42 measures) and the "Cybersecurity for micro-businesses and SMEs in 13 questions" guide. Each audit is tailored to the size and sector of your company.

01

IT estate mapping

Full inventory of your infrastructure: workstations, servers, network equipment, applications, remote access, cloud. You can only protect what you know.

02

Vulnerability scanning

Automated analysis of your network and systems to identify known vulnerabilities: outdated software, open ports, dangerous configurations, expired certificates.

03

Targeted penetration tests

Simulation of real attacks on your entry points: simulated phishing, unauthorised access attempts, privilege escalation. We test the way an attacker would.

04

Configuration review

Review of Active Directory policies, access rights, firewall rules, backups, antivirus, MFA. Comparison against the ANSSI 42-measure reference framework.

05

Report and action plan

Detailed deliverable: prioritised risk matrix, ranked recommendations (quick wins vs projects), budget estimate, remediation schedule.

03 — Concrete results

What the audit reveals — concrete examples

After dozens of audits carried out for SMEs in Reunion Island and mainland France, the same vulnerabilities recur consistently. Here is what we find in the majority of companies we audit.

Weak or shared passwords

Weak, reused or shared passwords increase the risk of privileged-account compromise.

Source: Microsoft Digital Defense Report 2025

Unpatched servers and workstations

Critical security updates pending for 6, 12, sometimes 18 months. Each missing patch is an open door — strains like Qilin or Akira exploit these known vulnerabilities.

Source: ANSSI — Panorama of the cyber threat 2025

Backups never tested

An untested backup does not prove that data can be restored after an incident. Restoration tests and an isolated copy are controls to document.

Source: ANSSI — 13-question guide for micro-businesses/SMEs

Unsecured remote access

Remote desktop (RDP) exposed to the internet, VPN without MFA, former employee accounts still active. All entry vectors for an attacker.

Source: ANSSI — 13-question guide for micro-businesses/SMEs

These are the vulnerabilities that ransomware exploits first. An audit makes it possible to identify and fix them before they are exploited. To understand how to concretely protect yourself against ransomware, visit our dedicated SME ransomware protection page.

IT security audit — cybersecurity verification checklist for SMEs
The IT security audit reviews every component of your IT estate against the ANSSI reference framework.
04 — Professional tools

Our audit tools — technologies used

We use industry-standard tools in the cybersecurity field — the same ones used by certified auditors and ANSSI teams. No opaque "in-house software" — proven tools whose results are verifiable.

Vulnerability scanning

Nessus / OpenVAS — industry-standard network vulnerability scanners. Detection of known vulnerabilities (CVE), dangerous configurations, outdated software. Detailed reports with criticality scores.

Web penetration testing

Burp Suite — web application security testing tool. Detection of SQL injections, XSS, authentication vulnerabilities. Used to audit your customer portals, intranets and business applications exposed to the internet.

Network analysis

Wireshark — network protocol analyser. Detects unencrypted traffic, suspicious communications, unknown devices on your network. Essential for post-incident analysis.

Active Directory audit

PingCastle / BloodHound — tools specialised in Active Directory auditing. Detection of attack paths, accounts with excessive privileges, dangerous GPO configurations.

All tools used are documented in the audit report. We explain what each tool tested and what it found — no jargon without context.

05 — ANSSI reference framework

ANSSI checklist — the 42 IT hygiene measures

ANSSI publishes a guide of 42 IT hygiene measures that every company should apply. Our audit assesses your compliance with each of these measures. Here are the main categories.

Know your IT estate

Hardware/software inventory, network mapping, list of access rights and permissions, identification of sensitive data

Authentication & access

Strong password policy, MFA on sensitive access, removal of unused accounts, least-privilege principle

Backups

Regular backups (3-2-1 rule), restoration tests, air-gapped backups (anti-ransomware), encryption of backed-up data

Updates

Patching policy, automatic updates enabled, vulnerability monitoring, replacement of obsolete systems (Windows 7, Server 2012...)

Firewall & network

Correctly configured firewall, network segmentation, secure Wi-Fi (WPA3), guest/production network isolation

Awareness

Phishing training for staff, signed IT charter, incident alert procedure, simulation exercises

In addition to the ANSSI framework, we verify your GDPR compliance — a point often overlooked in purely technical audits. Personal data protection, retention periods, data subject rights: these are also IT security topics. To find out more, visit our GDPR for SMEs in Reunion Island page.

IT security — digital lock symbolising information system protection
Securing your IT estate starts with a rigorous audit — every vulnerability identified is an attack prevented.
06 — Pricing

How much does an IT security audit cost?

PlanDurationScopeIndicative price
Flash auditAs scoped in the proposalMapping, vulnerability scan, summary reportBy quote
Full auditAs scoped in the proposalScan + pentest + organisational audit + detailed reportBy quote
Quarterly follow-upAs set in the contractRe-scan, remediation tracking, security dashboardCustom quote

The deliverable, risk matrix, action plan and any remediation work are specified in the quote. Eligibility for funding must be checked on the official website of the relevant programme.

07 — Frequently asked questions

FAQ — IT Security Audit

How long does an IT security audit take?

Duration depends on the number of devices and sites, the authorised tests and the deliverables. The schedule, intervention windows and reporting arrangements are confirmed in the proposal.

Will the audit disrupt my business operations?

Scans and tests are planned to limit impact, but their constraints and risks depend on scope. Intervention windows, exclusions and stop procedures are agreed before testing.

My company is too small for a cyber audit, isn't it?

Size alone does not remove risk. The audit level should reflect the data processed, exposed access and the organisation's dependence on its IT systems.

What is the difference between an audit and a pentest?

A security audit is holistic: it covers the organisational (policies, procedures), technical (configurations, vulnerabilities) and human (awareness) dimensions. A penetration test is a subset of the audit: it simulates a real attack to test the resilience of your defences.

Are there financial grants for a cybersecurity audit?

A programme's availability, eligibility and covered expenses must be checked against its official source when applying. Any administrative or technical assistance is scoped separately by quote.

What happens after the audit?

Deliverables are defined in the proposal. Remediation or periodic follow-up can be covered by a separate scope and quote.

You don't know where
your vulnerabilities are — we do

IT security audit: scope, deliverables, schedule and quote confirmed before work starts.