IT infrastructure and systems audit
An audit that reveals risk, cost and the right order of action.
We assess infrastructure, systems, security and IT governance. Every material finding is linked to evidence, business impact and a practical recommendation. Where agreed, we also indicate the likely scale of work and investment required to put the environment in order.
The first discussion does not require passwords or access to your systems.
When an audit makes sense
Facts first. Technology decisions second.
An audit is most valuable when it answers a specific business question — not when it exists merely to tick another compliance box.
Taking over or changing IT support
You need to understand the environment before a new team accepts responsibility for its operation.
Growth, investment or a new location
You need to know what can be expanded safely and what should be put in order first.
An incident or recurring outages
You want to understand causes, dependencies and risks instead of responding only to the next symptom.
Independent review for management
You need an evidence-based view before a budget decision, provider change or important project.
Audit scope
We assess technology as one connected business system.
The scope reflects your organisation and objective: a complete review, pre-investment assessment, post-incident verification or an independent review of a selected area.
Infrastructure and network
Servers, devices, LAN, Wi-Fi, VLANs, firewalls, connectivity and documentation.
Systems and cloud
Microsoft 365, email, domains, licensing, configuration, integrations and AI tools.
Identity and access
Accounts, roles, MFA, administrative privileges and user lifecycle.
Backup and continuity
Backup coverage, retention, recovery tests, RPO/RTO and emergency procedures.
Endpoint and server security
Patching, EDR/antivirus, encryption, event logging and monitoring.
IT governance
Contracts, ownership, tickets, inventory, ISMS, supplier risk, KSC/NIS2 and rules for AI use.
Step-by-step process
Know what we assess, who is involved and when decisions are made.
We do not begin with scanning or a request for unrestricted access. We first agree the objective, boundaries and a safe way to gather evidence.
-
01
Objective and scope
We define the decision the audit should support, the areas included and all explicit exclusions.
-
02
Safe access plan
We identify contacts, minimum privileges, working methods and any action that requires separate approval.
-
03
Evidence gathering
We analyse documentation, interview responsible people and verify configurations within the agreed scope.
-
04
Risk and effort assessment
Each finding is linked to business impact, priority, dependencies and an indicative scale of work.
-
05
Report and next decisions
We deliver the findings, review them with decision-makers and organise the next 30/90 days of action.
Working with your current IT team
A second pair of eyes, not an investigation of your IT staff.
What remains after the audit
Documents for action, not a compliance declaration.
The exact deliverable set follows the agreed scope. We describe every material finding within the assessment scope: with evidence, potential impact, a recommendation and an owner for the next action.
Inventory
Devices, services, accounts, licences and dependencies identified within the agreed assessment scope.
Findings register
Current state, evidence, deviations and constraints, including potential business impact and risk within the assessment scope.
30/90-day plan
Remediation order, ownership, dependencies and proposed delivery dates.
Executive summary
Key risks, decisions and indicative effort explained in language useful to non-technical stakeholders.
Method and boundaries
Evidence-based assessment without shortcut compliance claims.
The standard audit focuses on technical condition, risk and action priorities. With respect to KSC/NIS2, the AI Act, ISO/IEC 27001 and GDPR, we identify areas for further review. We do not issue binding opinions or confirmations of compliance.
How we assess the environment
We combine interviews, documentation and technical configuration evidence. We relate them to agreed control questions, identifying potential gaps and areas for further review. We do not determine the organisation’s sector, role or legal duties.
What the standard audit is not
Sigma Vision does not perform penetration tests or certification audits and does not issue legal opinions. The client commissions penetration tests, legal assessment, DPO work and certification directly from an appropriate specialist or organisation.
Transparent pricing
The price follows the actual scope.
We do not publish an arbitrary “from” price that does not describe a real environment. Before work starts, the client knows the price, scope, exclusions and pricing assumptions.
- number of locations
- users and devices
- servers and cloud services
- documentation quality
- verification depth
- on-site work and access conditions
Named accountability
Know who leads the work and who owns each area.
Before work begins, we identify the audit lead and the specialists required by the scope. Accountability is not replaced by an anonymous form or an automated scan alone.
Meet the Sigma Vision team →Mateusz Korpusik
IT environment administration and operational security, business continuity, incident diagnosis, technical implementation of audit recommendations and quotation of the resulting work.
Tomasz Czepek
Systems architecture, implementation and connecting technology with business objectives. Risk analysis, environment development planning and translating audit findings into an actionable change plan.
Free pre-audit checklist
10 questions for the person responsible for your IT.
We do not need your email address to demonstrate how we approach an audit. The answers help identify whether the main issue is security, continuity, documentation or unclear ownership.
- 01Who owns the administrative accounts, domains and cloud services?
- 02When was data last restored from backup as a test?
- 03Are privileged accounts and email protected with MFA?
- 04Is there a current inventory of devices, licences and users?
- 05Does an employee departure trigger a formal access-removal process?
- 06Are guest networks, devices and critical systems separated?
- 07Are updates and endpoint protection monitored centrally?
- 08Does the agreement define SLA, ownership, escalation and data ownership?
- 09Is there an inventory of AI systems, their owners, processed data, human oversight and initial risk classification?
- 10Does the company have an incident and outage plan and, where the Polish KSC Act may apply, identified technical and organisational areas requiring further review?
FAQ
Questions worth asking before an auditor enters your environment.
These answers describe our standard approach. Final working rules always follow the agreed scope and the project’s actual conditions.
How long does an IT infrastructure and systems audit take?+
We set the schedule after a short scoping discussion. It depends on the number of locations, users and devices, cloud complexity, available documentation and assessment depth. Before work starts, we provide the stages, preparation requirements and planned report review date.
Can the audit interrupt business operations?+
We begin with documentation, interviews and read-only verification. Any active action that could affect a service requires separate approval, a maintenance window and a rollback method. We do not perform disruptive testing without the client’s knowledge and consent.
Do we need to provide every password before the audit?+
No. We do not request passwords or administrative access during initial scoping. Later, we use only the minimum access required, preferably named temporary accounts protected with MFA and limited in time. Access should be revoked or changed after completion.
We already have an IT team or provider. Is an audit still useful?+
Yes. An audit is not about assigning blame or assessing one person. It gives management and the IT team an independent view of the environment, validates priorities and reveals dependencies that are difficult to see during day-to-day support.
Is this a penetration test or a formal assessment of KSC/NIS2, ISO 27001, GDPR or AI Act compliance?+
No. The technical audit organises available evidence about systems and their configuration, then identifies technical and organisational areas of potential risk. We do not determine the organisation’s role or legal duties, issue legal opinions, or confirm regulatory or certification compliance. The client commissions penetration tests, legal assessment, DPO work and formal certification directly from an appropriate specialist or organisation.
Can the audit identify KSC-related areas worth further review?+
Yes. Within the agreed scope, we identify technical and organisational areas worth further review, such as system security, incident handling, business continuity or supply-chain security. We do not determine sector, entity status or statutory duties; these require a separate assessment by an appropriate specialist.
What determines the audit price?+
The main factors are the number of locations, users, devices and systems, cloud-service scope, documentation quality, on-site work, verification depth and access conditions. Before work starts, the client receives the agreed scope, exclusions, schedule and price.
What should we prepare for the first discussion?+
The audit objective, a list of locations, approximate user and device counts, key systems and the person responsible for IT are enough to begin. Missing documentation does not prevent the discussion — it may itself be an area that needs attention.
What happens after the report is delivered?+
We review the main risks, dependencies and recommended order of action. Remediation may be completed by the client’s current team, another provider or Sigma Vision under a separately agreed scope. The audit does not require the client to purchase implementation or ongoing support from us.
A first step without granting system access
Start with the audit objective, not your passwords.
Describe the decision you need to make, your locations and the approximate environment size. We will respond with the questions required to define the scope.