Security audits are structured examinations of whether an organisation's protections actually exist and actually work, and they arrive in a small organisation's life through four doors: a client's questionnaire escalating into a requested audit, an insurer's condition, a regulator's rule, or an owner's own decision to find out the truth. Whatever the door, the examination covers three territories in some proportion: technical controls, are the machines patched, the factors enforced, the backups restorable; paperwork, do written policies exist, are they current, do they match reality; and conduct, do people actually do what the policies say, from payment confirmations to leaver offboarding. Small organisations fear the first territory and fail in the second and third. This guide walks what each territory's examination looks like, who performs audits and at what price shape, and the standing preparation that makes any audit a reading rather than an excavation.
The three territories, examined
Technical examination samples reality: patch states pulled from machines, factor coverage read from admin consoles, a restore actually attempted, firewall rules read against stated intentions. Paperwork examination reads the programme: the policy set's existence, its dates, its ownership, and, sharply, whether it describes this organisation or a template's imagination, auditors meet borrowed binders weekly and discount them on sight. Conduct examination tests the joins: pick three leavers and check their access died, pick three payments and check the confirmations happened, pick an incident and read what was logged. The findings that hurt are almost always in territories two and three, because technical gaps are cheap to fix and conduct gaps are cultural.
Who audits, and the price shapes
Four performer tiers: self-audit against a published checklist, free and worth doing quarterly, limited by self-knowledge; your own provider's review, included or cheap, limited by homework-marking; an independent assessor engaged for the purpose, the meaningful middle, priced per engagement by scope; and a certified audit against a formal standard when a contract demands one, the expensive tier, priced by the standard's requirements. Small organisations should live in tiers one and three: the quarterly self-check against the written programme, and the annual or biennial independent look. The cost driver in every tier is discovery, how long the auditor spends finding out what exists, which is exactly the cost preparation removes.
The standing preparation
Audit-readiness is a by-product of an owned programme, not a project before each audit. The standing state: the policy set current and dated, with review dates kept; the inventory appendix, systems, devices, vendors, matching reality; the evidence habits, monthly reports filed, restore tests dated, training logged, leaver checklists retained; and the exceptions list, every accepted risk written and dated, because auditors respect a recorded acceptance and excavate an unexplained gap. That standing state is what this site's product exists to maintain: the free sheet counts the set and prices its drafting, Hardenvo Pro generates the documents, files each with a status and review date, and the audit becomes a reading of a machine that was already running.
Questions people ask about security audits
What does a security audit cover?
Three territories: technical controls sampled from reality (patches, factors, an attempted restore), paperwork (the policy set's existence, currency and fit to this organisation), and conduct (leaver access, payment confirmations, incident logs actually checked). Findings cluster in the last two.
Who should perform a small organisation's security audit?
Quarterly: yourself, against your own written programme. Annually or biennially: an independent assessor, not your own provider marking their homework. A certified audit against a formal standard only when a contract or regulator demands it.
How do I prepare for a security audit?
Maintain the standing state rather than a pre-audit project: dated current policies, a true inventory, filed monthly evidence (reports, restore tests, training, leaver checklists), and a written exceptions list. Preparation is ownership, and it halves the engagement's discovery cost.