How to conduct a cybersecurity pre-audit?
A cybersecurity pre-audit does not aim to exploit specific technical vulnerabilities, unlike a penetration test. It assesses the organization's overall posture: infrastructure, access management, backups, disaster recovery plan, vulnerability management, monitoring. The goal is to produce a risk map within a few days, not after several weeks of in depth technical testing.
The domains to cover first are those whose failure has the most consequences. Lax access management (shared accounts, no multi factor authentication) or backups that have never been tested rank, year after year, among the most cited causes of incidents reported to Cybermalveillance.gouv.fr, the French public body that supports victims of cyberattacks, well ahead of the exploitation of sophisticated software vulnerabilities.

Why SMEs are particularly exposed
In its 2024 activity report, Cybermalveillance.gouv.fr recorded more than 420,000 assistance requests, up nearly 50% year over year, with a growing share coming from businesses, mostly small and midsize companies. Phishing remains the top reported threat, involved in about 73% of intrusions suffered by SMEs in 2024. According to the OpinionWay 'Cyber Impact' study commissioned by the agency, 68% of SMEs spend less than €2,000 a year on IT security, a budget far below the average cost of an incident.
In its 2024 Cyber Threat Overview, the French cybersecurity agency ANSSI handled 4,386 security events and confirmed 144 ransomware compromises, up 15% year over year. SMEs alone account for 37% of recorded ransomware victims, the hardest hit category ahead of large enterprises and public bodies. These figures capture only a fraction of real incidents, since most SMEs never report the attacks they suffer.
Cybersecurity Diagnostic·See a diagnostic preview
The concrete steps of a pre-audit
- Scope the exercise: which systems, which sites, which teams are covered by the pre-audit, and over what timeframe.
- Gather existing documentation: network diagram, asset inventory, backup policy, contracts with IT providers.
- Interview business and IT managers about actual practices, not just written procedures — the gap between the two is often the most revealing signal.
- Verify critical points concretely: test a backup restore, review the list of privileged accounts, examine login logs from recent months.
- Cross reference findings against a recognized framework (ANSSI's cyber hygiene guide, ISO 27001 controls) to objectively rate the maturity level.
- Report results as prioritized risks, each with a severity level, an estimated remediation effort, and a named owner.
Domains to examine first
| Domain | What is checked | Frequent red flag |
|---|---|---|
| Access management | Privileged accounts, MFA, access reviews | Shared accounts, former employees still active |
| Backups | Frequency, isolation, restore testing | No restore tested in over a year |
| Workstations and servers | Patch level, antivirus/EDR, encryption | Unsupported systems still in production |
| Network and external exposure | Exposed services, VPN, segmentation | Open ports or services with no documented justification |
| Disaster recovery plan | Existence, last update, real-world test | Plan written once and never revisited |
| Awareness | Staff training, phishing simulations | No awareness action since hiring |
For a company without a dedicated security team, the challenge is as much organizational as technical: who decides in the event of an incident, who has access to what, when the last successful restore test actually happened. These are simple questions to ask, yet they often go unanswered simply because nobody has formally asked them. The Verizon DBIR 2024, which analyzed more than 10,000 confirmed data breaches worldwide, found that 68% of incidents involve a non-malicious human element — a misconfiguration, a click on a malicious link, a reused password — far more often than a sophisticated technical flaw.
Common mistakes to avoid
- Confusing a pre-audit with a penetration test: the former assesses overall posture, the latter exploits specific technical flaws within a narrow scope.
- Focusing only on technical aspects without questioning processes (who decides, who alerts, who remediates) even though most incidents have a human or organizational component.
- Producing an exhaustive fifty-page report instead of a short, prioritized list of genuinely actionable risks.
- Not setting a follow-up date: a pre-audit without a dated action plan often becomes a dead letter six months later.
A well run pre-audit ends with a list of risks ranked by impact and remediation effort, directly actionable, rather than a report nobody will read to the end. Its limit is real, though: it captures a state at a given point in time and replaces neither a penetration test for publicly exposed systems, nor a certification audit if the company is pursuing ISO 27001 or must meet specific contractual requirements.
Related diagnostic
Ready to assess your organization?
Try for free