A fixed-fee security audit costs the same whether you are ready or not \u2014 the fee is fixed, but the findings are not. An unprepared team spends the first paid hour on inventory archaeology: who has the server password, where the backups actually go, whether the departed finance manager's account is still live. A prepared team starts at check one with the evidence already on the table.
Here is the one-day preparation checklist. It works for a paid outside audit, and it works exactly the same for the free version \u2014 the 45-point self-audit you run on yourself.
1. The readiness packet: six documents. Asset inventory (every device, account and subscription, with an owner column), access list (who can reach what; flag admins and anyone who left in the last year), a one-page policy (password rule, MFA rule, backup schedule, the 2am phone line), the incident and near-miss log (a phishing email someone almost clicked is evidence, not confession), the vendor list (who holds your data), and backup evidence \u2014 the last three restore tests, dated. If a document does not exist, that fact is the first finding; write it down and keep moving.
2. Score yourself first. Run the interactive 45-check scorecard the day before, honestly. Three reasons, all money: no finding surprises you (an audit where the buyer gasps becomes an argument), you pre-close the cheap failures overnight, and you pay for insight instead of discovery \u2014 fixed-fee audits assume a walkthrough, not archaeology.
3. The fix-first ten. Under a day each, heaviest findings removed first: MFA on every admin account; remove departed staff (every account older than the last offboarding is a finding with your name on it); patch the internet-facing things (router, CMS, anything with a public IP); run one restore test and screenshot it; kill shared passwords; move registrar and DNS to a company mailbox; turn on device encryption on every laptop; revoke stale API keys; write the 2am call line; screenshot everything you fixed.
4. The evidence folder. One folder, numbered to the 45 checks, dated files: 01-mfa-admin.png, 17-restore-test-2026-09-11.pdf. When the walkthrough hits check 17, you open folder 17 \u2014 ten seconds instead of a "let me get back to you." Screenshots over promises: a settings page with the date visible beats a paragraph saying "we do that." Redact live secrets and customer lists before anything leaves the building.
5. The eight questions you will be asked. Who has admin rights, and when did you last check? How does an ex-employee lose access the day they leave? What gets restored after ransomware, and how do you know the backup is good? What did your last phishing near-miss change? Where are the passwords for the router, registrar and server? Which vendor could hurt you most? What is on the public internet that you think is not? And if the owner's phone was stolen tonight \u2014 what happens by morning?
6. Hand over carefully, not wide open. Least privilege first: read-only accounts where read-only exists, a named contact for the rest. Secrets never travel by email or chat \u2014 password-manager share links with expiry dates, or not at all. Rotate anything raw the day the engagement ends. Redact customer names and staff personal data from whatever leaves.
7. The one-page current-state memo. Write it last: what we protect (the crown jewels, named), what we know is weak (your honest scorecard failures and why they are open), what we want from this audit ("tell us the order to fix things in, and what we can defer"). This converts the engagement from find what you find to confirm, correct, sequence \u2014 which is what produces a fix plan you will actually execute.
A worked example. An 11-person logistics firm booked an audit after a customer's security questionnaire came back "unable to verify." Prep took one working day \u2014 most of it spent hunting two SaaS tools nobody remembered buying. Scorecard: 31 of 45. Seven of the fourteen failures were in the fix-first ten and closed by the next morning: admin MFA, two departed-staff accounts, a restore test that restored, the registrar moved off a founder's personal mailbox, screenshots for all five. The audit was one 41-minute walkthrough call. The report arrived day three: seven findings marked remediated during preparation, five medium, two critical \u2014 the forgotten SaaS tools holding customer data with no MFA. Total surprise: zero. The questionnaire was resubmitted with the report attached, and the deal that had been cooling for a month closed the following week.
The unprepared version of the same audit is easy to price: the walkthrough becomes two calls, three of five days go to discovery you pay for either way, and the findings arrive later, hit harder, and change nothing fast.
The full checklist \u2014 the six documents, the fix-first ten with the controls behind each one, the evidence folder convention, the hand-over rules and the audit-readiness numbers \u2014 is on my ops-notes site: Security Audit Preparation Checklist.
Top comments (0)