HIVE80lab — Ops notes

Security audit preparation checklist: be audit-ready in a day

A security audit costs the same whether you are ready for it or not — the fee is fixed, but the findings are not. An unprepared team spends the first paid hour of the audit on inventory archaeology: who has the server password, where the backups actually go, whether the departed finance manager's account is still live. A prepared team starts at check one with the evidence already on the table. Preparation is the difference between an audit that finds your real risks and an audit that finds your filing.

This is the checklist: a six-document readiness packet, a self-score before anyone else scores you, the ten cheap fixes you close before the walkthrough, an evidence folder numbered to the same 45 checks the auditor uses, the eight questions you will be asked, a hand-over that protects your secrets, and a one-page memo that turns the whole exercise into a decision.

1. The readiness packet: six documents

Everything an auditor needs fits in six documents. If any of them does not exist, that fact is itself the first finding — write it down and move on; do not let a missing document stop the prep.

2. Score yourself first

Run the 45-check audit scorecard the day before the auditor arrives — honestly, not aspirationally. Three reasons, all of them money:

3. The fix-first ten

Ten controls that cost under a day each and remove the findings auditors weight heaviest. Do these before the walkthrough, in this order:

  1. MFA on every admin account — email admin, cloud consoles, registrar, banking. One afternoon, closes the single most common critical finding.
  2. Remove departed staff — work through the access list chronologically; every account older than the last offboarding is a finding with your name on it. The user access review checklist is the sweep pattern.
  3. Patch the internet-facing things — router firmware, the website's CMS and plugins, anything with a public IP. The patch cadence keeps it that way.
  4. Run one restore test — restore yesterday's backup of one file share to a scratch location, screenshot it. This converts "backups: unknown" to "backups: verified" on the report.
  5. Kill shared passwords — the admin password taped under the keyboard, the everyone@ logins. A password manager rollout is a day of work.
  6. Move registrar and DNS to a company mailbox — the domain sitting on a founder's personal Gmail is how a business loses its name.
  7. Turn on device encryption — FileVault or BitLocker on every laptop in the inventory; it is two clicks and it deletes the "stolen laptop" scenario from the risk list.
  8. Revoke stale API keys and tokens — anything older than six months or belonging to a person who left.
  9. Write the 2am line — one sentence in the policy one-pager: who gets called, in what order, from which phone. The incident response plan template is the skeleton.
  10. Screenshot everything you just fixed — into the evidence folder, next section.

4. The evidence folder

An auditor's report is only as strong as its evidence, and your remediation list is only as short. Build one folder, numbered to match the 45 checks:

5. The eight questions you will be asked

Every small-team audit walks the same eight questions. Prepare the one-sentence answers and the evidence pointer for each:

  1. "Who has admin rights, and when did you last check?"
  2. "How does an ex-employee stop having access the day they leave?"
  3. "If ransomware lands at 9am Monday, what gets restored, and how do you know the backup is good?"
  4. "What did your last phishing near-miss look like, and what changed after it?"
  5. "Where are the passwords for the router, the registrar and the server?"
  6. "Which vendor could hurt you most if they were breached, and what did you check about them?"
  7. "What is on the public internet that you think is not?" (the shadow-IT answer feeds the shadow IT audit)
  8. "If the owner's phone was stolen tonight, what happens by morning?" (stolen-device flow: the lost laptop runbook)

6. Hand over carefully, not wide open

Prepared does not mean exposed. Three rules protect you while the audit reads your estate:

7. The one-page current-state memo

The last document in the packet is the one you write last: one page, three sections — what we protect (the crown jewels, named), what we know is weak (your honest self-score, the failures you have not closed yet and why), and what we want out of this audit (priorities, not pleasantries: "tell us the order to fix things in, and what we can defer").

This memo changes the audit's shape. It converts the engagement from "find what you find" to "confirm, correct and sequence" — which is what produces a fix plan you will actually execute instead of a report that goes in a drawer. The output format it feeds is the one-page audit report.

8. Worked example

An 11-person logistics firm booked an audit after a customer's security questionnaire came back with "unable to verify." Prep took one working day: the packet was assembled from existing exports (three hours, mostly hunting the two SaaS tools nobody remembered buying), the scorecard came out at 31 of 45, and seven of the fourteen failures were in the fix-first ten — closed by the next morning: MFA on the three admin accounts, two departed-staff accounts removed, a restore test that actually restored, registrar moved off a personal mailbox, and screenshots for all five.

The audit itself: one walkthrough call, 41 minutes. The report arrived on day three, fourteen findings — seven marked remediated during preparation, five ranked medium, two critical (the forgotten SaaS tools with customer data and no MFA). Total surprise: zero. The customer questionnaire was resubmitted with the report attached, and the deal — which had been cooling for a month — closed the following week.

The unprepared version of the same audit is easy to price: the walkthrough becomes two calls because the access list did not exist, three of the five days are spent on discovery the client pays for either way, and the findings arrive later, hit harder, and change nothing fast.

9. Five audit-readiness numbers

Where this fits

Preparation makes the audit cheap; the audit itself is the 45-point small-business security audit, scored live in the interactive scorecard. If you would rather hand the walkthrough to an outside pair and receive the prioritized fix plan, that is the Small-Team Ops Audit; and when the findings say you would not survive Tuesday, the Custom Incident Runbook turns them into a procedure your team can run at 2am. If the question is budget, the honest price tiers are in the audit cost guide.