If your organisation runs on Microsoft 365, uses VoIP for calls, depends on cloud apps and online sales, your IT isn’t “just IT” anymore—it’s the backbone of your business. Yet most issues that lead to downtime, data loss or cyber incidents aren’t exotic zero‑days; they’re basic gaps: unpatched devices, weak access controls, stale admin accounts, backups that don’t restore, or end‑of‑life systems left running because “they still work”.
An IT audit is the simplest way to surface and fix those gaps before they become costly problems. Below we explain what an IT audit actually covers, why it matters right now, what “good” looks like, and how a free audit from Verstech works without disruption to your day‑to‑day.
Why this matters right now
- Incidents are common and costly. The government’s Cyber Security Breaches Survey 2025 found 43% of UK businesses identified a breach or attack in the last 12 months (rising to 67% for medium and 74% for large firms). That’s roughly 612,000 UK businesses affected—phishing remains the top vector.
- Basic hygiene still makes the biggest difference. UK guidance continues to emphasise five simple pillars—backups, patching, MFA/strong authentication, asset visibility and keeping software supported—as the fastest way to lower risk.
- Unsupported tech is a growing risk. With Windows 10 support ending on 14 October 2025, any PCs left behind will stop receiving security updates, increasing exposure. The NCSC advises migrating from obsolete/unsupported software wherever possible, and applying strict mitigations if you can’t move immediately.
- Downtime is expensive. UK firms lost over 50 million hours to internet failures in 2023, costing £3.7 billion. Connectivity resilience (and tested failover) belongs in your audit scope—because the cost of an outage dwarfs the saving on a cheaper line.
What is an IT audit (and what it isn’t)?
An IT audit is a structured, evidence‑based health check of your environment. It’s not a compliance witch‑hunt or a weeks‑long consultancy project. Done well, it’s a time‑boxed review that shows where you stand today, where the risks and inefficiencies are, and what to do next—prioritised by business impact.
At Verstech, we split audits into five practical lenses:
1. Identity & Access
- MFA coverage across Microsoft 365 and other critical services; admin roles and break‑glass accounts; conditional access; password policies; privileged access workstations (if used).
- Why: strong authentication is one of the highest‑value controls you can implement quickly.
2. Devices & Patch/Vulnerability Management
- Endpoint inventory and compliance (Windows, macOS, mobile); OS and application patch cadence; EDR status; encryption; local admin use; firmware update approach.
- Why: NCSC’s vulnerability management guidance is unambiguous—use supported software and patch promptly; plan migrations for products at end‑of‑support.
3. Data Protection, Backups & Recovery
- 3‑2‑1 style backups for servers and cloud data; separation from the production domain; backup encryption and access controls; test restores; RPO/RTO realism.
- Why: the NCSC’s small business guidance starts with backups as step one for a reason—when incidents happen, recovery speed is everything.
4. Cloud & SaaS Configuration (Microsoft 365 and friends)
- Secure defaults in Entra ID / Microsoft 365; Secure Score context; data loss prevention; SharePoint/OneDrive sharing posture; mailbox security; third‑party app access; logging and monitoring.
- Why: misconfigurations—not just malware—cause a large slice of incidents; simple configuration hardening yields outsized risk reduction.
5. Network, Connectivity & Perimeter
- Firewall rules and change control; segmentation (e.g., guest/IoT/Wi‑Fi VLANs); DNS filtering; SD‑WAN/QoS for VoIP and Teams; leased line vs FTTP posture; failover path (4G/5G or second circuit).
- Why: you can’t secure or keep productive what you can’t see or prioritise—asset visibility and resilient connectivity are foundational.
Each lens produces clear findings, a severity rating, and fixes categorised as Quick wins (0–30 days), Near‑term (30–90 days) and Roadmap (quarterly).
What a good IT audit uncovers (common UK findings)
- MFA gaps: user MFA set, but global admins or legacy protocols aren’t enforced; SMS still used where app‑based, phishing‑resistant methods would be stronger.
- Unsupported tech: Windows 10, old firewalls/routers or line‑of‑business apps beyond support; mitigation plans missing ahead of vendor end‑of‑life.
- Backups that don’t restore: nightly jobs “green”, but no test restore in the last quarter; backups writable from the production domain (ransomware risk). NCSC recommends keeping backups separate and tested.
- Patch blind spots: third‑party apps and firmware lagging; no service owner for updates; weak inventory so some assets simply don’t get patched. Vulnerability management hinges on supported software and asset visibility.
- Over‑permissive sharing: Microsoft 365/SharePoint links set to “Anyone” by default; lack of DLP; legacy mail forwarding rules still live. UK guidance highlights reducing the impact of common attacks through secure configuration.
- Single‑path internet: one circuit, no 4G/5G failover; QoS not configured for voice/video, so Teams/VoIP degrade at peak times; outage costs not understood. The national cost of downtime shows why a second path matters.
What “good” looks like after the audit
- Identity: MFA on all accounts (with stronger methods for admins), conditional access enforcing device health, time‑bound privileged access, and clear joiner‑mover‑leaver processes.
- Devices: an accurate asset register; patch SLAs for OS, apps and firmware; encryption on; EDR deployed and monitored; unsupported systems minimised with documented mitigations and retirement dates.
- Data: backups are isolated, encrypted and regularly restored in tests; RPO/RTO documented and met; SaaS data (e.g., M365) protected by policy and backup where appropriate.
- Cloud config: Microsoft 365 baselines applied; phishing protections and safe links; risky legacy auth blocked; sharing defaults tightened; auditable logs retained to support investigations.
- Network & connectivity: least‑privilege firewall rules; segmented Wi‑Fi (guest/IoT/user); DNS filtering; SD‑WAN/QoS for collaboration tools; diverse failover tested; SLA aligned to your real business risk
How an IT audit reduces cost (not just risk)
- Fewer incidents and faster fixes
Clearing hygiene issues (MFA, patching, backups) cuts incident volume and shrinks downtime, which carries direct cost. The UK’s 2023 downtime figures illustrate how quickly losses add up when connectivity fails; the same logic applies to system outages and ransomware recovery time. - Licence & estate rationalisation
Audits reveal unused SaaS seats, duplicate security tools and over‑specced connectivity. Reclaiming licences and right‑sizing lines often funds the fixes. - Compliance made easier
The security principle of UK GDPR requires “appropriate technical and organisational measures”. An audit gives you the evidence trail (policies, controls, logs) to demonstrate accountability—something the ICO explicitly encourages - Planning hardware refresh on your terms
With Windows 10 EoS approaching, an audit helps you prioritise which devices to upgrade or replace—and where temporary mitigations (e.g., isolation) are acceptable until budget cycles align.
What we check (a practical checklist you can reuse)
- Identity & Access: MFA coverage; break‑glass admin; conditional access; stale accounts; privileged access paths.
- Devices: asset inventory; OS/app/firmware versions; encryption; local admin use; EDR status; vulnerable drivers.
- Patching & Vulnerabilities: cadence, ownership, service‑level targets; visibility of out‑of‑support software.
- Backups: scope (servers, cloud data), isolation, retention, encryption, restore tests, RPO/RTO.
- Microsoft 365: tenant defaults, Secure Score context, mail flow hygiene, external sharing defaults, DLP, third‑party app permissions, logging.
- Network & Connectivity: firewall baseline; segmentation; DNS filtering; SD‑WAN/QoS for VoIP/Teams; primary/secondary circuits and 4G/5G failover; SLA alignment to business tolerance.
- Policies & Evidence: Cyber Essentials five controls coverage; incident response basics; change and access reviews.
How our free IT audit works (no disruption)
- 15‑minute scoping call – we agree what’s in scope (e.g., 365 tenant + top two sites), confirm read‑only access where needed, and schedule.
- Lightweight data collection – export reports from your existing tools (e.g., Intune/Endpoint Manager, Microsoft 365, EDR, firewall). If you don’t have them, we use safe discovery methods that won’t impact users.
- On‑site walk‑through (optional) – quick look at comms rooms, Wi‑Fi coverage and cabinet hygiene; validate failover paths.
- Findings workshop – a plain‑English readout with:
We can optionally align the plan to Cyber Essentials so you get a recognised UK baseline as you implement fixes.
FAQs
Isn’t this just a sales exercise?
No. You’ll get the findings and the plan whether you engage us or not. If you already have an MSP, use the report to hold them (and us) to account.
Will it affect our users?
No. We use read‑only reporting and out‑of‑hours checks if anything invasive is required (rare).
We’re a small team—will we be judged?
Not at all. The aim is to remove toil and risk, not point fingers. The 2025 survey shows many SMEs are still maturing processes; a light audit is a fast way to move forward with confidence.
Next steps
If you’d like us to run a free IT audit, we’ll benchmark your current state against UK best practice, highlight the quick wins, and give you a 90‑day action plan tailored to your budget and risk profile. It’s a straightforward, no‑nonsense way to cut risk, reduce costs and keep people productive.



