March Code

HowtoRunanITAudit:A15-PointChecklist

A 15-point IT audit checklist: infrastructure, security, business processes, software and data. How to run the audit yourself or with an outside firm, and what it costs (from $3,900).

How to Run an IT Audit: A 15-Point Checklist
Eugene OlshevskyEugene OlshevskyCTO and co-founder
16 min read

An IT audit is not “checking the computers.” It's an X-ray of your business through the lens of technology: where money leaks into broken processes, where data is at risk, where the infrastructure won't survive growth. If you've never run an IT audit, there's a 90% chance you're losing 10–20% of your IT budget on workarounds nobody notices.

This guide is a practical 15-point checklist. Use it for a self-audit or as a brief for an external auditor. It fits companies with 20+ employees and IT infrastructure of any complexity.

15
checklist points
2–4 weeks
typical audit length
from $3,900
cost of an
external IT audit

Why you need an IT audit

Nobody runs an IT audit just to tick a box. You run one when you have a decision to make:

Before automation. Before you roll out an ERP, a CRM or any other system, understand what you have now. Otherwise you automate chaos. This is the foundation of any business automation project.

During fast growth. Infrastructure that worked for 20 people breaks at 100. An audit shows what to scale ahead of time, not in a panic.

After an incident. A data leak, a server crash, a lost database. An audit finds the cause and prevents a repeat.

When IT leadership changes. A new CTO needs to know what they've inherited: where the landmines are, where the technical debt sits, where the quick wins are.

Before fundraising or M&A. Investors and buyers check IT: security, scalability, dependence on specific people. Audit early and you'll face fewer unpleasant surprises during due diligence.

IT audit checklist: 15 points

Block 1: Infrastructure (points 1–4)

1
Servers and hosting. What to check: where the servers physically sit (on-premises / cloud / colocation), operating systems and versions, CPU / RAM / disk load (average and peak), redundancy (what happens if a server dies?), monthly infrastructure cost. Red flags: a server under the sysadmin's desk, Windows Server 2012 in production, CPU load constantly above 80%, no standby server
2
Network and connectivity. What to check: network topology (physical and logical), bandwidth and latency, Wi-Fi coverage (dead zones?), VPN for remote staff, internet provider (is there a backup line?). Red flags: a single provider with no backup, no VPN (employees connect to the accounting system over RDP from their home Wi-Fi), one router from 2018 serving Wi-Fi to 50 people
3
Workstations. What to check: age and specs of the computers, OS versions (Windows 10/11, macOS), standardization (a standard software set or “everyone has their own”), licenses (unlicensed software = legal risk). Red flags: computers older than 5 years (they slow people down), unlicensed Office / Photoshop, no antivirus
4
Backups. What to check: what gets backed up (databases, files, email, configurations), how often (daily at a minimum), where to (a separate server, the cloud, off-site), whether restores have been tested (and when was the last time?). Red flags: no backups (20% of companies!), backups on the same server (the server dies and takes the backups with it), restores never tested (a backup can be corrupted)
Tip

The 3-2-1 rule: three copies of your data, on two different media, one copy off-site (the cloud or another data center). If that's not your setup, it's the first thing to fix after the audit. Lose your data and you lose your business.

Block 2: Security (points 5–8)

5
Access management. What to check: password policy (length, complexity, rotation), two-factor authentication (2FA), the role model (who has access to what), the offboarding procedure (are accounts disabled?), shared accounts (admin/admin123). Red flags: no 2FA on email and company systems, former employees with active accounts, “123456” as a server password
6
Perimeter protection. What to check: a firewall (is there one, is it configured), antivirus / EDR on workstations and servers, security updates (when were they last installed?), DDoS protection (if you run public-facing services), email protection (anti-spam, anti-phishing). Red flags: no firewall, an antivirus with an expired subscription, Windows updates not installed for 6+ months
7
Data protection. What to check: data encryption (at rest and in transit), compliance with GDPR or other data protection rules (if you process personal data), a policy for handling confidential information, a DLP system (data loss prevention), access logging for critical data. Red flags: personal data stored unencrypted, no personal data processing policy, anyone can copy the customer database to a USB stick
8
Incident management. What to check: whether there's a response plan for incidents (cyberattack, leak, outage), who's responsible, how stakeholders get notified, whether drills have been run. Red flags: no plan (70% of companies), the person responsible is a sysadmin who's on vacation, the last incident was “heroically solved” with no root-cause analysis

Block 3: Software (points 9–11)

9
Software inventory. What to check: a full list of the software in use (on-premises, cloud, SaaS), licenses and their cost, duplication (two tools for one job), unused subscriptions (“forgotten” SaaS tools that quietly bill every month). Typical finding: the company pays for 3–5 SaaS tools nobody uses, and that money is simply thrown away every year
10
Business systems (ERP, CRM, accounting). What to check: versions and how current the updates are, adoption (what % of features actually get used), integrations between systems (is data moved by hand?), performance (does it slow down under peak load), customizations (are they documented). Red flags: an accounting or ERP system stuck on a 2018 version, a CRM used as an address book (10% of its features), data retyped from one system into another by hand
11
Web properties. What to check: the website (how current the CMS is, SSL certificate, load speed, mobile responsiveness), domains (renewals, DNS records), hosting (stability, backups). Red flags: a site on WordPress 5.x with 20 outdated plugins (vulnerabilities), no SSL, load time over 5 seconds, a domain registered to a former employee's personal email

Block 4: Processes and people (points 12–15)

12
IT team. What to check: structure (in-house vs outsourced), skills (do they cover current needs), bus factor (if a key person leaves, what breaks), workload (constant firefighting means too few people or broken processes). Red flags: everything depends on one sysadmin (bus factor = 1), the IT director handles both strategy and printer setup
13
Documentation. What to check: whether the architecture is documented, whether there are user guides, whether recovery procedures are written down, whether the documentation is current (updated when things change). Red flags: no documentation (60% of companies), documentation 3 years old (no longer matches reality), all the knowledge lives in one person's head
14
IT budget. What to check: spending structure (hardware, software, people, cloud, support), ROI on IT investments over the past year, “hidden” spending (shadow IT: employees buying SaaS on the company card without approval), benchmarking (what competitors of a similar size spend). Typical finding: 15–25% of the IT budget is wasted
15
Alignment with business strategy. What to check: whether the current IT setup supports the company's growth plans (scaling, new products, new markets), whether there's an IT strategy (or just firefighting), IT project priorities (do they match business goals). Red flags: the IT department doesn't know the company's strategy, priorities go to whoever shouts loudest

How to run the audit: in-house or with an outside firm

Self-audit

When it works: a company of up to 50 people, simple infrastructure, an IT director or an experienced sysadmin on staff.

How to do it: use the checklist above. For each point, record the current state (green / yellow / red), what needs fixing, the priority and a rough budget. Time: 1–2 weeks of full-time work.

Limitations: an internal auditor has blind spots and stops seeing familiar problems. There's no benchmarking (nothing to compare against). You may lack expertise in narrow areas (security, architecture).

External audit

When you need it: a company of 50+ people, complex infrastructure, a major IT project ahead (ERP, digital transformation), or you need an objective assessment.

Cost: from $3,900 for an express audit (infrastructure + security, 1–2 weeks), around $7,000–15,000 for a full audit (all 15 points, 2–4 weeks), from $14,900 for an in-depth audit with recommendations and a roadmap.

What you get: a report with prioritized recommendations, a roadmap (what to do first), benchmarking (how you look against your industry), an objective assessment (no “that's just how it's always been”).

A good IT audit pays for itself 5–10 times over. Typical savings after auditing a 100-person company: $7,000–17,000 a year on unused subscriptions, $10,000–35,000 on prevented incidents, $17,000–65,000 on infrastructure optimization. A $10,000 audit returns $35,000–100,000 in savings.

What to do after the audit

Prioritization: the impact × effort matrix

Score every problem you found on two axes: business impact (1–5) and the difficulty and cost of fixing it (1–5). Start with the “high impact + low effort” quadrant (quick wins). The usual suspects: update passwords, set up backups, cancel unused subscriptions. Fast, cheap, and the effect is noticeable.

Roadmap

Months 1–2: Critical security. Passwords, 2FA, backups, security updates. Budget: $0–1,500 (mostly labor).

Months 2–4: Infrastructure. Migration to current software versions, network optimization, redundancy. Budget: $3,000–15,000.

Months 4–8: Processes and automation. System integration, document workflow automation, new tools. Budget: $10,000–65,000.

Months 8–12: Strategic projects. ERP, a new CRM, a corporate portal, moving to the cloud. Budget: $35,000–330,000.

Our approach to IT audits

At March Code we run IT audits as a standalone service and as part of the groundwork for automation projects. The format: 2–3 weeks of work, then a report with prioritized recommendations and a 12-month roadmap.

from $3,900
express IT audit
2–3 weeks
duration
5–10x
typical ROI
of the recommendations

FAQ

How often should you run an IT audit?

A full audit: every 1–2 years. An express security check: every 6 months. Unscheduled: when IT leadership changes, after an incident, before a major project, when the company grows several times over. In regulated industries (fintech, healthcare), an annual security audit is usually mandatory.

What if the audit uncovers critical problems?

Don't panic, prioritize. Critical security issues (no backups, open ports, former employees with access) get fixed within 1–2 days. Infrastructure issues get a 2–4 week plan. Process issues get a 1–3 month plan. The main thing is to start instead of waiting for “the perfect moment.”

How much does an IT audit cost for a 100-person company?

Express (infrastructure + security): from $3,900. Full (all 15 points): around $10,000–15,000. With a roadmap and support during implementation: from $14,900. The price depends on how complex the infrastructure is: 2 servers + a cloud account is simpler than 20 servers + 3 data centers + 5 branch offices.

Can an IT audit be done remotely?

Infrastructure and software: about 80% of it, yes (remote access, network scanning, configuration analysis). Security: partly (we need access to logs and configurations, but not necessarily a physical presence). Processes and people: these need interviews (Zoom works fine). Physical infrastructure (server room, network, cabling): needs a site visit. Where a visit is possible, we use a hybrid format: 70% remote, 30% on site.

What tools are used in an IT audit?

Network: Nmap (port scanning), Wireshark (traffic analysis). Security: Nessus / OpenVAS (vulnerability scanning), OWASP ZAP (web security). Infrastructure: Zabbix / Grafana (monitoring), Ansible (inventory). Software: Snow / Lansweeper (software and license inventory). Processes: interviews + questionnaires + documentation review.

About the authors

The March Code team

We're a software studio with years of commercial development experience in Russian and international markets. We help businesses go digital: we build web and mobile apps, automate routine work and bring AI in where it's actually needed.

Over that time we've delivered 20+ projects, from startup MVPs to complex SaaS platforms and enterprise solutions. Our clients include hospitality, e-commerce, logistics and education. For us, every project is not just code but a product that has to deliver results.

20+ delivered projects13+ years of founder experienceNDA on requestMore about the company →

An architect reviews your spec or idea in 48 hours

Free

Prices are indicative and not a binding offer.

We'll point out the risks, unnecessary features and a realistic budget range before you sign with a vendor.

Send your spec on Telegram, no form