Secure IT for business
PL

IT infrastructure and systems audit

An audit that reveals risk, cost and the right order of action.

We assess infrastructure, systems, security and IT governance. Every material finding is linked to evidence, business impact and a practical recommendation. Where agreed, we also indicate the likely scale of work and investment required to put the environment in order.

The first discussion does not require passwords or access to your systems.

01Know what requires action now
02Know what can safely wait
03Plan budget, ownership and sequence

When an audit makes sense

Facts first. Technology decisions second.

An audit is most valuable when it answers a specific business question — not when it exists merely to tick another compliance box.

01

Taking over or changing IT support

You need to understand the environment before a new team accepts responsibility for its operation.

02

Growth, investment or a new location

You need to know what can be expanded safely and what should be put in order first.

03

An incident or recurring outages

You want to understand causes, dependencies and risks instead of responding only to the next symptom.

04

Independent review for management

You need an evidence-based view before a budget decision, provider change or important project.

Audit scope

We assess technology as one connected business system.

The scope reflects your organisation and objective: a complete review, pre-investment assessment, post-incident verification or an independent review of a selected area.

01

Infrastructure and network

Servers, devices, LAN, Wi-Fi, VLANs, firewalls, connectivity and documentation.

02

Systems and cloud

Microsoft 365, email, domains, licensing, configuration, integrations and AI tools.

03

Identity and access

Accounts, roles, MFA, administrative privileges and user lifecycle.

04

Backup and continuity

Backup coverage, retention, recovery tests, RPO/RTO and emergency procedures.

05

Endpoint and server security

Patching, EDR/antivirus, encryption, event logging and monitoring.

06

IT governance

Contracts, ownership, tickets, inventory, ISMS, supplier risk, KSC/NIS2 and rules for AI use.

Step-by-step process

Know what we assess, who is involved and when decisions are made.

We do not begin with scanning or a request for unrestricted access. We first agree the objective, boundaries and a safe way to gather evidence.

  1. 01

    Objective and scope

    We define the decision the audit should support, the areas included and all explicit exclusions.

  2. 02

    Safe access plan

    We identify contacts, minimum privileges, working methods and any action that requires separate approval.

  3. 03

    Evidence gathering

    We analyse documentation, interview responsible people and verify configurations within the agreed scope.

  4. 04

    Risk and effort assessment

    Each finding is linked to business impact, priority, dependencies and an indicative scale of work.

  5. 05

    Report and next decisions

    We deliver the findings, review them with decision-makers and organise the next 30/90 days of action.

Working with your current IT team

A second pair of eyes, not an investigation of your IT staff.

What remains after the audit

Documents for action, not a compliance declaration.

The exact deliverable set follows the agreed scope. We describe every material finding within the assessment scope: with evidence, potential impact, a recommendation and an owner for the next action.

01

Inventory

Devices, services, accounts, licences and dependencies identified within the agreed assessment scope.

02

Findings register

Current state, evidence, deviations and constraints, including potential business impact and risk within the assessment scope.

03

30/90-day plan

Remediation order, ownership, dependencies and proposed delivery dates.

04

Executive summary

Key risks, decisions and indicative effort explained in language useful to non-technical stakeholders.

Method and boundaries

Evidence-based assessment without shortcut compliance claims.

The standard audit focuses on technical condition, risk and action priorities. With respect to KSC/NIS2, the AI Act, ISO/IEC 27001 and GDPR, we identify areas for further review. We do not issue binding opinions or confirmations of compliance.

01

How we assess the environment

We combine interviews, documentation and technical configuration evidence. We relate them to agreed control questions, identifying potential gaps and areas for further review. We do not determine the organisation’s sector, role or legal duties.

02

What the standard audit is not

Sigma Vision does not perform penetration tests or certification audits and does not issue legal opinions. The client commissions penetration tests, legal assessment, DPO work and certification directly from an appropriate specialist or organisation.

Transparent pricing

The price follows the actual scope.

We do not publish an arbitrary “from” price that does not describe a real environment. Before work starts, the client knows the price, scope, exclusions and pricing assumptions.

  • number of locations
  • users and devices
  • servers and cloud services
  • documentation quality
  • verification depth
  • on-site work and access conditions

Named accountability

Know who leads the work and who owns each area.

Before work begins, we identify the audit lead and the specialists required by the scope. Accountability is not replaced by an anonymous form or an automated scan alone.

Meet the Sigma Vision team →

Mateusz Korpusik

IT environment administration and operational security, business continuity, incident diagnosis, technical implementation of audit recommendations and quotation of the resulting work.

Tomasz Czepek

Systems architecture, implementation and connecting technology with business objectives. Risk analysis, environment development planning and translating audit findings into an actionable change plan.

Free pre-audit checklist

10 questions for the person responsible for your IT.

We do not need your email address to demonstrate how we approach an audit. The answers help identify whether the main issue is security, continuity, documentation or unclear ownership.

  1. 01Who owns the administrative accounts, domains and cloud services?
  2. 02When was data last restored from backup as a test?
  3. 03Are privileged accounts and email protected with MFA?
  4. 04Is there a current inventory of devices, licences and users?
  5. 05Does an employee departure trigger a formal access-removal process?
  6. 06Are guest networks, devices and critical systems separated?
  7. 07Are updates and endpoint protection monitored centrally?
  8. 08Does the agreement define SLA, ownership, escalation and data ownership?
  9. 09Is there an inventory of AI systems, their owners, processed data, human oversight and initial risk classification?
  10. 10Does the company have an incident and outage plan and, where the Polish KSC Act may apply, identified technical and organisational areas requiring further review?

FAQ

Questions worth asking before an auditor enters your environment.

These answers describe our standard approach. Final working rules always follow the agreed scope and the project’s actual conditions.

How long does an IT infrastructure and systems audit take?

We set the schedule after a short scoping discussion. It depends on the number of locations, users and devices, cloud complexity, available documentation and assessment depth. Before work starts, we provide the stages, preparation requirements and planned report review date.

Can the audit interrupt business operations?

We begin with documentation, interviews and read-only verification. Any active action that could affect a service requires separate approval, a maintenance window and a rollback method. We do not perform disruptive testing without the client’s knowledge and consent.

Do we need to provide every password before the audit?

No. We do not request passwords or administrative access during initial scoping. Later, we use only the minimum access required, preferably named temporary accounts protected with MFA and limited in time. Access should be revoked or changed after completion.

We already have an IT team or provider. Is an audit still useful?

Yes. An audit is not about assigning blame or assessing one person. It gives management and the IT team an independent view of the environment, validates priorities and reveals dependencies that are difficult to see during day-to-day support.

Is this a penetration test or a formal assessment of KSC/NIS2, ISO 27001, GDPR or AI Act compliance?

No. The technical audit organises available evidence about systems and their configuration, then identifies technical and organisational areas of potential risk. We do not determine the organisation’s role or legal duties, issue legal opinions, or confirm regulatory or certification compliance. The client commissions penetration tests, legal assessment, DPO work and formal certification directly from an appropriate specialist or organisation.

Can the audit identify KSC-related areas worth further review?

Yes. Within the agreed scope, we identify technical and organisational areas worth further review, such as system security, incident handling, business continuity or supply-chain security. We do not determine sector, entity status or statutory duties; these require a separate assessment by an appropriate specialist.

What determines the audit price?

The main factors are the number of locations, users, devices and systems, cloud-service scope, documentation quality, on-site work, verification depth and access conditions. Before work starts, the client receives the agreed scope, exclusions, schedule and price.

What should we prepare for the first discussion?

The audit objective, a list of locations, approximate user and device counts, key systems and the person responsible for IT are enough to begin. Missing documentation does not prevent the discussion — it may itself be an area that needs attention.

What happens after the report is delivered?

We review the main risks, dependencies and recommended order of action. Remediation may be completed by the client’s current team, another provider or Sigma Vision under a separately agreed scope. The audit does not require the client to purchase implementation or ongoing support from us.

A first step without granting system access

Start with the audit objective, not your passwords.

Describe the decision you need to make, your locations and the approximate environment size. We will respond with the questions required to define the scope.

Describe your environment →