What the audit is — and is not
An IT audit from GlabIT is a practical technical and operational assessment. We look at what is actually in place, gather evidence that it works (or does not), and tell you what matters most and in what order to fix it. It is not a statutory financial audit, not an ISO certification audit, not a legal opinion, and not a guarantee of compliance or of the absence of undiscovered issues. Where a finding is verified — we saw the configuration, we watched the restore, we checked the account list — the report says so, and “verified” means verified only for the stated evidence, sample, system and date; where we are recommending on the basis of interviews or documents alone, the report says that too.
Areas reviewed
Scope is agreed before the engagement and can cover:
- IT governance. Ownership, policies, risk management, decision-making
- Asset inventory. Hardware, software, cloud subscriptions and services; what exists, who owns it, what is unsupported
- Identity and access management. Directory, MFA coverage, privileged and service accounts, joiner–mover–leaver processes
- Microsoft 365, Google Workspace and cloud configuration where applicable
- Endpoint, server and network management. Build standards, management tooling, coverage
- Patch management and vulnerability handling, including unsupported systems and exceptions
- Network architecture. Segmentation, firewalls, VPN and remote access
- Backups. Coverage, immutability, recovery objectives, and evidence of restore testing
- Logging, monitoring, alert handling and incident-response readiness
- Change and configuration management
- Business continuity, disaster recovery and operational dependencies
- Third parties. MSP oversight, technology suppliers, contractual and access controls
- Data handling and access controls relevant to the agreed scope
How the evidence is gathered
Depending on scope, the work combines interviews with the people who run the systems, review of policies, contracts and runbooks, configuration sampling from consoles and exports, read-only technical inspection, and validation of selected controls — for example a restore test, an MFA coverage check, a review of privileged group membership. Where sampling is used the report states the sample and does not imply exhaustive testing.
Methodology and frameworks
The review is structured around control areas that are mapped to, or informed by, ISO/IEC 27001 and ISO/IEC 27002, the CIS Controls and relevant CIS Benchmarks, the NIST Cybersecurity Framework, NIS2 Article 21 measures where applicable, DORA requirements where they apply to the client, and the client’s own policies, contracts and control requirements. Which of these are used — and how deep the mapping goes — is agreed in the scope; we do not reproduce the standards themselves, and a mapping in our report is not a certification, accreditation or regulatory decision.
Where it fits
An IT audit is usually the assess stage of an engagement: it gives you the baseline before a compliance programme, before an ISO/IEC 27001 project, before changing providers, or after an acquisition. Its findings can be tested further with a penetration test and fixed through Cybersecurity-as-a-Service or Secure Engineering.
Scope note: findings and recommendations are based on the agreed scope and the evidence made available during the engagement. Regulatory and framework mappings are provided only where included in scope. Certification decisions remain with an accredited certification body where applicable.