Security audit preparation checklist: be audit-ready in a day
A security audit costs the same whether you are ready for it or not — the fee is fixed, but the findings are not. An unprepared team spends the first paid hour of the audit on inventory archaeology: who has the server password, where the backups actually go, whether the departed finance manager's account is still live. A prepared team starts at check one with the evidence already on the table. Preparation is the difference between an audit that finds your real risks and an audit that finds your filing.
This is the checklist: a six-document readiness packet, a self-score before anyone else scores you, the ten cheap fixes you close before the walkthrough, an evidence folder numbered to the same 45 checks the auditor uses, the eight questions you will be asked, a hand-over that protects your secrets, and a one-page memo that turns the whole exercise into a decision.
1. The readiness packet: six documents
Everything an auditor needs fits in six documents. If any of them does not exist, that fact is itself the first finding — write it down and move on; do not let a missing document stop the prep.
- The asset inventory — every laptop, phone, server, router, cloud account and SaaS subscription, one row each, with an owner column. The IT asset inventory template is the format.
- The access list — who can reach what: email, file shares, admin consoles, banking, the builder panel. Flag anyone with admin rights and anyone who left the company in the last twelve months.
- The policy one-pager — your password rule, your MFA rule, your backup schedule, your "who to call at 2am" line. One page. If it lives in the owner's head, the page says that, and the page gets written.
- The incident and near-miss log — every phishing email someone almost clicked, every laptop that went missing, every outage. Near-misses are evidence the process exists, not confessions.
- The vendor list — every third party that holds your data or runs your payments, with what they hold. This feeds the vendor security review.
- Backup evidence — the last three restore-test results with dates. A backup you have never restored is a hope, not a control, and auditors price it that way.
2. Score yourself first
Run the 45-check audit scorecard the day before the auditor arrives — honestly, not aspirationally. Three reasons, all of them money:
- No findings should surprise you. An audit where the buyer gasps at page one is an audit that becomes an argument. You already know the score; the auditor's job is to confirm, prioritize and write the fix plan.
- You can pre-close the cheap failures. Every check you pass overnight is one the auditor records as "remediated" instead of "open finding" — the report reads better and the fix list gets shorter.
- You pay for insight, not discovery. Fixed-fee audits like the Small-Team Ops Audit assume the walkthrough, not the archaeology. A prepared packet is why the five-day turnaround holds.
3. The fix-first ten
Ten controls that cost under a day each and remove the findings auditors weight heaviest. Do these before the walkthrough, in this order:
- MFA on every admin account — email admin, cloud consoles, registrar, banking. One afternoon, closes the single most common critical finding.
- Remove departed staff — work through the access list chronologically; every account older than the last offboarding is a finding with your name on it. The user access review checklist is the sweep pattern.
- Patch the internet-facing things — router firmware, the website's CMS and plugins, anything with a public IP. The patch cadence keeps it that way.
- Run one restore test — restore yesterday's backup of one file share to a scratch location, screenshot it. This converts "backups: unknown" to "backups: verified" on the report.
- Kill shared passwords — the admin password taped under the keyboard, the everyone@ logins. A password manager rollout is a day of work.
- Move registrar and DNS to a company mailbox — the domain sitting on a founder's personal Gmail is how a business loses its name.
- Turn on device encryption — FileVault or BitLocker on every laptop in the inventory; it is two clicks and it deletes the "stolen laptop" scenario from the risk list.
- Revoke stale API keys and tokens — anything older than six months or belonging to a person who left.
- Write the 2am line — one sentence in the policy one-pager: who gets called, in what order, from which phone. The incident response plan template is the skeleton.
- Screenshot everything you just fixed — into the evidence folder, next section.
4. The evidence folder
An auditor's report is only as strong as its evidence, and your remediation list is only as short. Build one folder, numbered to match the 45 checks:
- One folder, numbered subfolders, dated files.
01-mfa-admin.png,02-access-list.csv,17-restore-test-2026-09-11.pdf. When the walkthrough hits check 17, you open folder 17. Ten seconds, no "let me get back to you." - Screenshots over promises. A settings page with the date visible beats a paragraph saying "we do that." The report cites evidence; it cannot cite intentions.
- Redact what the folder shows. Usernames can stay; the screenshots should not include live secrets, full customer lists, or anything you would not hand a contractor.
5. The eight questions you will be asked
Every small-team audit walks the same eight questions. Prepare the one-sentence answers and the evidence pointer for each:
- "Who has admin rights, and when did you last check?"
- "How does an ex-employee stop having access the day they leave?"
- "If ransomware lands at 9am Monday, what gets restored, and how do you know the backup is good?"
- "What did your last phishing near-miss look like, and what changed after it?"
- "Where are the passwords for the router, the registrar and the server?"
- "Which vendor could hurt you most if they were breached, and what did you check about them?"
- "What is on the public internet that you think is not?" (the shadow-IT answer feeds the shadow IT audit)
- "If the owner's phone was stolen tonight, what happens by morning?" (stolen-device flow: the lost laptop runbook)
6. Hand over carefully, not wide open
Prepared does not mean exposed. Three rules protect you while the audit reads your estate:
- Least privilege first. The auditor gets a read-only account where read-only is possible, and a named contact for everything else — not the domain admin password in an email.
- Secrets never travel by email or chat. Credentials go through a password manager's share link with an expiry date, or not at all. If a tool demands a raw secret, rotate it the day the engagement ends.
- Redact on the way out. Customer names, payment details and staff personal data get masked in the packet. An auditor testing access control needs the structure of the access list, not the identities.
7. The one-page current-state memo
The last document in the packet is the one you write last: one page, three sections — what we protect (the crown jewels, named), what we know is weak (your honest self-score, the failures you have not closed yet and why), and what we want out of this audit (priorities, not pleasantries: "tell us the order to fix things in, and what we can defer").
This memo changes the audit's shape. It converts the engagement from "find what you find" to "confirm, correct and sequence" — which is what produces a fix plan you will actually execute instead of a report that goes in a drawer. The output format it feeds is the one-page audit report.
8. Worked example
An 11-person logistics firm booked an audit after a customer's security questionnaire came back with "unable to verify." Prep took one working day: the packet was assembled from existing exports (three hours, mostly hunting the two SaaS tools nobody remembered buying), the scorecard came out at 31 of 45, and seven of the fourteen failures were in the fix-first ten — closed by the next morning: MFA on the three admin accounts, two departed-staff accounts removed, a restore test that actually restored, registrar moved off a personal mailbox, and screenshots for all five.
The audit itself: one walkthrough call, 41 minutes. The report arrived on day three, fourteen findings — seven marked remediated during preparation, five ranked medium, two critical (the forgotten SaaS tools with customer data and no MFA). Total surprise: zero. The customer questionnaire was resubmitted with the report attached, and the deal — which had been cooling for a month — closed the following week.
The unprepared version of the same audit is easy to price: the walkthrough becomes two calls because the access list did not exist, three of the five days are spent on discovery the client pays for either way, and the findings arrive later, hit harder, and change nothing fast.
9. Five audit-readiness numbers
- Packet completeness (documents present of six — target: 6/6 within a quarter of adopting this page; a missing incident log is the most common gap).
- Evidence coverage (checks with dated evidence / 45 — 60% is enough to change the report's tone; chase it before the walkthrough, not after).
- Fix-first closure rate (of the ten, closed before audit — below 7, the audit is buying archaeology).
- Departed-staff residual (accounts still live more than a day after offboarding — target: zero; this is the number auditors quote first).
- Days from booking to walkthrough-ready (the prep clock — one day is the bar this checklist sets; a week means the packet is being written from scratch each time, which means it is not a packet, it is an event).
Where this fits
Preparation makes the audit cheap; the audit itself is the 45-point small-business security audit, scored live in the interactive scorecard. If you would rather hand the walkthrough to an outside pair and receive the prioritized fix plan, that is the Small-Team Ops Audit; and when the findings say you would not survive Tuesday, the Custom Incident Runbook turns them into a procedure your team can run at 2am. If the question is budget, the honest price tiers are in the audit cost guide.