Digital Resilience Associations
РусскийРусский

What a Cybersecurity Audit Actually Looks Like, Step by Step

“Isn’t everything already fine?” is the most common question before an audit starts. And “not quite” is the most common answer afterward — not because something went catastrophically wrong, but because cybersecurity rarely becomes a priority until there’s a reason to look. Here’s how a typical audit usually unfolds, step by step, without tying it to any specific client.

Step 1. Initial meeting and scoping
Before checking anything, you need to know what you’re checking: which systems the company uses, who has access to customer data, whether there are remote employees, contractors, or cloud services involved. This step often reveals the first issue — no one in the company has a complete, accurate list of the services in use or who has access to what.

Step 2. Technical review
This covers access settings, password policies, two-factor authentication on critical services, software updates, and backups. The most common findings tend to repeat: employees who left six months ago but still have system access; shared passwords across multiple accounts; missing MFA exactly where it matters most — accounting and banking tools.

Step 3. Legal compliance check
A separate track covers registration in the GAZPD personal data holder registry, whether a Privacy Policy exists, and whether someone has been formally assigned as responsible for personal data protection. This is the legal side of the audit, not the technical one — and it’s often the most overlooked part, treated as a formality rather than a real fine risk.

Step 4. Human factor check
Short employee interviews, or a test phishing email, tend to be the most revealing part. Systems can be configured correctly and an untrained employee can still open a suspicious file if no one has ever shown them what to look for.

Step 5. Prioritized report
The final document isn’t a 40-item “fix everything at once” list — it’s prioritized: what needs fixing this week, what can be planned over the quarter, and what can simply be monitored. An audit without clear priorities is close to useless — companies either drown in the list or ignore it entirely.

Step 6. Implementation support
A good audit doesn’t end with the report. What follows is help with implementation — from setting up MFA to registering with GAZPD and training staff.

The outcome is usually the same across companies: rarely a technical disaster, but a buildup of small gaps that, individually minor, add up to real exposure together.