Back to blogCybersecurity

How to conduct a cybersecurity pre-audit?

NRNicolas Renard·April 27, 2026· 10 min read

A cybersecurity pre-audit does not aim to exploit specific technical vulnerabilities, unlike a penetration test. It assesses the organization's overall posture: infrastructure, access management, backups, disaster recovery plan, vulnerability management, monitoring. The goal is to produce a risk map within a few days, not after several weeks of in depth technical testing.

The domains to cover first are those whose failure has the most consequences. Lax access management (shared accounts, no multi factor authentication) or backups that have never been tested rank, year after year, among the most cited causes of incidents reported to Cybermalveillance.gouv.fr, the French public body that supports victims of cyberattacks, well ahead of the exploitation of sophisticated software vulnerabilities.

Analyst focused on dual monitors displaying code, representing the work of a cybersecurity pre-audit

Why SMEs are particularly exposed

In its 2024 activity report, Cybermalveillance.gouv.fr recorded more than 420,000 assistance requests, up nearly 50% year over year, with a growing share coming from businesses, mostly small and midsize companies. Phishing remains the top reported threat, involved in about 73% of intrusions suffered by SMEs in 2024. According to the OpinionWay 'Cyber Impact' study commissioned by the agency, 68% of SMEs spend less than €2,000 a year on IT security, a budget far below the average cost of an incident.

In its 2024 Cyber Threat Overview, the French cybersecurity agency ANSSI handled 4,386 security events and confirmed 144 ransomware compromises, up 15% year over year. SMEs alone account for 37% of recorded ransomware victims, the hardest hit category ahead of large enterprises and public bodies. These figures capture only a fraction of real incidents, since most SMEs never report the attacks they suffer.

Cybersecurity Diagnostic·See a diagnostic preview

The concrete steps of a pre-audit

  1. Scope the exercise: which systems, which sites, which teams are covered by the pre-audit, and over what timeframe.
  2. Gather existing documentation: network diagram, asset inventory, backup policy, contracts with IT providers.
  3. Interview business and IT managers about actual practices, not just written procedures — the gap between the two is often the most revealing signal.
  4. Verify critical points concretely: test a backup restore, review the list of privileged accounts, examine login logs from recent months.
  5. Cross reference findings against a recognized framework (ANSSI's cyber hygiene guide, ISO 27001 controls) to objectively rate the maturity level.
  6. Report results as prioritized risks, each with a severity level, an estimated remediation effort, and a named owner.

Domains to examine first

DomainWhat is checkedFrequent red flag
Access managementPrivileged accounts, MFA, access reviewsShared accounts, former employees still active
BackupsFrequency, isolation, restore testingNo restore tested in over a year
Workstations and serversPatch level, antivirus/EDR, encryptionUnsupported systems still in production
Network and external exposureExposed services, VPN, segmentationOpen ports or services with no documented justification
Disaster recovery planExistence, last update, real-world testPlan written once and never revisited
AwarenessStaff training, phishing simulationsNo awareness action since hiring

For a company without a dedicated security team, the challenge is as much organizational as technical: who decides in the event of an incident, who has access to what, when the last successful restore test actually happened. These are simple questions to ask, yet they often go unanswered simply because nobody has formally asked them. The Verizon DBIR 2024, which analyzed more than 10,000 confirmed data breaches worldwide, found that 68% of incidents involve a non-malicious human element — a misconfiguration, a click on a malicious link, a reused password — far more often than a sophisticated technical flaw.

Common mistakes to avoid

  • Confusing a pre-audit with a penetration test: the former assesses overall posture, the latter exploits specific technical flaws within a narrow scope.
  • Focusing only on technical aspects without questioning processes (who decides, who alerts, who remediates) even though most incidents have a human or organizational component.
  • Producing an exhaustive fifty-page report instead of a short, prioritized list of genuinely actionable risks.
  • Not setting a follow-up date: a pre-audit without a dated action plan often becomes a dead letter six months later.

A well run pre-audit ends with a list of risks ranked by impact and remediation effort, directly actionable, rather than a report nobody will read to the end. Its limit is real, though: it captures a state at a given point in time and replaces neither a penetration test for publicly exposed systems, nor a certification audit if the company is pursuing ISO 27001 or must meet specific contractual requirements.

Ready to assess your organization?

Try for free