Cybersecurity · 6 min

IT security audit — what it covers

IT security audit — where to start and what it should include.

1 October 2025

Cyberattacks on Polish businesses are no longer a problem for large corporations only. In 2026 the primary targets are small and mid-sized companies, because they have data, money and weaker defences. Below we show exactly what IT security audit — what it covers means and which decisions are worth making this quarter.

IT security audit — where to start and what it should include.

Audit scope

This section frames the topic "Audit scope" in the context of IT security audit — what it covers. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Significantly reduced risk of ransomware and customer data leaks.
  • Compliance with GDPR, NIS2 and cyber insurers' requirements.
  • Trust from partners in procurement processes and security audits.

Most common mistakes

  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • A backup that was never tested — in practice equivalent to no backup at all.
  • No anti-phishing training — 90% of incidents start with a click on a link.

Methodology

This section frames the topic "Methodology" in the context of IT security audit — what it covers. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Significantly reduced risk of ransomware and customer data leaks.
  • Compliance with GDPR, NIS2 and cyber insurers' requirements.
  • Trust from partners in procurement processes and security audits.

Most common mistakes

  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • A backup that was never tested — in practice equivalent to no backup at all.
  • No anti-phishing training — 90% of incidents start with a click on a link.

Report

SLA (Service Level Agreement) is not marketing — it is a specific contract clause saying: "we will respond within this time" and "we will resolve within this time". These two parameters are response time and resolution time — they are different and you must see both in the contract.

  • Response time — from ticket to work starting. Market standard: 15 minutes to 2 hours in business hours.
  • Resolution time — from work starting to solution. Depends on incident priority (P1–P4).
  • Availability — 99.5% monthly means about 3.5 hours of acceptable downtime.
  • Contract penalties — without them, an SLA is a declaration, not a commitment.

How to verify the SLA

Require monthly reports from the provider's ticketing system. If they cannot show you in a table how many tickets, in what times and with what priority they closed — the SLA exists only on paper.

Price

A conversation about IT costs starts with a single question: what exactly are we buying?. In practice there are three types of billing: flat fee, hourly, and mixed (base + overage). Each makes sense in a different scenario.

  • Flat fee — a predictable cost, best for companies with a stable number of users and systems.
  • Hourly — flexible, but hard to budget for a whole year.
  • Mixed — the base covers 80% of the work, overage is billed separately; the most common model in SMEs.

What to watch for in a quote

The rate alone is not everything. Check what exactly the price covers, what the hour cap is, how out-of-scope projects are priced and whether travel is billed. The gap between the cheapest and most expensive offer in Poland can be 3–4× — and it usually comes down to what is "in the price" and what is not.

Key takeaways

  • Significantly reduced risk of ransomware and customer data leaks.
  • Relying only on antivirus instead of layered protection (EDR + MFA + backup).
  • Treat the topic of "IT security audit — what it covers" as a project, not a one-off purchase — the best results come from a step-by-step approach.

Frequently asked questions

Check your company's security level

We invite you to a free cybersecurity consultation. We will walk through a checklist of 30 key areas (MFA, backup, EDR, training) and point out priorities for the next quarter.