Preparing for an IT Security Audit: A 30-Day Remediation Roadmap

    Consult Circle6 min readCybersecurity
    Preparing for an IT Security Audit: A 30-Day Remediation Roadmap

    CONSULT CIRCLE | SECURITY & COMPLIANCE

    What auditors look for, what they find, and a week-by-week plan for the month before the audit.

    Audits rarely fail on sophisticated technical weaknesses. They fail on missing evidence, stale access, undocumented processes and controls that exist in principle but cannot be demonstrated.

    Thirty days is enough to fix most of what is commonly found, provided you work in the right order. This roadmap prioritises findings that are both frequently raised and realistically fixable in the time available.

    Before week one: Get the audit scope and the control framework in writing. Preparing against the wrong standard is the most expensive mistake available, and it is entirely avoidable by asking.

    Week 1: Establish what is true

    You cannot remediate what you have not measured. This week is assessment, not fixing.

    • Confirm audit scope, the framework, the period covered and the evidence format expected.
    • Produce an asset inventory: endpoints, servers, cloud resources, network devices, applications and data stores.
    • Extract a full user access list, including privileged accounts, service accounts and any external or third-party access.
    • Run a vulnerability scan across the estate.
    • Collect existing policy documents and note which are missing, out of date or unapproved.
    • Identify where evidence lives for each control, and where no evidence exists at all.
    Deliverable for week 1: A gap list mapped to the control framework, with each gap marked as fixable in thirty days, fixable later, or requiring a compensating control and a documented plan.

    Week 2: Access and identity

    Access findings are the most commonly raised and among the quickest to resolve.

    • Disable accounts for leavers. Reconcile the user list against the HR record; the gap is usually larger than expected.
    • Review privileged accounts and remove administrative rights that are not required.
    • Enforce multi-factor authentication, prioritising administrators, remote access and anything internet-facing.
    • Inventory service accounts, identify their owners, and document what each is for.
    • Remove or review shared accounts, and where one genuinely cannot be removed, document the compensating control.
    • Review third-party and vendor access, and remove anything dormant.
    • Evidence a completed access review with dates and approvers. The review itself is frequently the control being tested.

    Our Active Directory health check guide covers the identity hygiene most of this depends on.

    Week 3: Technical controls

    • Patch critical and high-severity vulnerabilities on internet-facing and business-critical systems first.
    • Confirm endpoint protection is deployed everywhere, reporting correctly, and that gaps are investigated rather than tolerated.
    • Verify backups run successfully, and test a restore. A backup that has never been restored is not evidence of anything.
    • Confirm logging is enabled on key systems and retained for the period the framework requires.
    • Review firewall rules and remove anything permissive, temporary or unexplained.
    • Check encryption at rest and in transit for systems holding sensitive data.
    • Confirm change control is being followed and that recent changes have records.

    Week 4: Documentation and rehearsal

    The week where evidence is assembled and the process is tested, rather than assumed.

    • Update policies: acceptable use, access control, incident response, business continuity, data retention.
    • Ensure policies are approved and dated. An unapproved policy is a draft, and auditors treat it as one.
    • Assemble the evidence pack, organised by control so nothing has to be searched for during the audit.
    • Run a tabletop incident response exercise and record it. The record is itself evidence.
    • Brief the people who will be interviewed on scope and on which documents apply to them.
    • Complete a dry run against the control list and note anything still unevidenced.
    • Document remaining gaps with an owner and a target date. A known, planned gap is treated very differently from one discovered by the auditor.

    What auditors most often find

    FindingWhy it happensFix time
    Leaver accounts still activeNo reliable link between HR and identity managementDays
    Excessive administrative privilegeRights granted for a task and never removedDays to weeks
    No evidence of access reviewsReviews happen informally and are not recordedDays
    Backups never restore-testedBackup success is monitored; restore capability is assumedDays
    Missing or unapproved policiesWritten once, never reviewed or formally approvedDays
    Unpatched systemsNo consistent patching cycle, or exceptions never revisitedWeeks
    Insufficient log retentionDefaults left in place, shorter than the framework requiresDays to configure, longer to accumulate
    No tested incident response planPlan exists on paper and has never been exercisedDays for a tabletop
    Undocumented third-party accessGranted during a project and never reviewedDays

    Table 1 — Common audit findings and realistic fix times.

    Do not fabricate evidence: Backdating approvals or manufacturing review records turns a control finding into an integrity finding, which is a materially worse outcome. A documented gap with an owner and a date is a normal audit result. Falsified evidence is not.

    Where to go next

    Frequently Asked Questions

    How do we prepare for an IT security audit?

    Establish the scope and framework, assess against it to produce a gap list, then remediate in priority order: access and identity first, then technical controls, then documentation and evidence. Thirty days is enough for most commonly raised findings.

    What do auditors look for most?

    Evidence that controls operate, not just that they exist. Access reviews with dates and approvers, tested restores, approved policies, and records of changes and incidents.

    What if we cannot fix everything in time?

    Document the remaining gaps with an owner, a plan and a target date, and put a compensating control in place where you can. A known and managed gap is treated far more favourably than one the auditor discovers.

    How long should we retain logs?

    Whatever your control framework or regulator specifies, which is often longer than the default configuration. Check the requirement rather than assuming, because retention cannot be applied retrospectively.

    Is a tabletop exercise enough for incident response?

    For most audits, a documented tabletop exercise demonstrates the plan has been tested and that participants know their roles. It is far better than an untested plan, and it can be arranged within the month.

    Talk to Consult Circle

    We help organisations prepare for security audits, from gap assessment through remediation to the evidence pack. Book a free 30-minute call - 0203 916 5593 - info@consultcircle.com

    Share this article: