Cyberattacks on Polish businesses are no longer a problem for large corporations only. In 2026 the primary targets are small and mid-sized companies, because they have data, money and weaker defences. Below we show exactly what IT security audit — what it covers means and which decisions are worth making this quarter.
IT security audit — where to start and what it should include.
Audit scope
This section frames the topic "Audit scope" in the context of IT security audit — what it covers. We approach it from the business side — what concrete value or risk it brings to the company.
What you gain
- Significantly reduced risk of ransomware and customer data leaks.
- Compliance with GDPR, NIS2 and cyber insurers' requirements.
- Trust from partners in procurement processes and security audits.
Most common mistakes
- Relying only on antivirus instead of layered protection (EDR + MFA + backup).
- A backup that was never tested — in practice equivalent to no backup at all.
- No anti-phishing training — 90% of incidents start with a click on a link.
Methodology
This section frames the topic "Methodology" in the context of IT security audit — what it covers. We approach it from the business side — what concrete value or risk it brings to the company.
What you gain
- Significantly reduced risk of ransomware and customer data leaks.
- Compliance with GDPR, NIS2 and cyber insurers' requirements.
- Trust from partners in procurement processes and security audits.
Most common mistakes
- Relying only on antivirus instead of layered protection (EDR + MFA + backup).
- A backup that was never tested — in practice equivalent to no backup at all.
- No anti-phishing training — 90% of incidents start with a click on a link.
Report
SLA (Service Level Agreement) is not marketing — it is a specific contract clause saying: "we will respond within this time" and "we will resolve within this time". These two parameters are response time and resolution time — they are different and you must see both in the contract.
- Response time — from ticket to work starting. Market standard: 15 minutes to 2 hours in business hours.
- Resolution time — from work starting to solution. Depends on incident priority (P1–P4).
- Availability — 99.5% monthly means about 3.5 hours of acceptable downtime.
- Contract penalties — without them, an SLA is a declaration, not a commitment.
How to verify the SLA
Require monthly reports from the provider's ticketing system. If they cannot show you in a table how many tickets, in what times and with what priority they closed — the SLA exists only on paper.
Price
A conversation about IT costs starts with a single question: what exactly are we buying?. In practice there are three types of billing: flat fee, hourly, and mixed (base + overage). Each makes sense in a different scenario.
- Flat fee — a predictable cost, best for companies with a stable number of users and systems.
- Hourly — flexible, but hard to budget for a whole year.
- Mixed — the base covers 80% of the work, overage is billed separately; the most common model in SMEs.
What to watch for in a quote
The rate alone is not everything. Check what exactly the price covers, what the hour cap is, how out-of-scope projects are priced and whether travel is billed. The gap between the cheapest and most expensive offer in Poland can be 3–4× — and it usually comes down to what is "in the price" and what is not.
Key takeaways
- Significantly reduced risk of ransomware and customer data leaks.
- Relying only on antivirus instead of layered protection (EDR + MFA + backup).
- Treat the topic of "IT security audit — what it covers" as a project, not a one-off purchase — the best results come from a step-by-step approach.
Frequently asked questions
Check your company's security level
We invite you to a free cybersecurity consultation. We will walk through a checklist of 30 key areas (MFA, backup, EDR, training) and point out priorities for the next quarter.