🛡️

IT Security Audit Checklist

Run a thorough security audit on any SMB environment. Covers network, endpoints, identity, email, backups, and physical security.

R249 once-off

Instant download • DOCX • XLSX • PDF • 200+ audit points

Audit Domains

  • Network security (firewall, VLANs, Wi-Fi)
  • Endpoint protection (AV, EDR, patching)
  • Identity & access management
  • Email security (SPF, DKIM, DMARC)
  • Backup & disaster recovery
  • Cloud / M365 security
  • Physical security
  • Compliance & policy review
  • Vendor & third-party risk
  • Incident response readiness

Formats

  • Microsoft Word (.docx) — audit report template
  • Microsoft Excel (.xlsx) — scoring sheet
  • PDF — print-ready checklist

Overview

Most SMBs don't have a full-time security team. This audit checklist gives you a repeatable framework to assess an organisation's security posture, identify gaps, and produce a professional findings report. Over 200 audit points across 10 domains, each with severity ratings and remediation guidance.

Who it's for: IT consultants, MSP technicians, and internal IT staff who need to perform security audits for SMBs (10–500 users) without a dedicated security tooling stack.

What You'll Get

Network Security

Firewall rule audit, VLAN segmentation check, Wi-Fi encryption standards, guest network isolation, VPN configuration review, SNMP exposure check, and rogue device detection guidance.

Endpoint Protection

Antivirus/EDR coverage, patch management status, OS version support lifecycle, disk encryption (BitLocker/FileVault), screen lock policy, and application whitelisting review.

Identity & Access

MFA adoption audit, dormant account review, privileged access review, Entra ID (Azure AD) security defaults, conditional access policy evaluation, service account hygiene.

Email Security

SPF/DKIM/DMARC record verification, anti-phishing policy, mailbox auditing, external forwarding rules review, mail flow rules (transport rules) security check, and impersonation protection.

Backup & Recovery

3-2-1 rule validation, backup encryption status, recovery test verification, offsite/cloud replication check, backup monitoring alerting, and DR documentation completeness.

M365 Security (Additional)

Secure Score review, auditing & logging configuration, DLP policy presence, sharing policy for SharePoint/OneDrive, external sharing audit, and Entra ID risk policies.

Why This Checklist?

This checklist is built from real audit work I've done for South African SMBs — not from a textbook. It's designed to be used at a client site with nothing more than a laptop, a browser, and access to their environment. Each domain includes:

  • Audit item — what to check and how to check it
  • Severity rating — Critical, High, Medium, Low, Info
  • Remediation guidance — plain-English steps to fix each finding
  • Evidence field — space to record what you found

The Excel scoring sheet automatically calculates an overall security maturity score by domain, so you can present a professional heatmap to the client.

SA-specific: Includes POPIA data security requirements mapped to audit items, local ISP security checks (Afrihost, Vox, RSAWeb web hosting), and references to South African cybersecurity resources (SABRIC, CSIRT).