Cybersecurity

IT security audit for small businesses in Nice and the Alpes-Maritimes

An IT security audit takes full stock of your estate, your backups and your access rights, then sets it all down in a written report that ranks every risk by severity and by the cost of putting it right. At MZ Informatique it takes half a day on site, two to three days of analysis and a one-hour debrief. The first audit is free and carries no obligation, and the report is yours to keep.

What is an IT security audit for a small business?

An IT security audit is a complete stock-take of your IT, carried out on site and then written up. It is not a questionnaire filled in remotely: we open the cabinet, we test a backup restore, and we watch how your teams actually work. The audit covers four areas: the estate (workstations, servers, mobiles, network equipment), the backups and whether they really restore, the user accounts and remote access, and finally the updates and the protections installed.

At the end you hold a single document that ranks every risk by severity and by the cost of correcting it. The first audit is free and carries no obligation, and the report stays yours even if you do not go on to work with us.

  • The report is yours to keep, even if you do not work with us.
  • No interruption to your business: the tests run outside critical hours.
  • The report is readable by a company director, not only by an IT specialist.

How does the audit run, step by step?

In three stages, over roughly a week. Half a day on site: an inventory of workstations, servers, mobiles and network equipment, a check of the backups and of a real restore, a review of user accounts and remote access, and a look at updates and anti-virus. Two to three days of analysis: mapping the sensitive data, testing passwords, looking for anything exposed publicly and for credentials already known to have leaked. A one-hour debrief: we present the written report and the action plan prioritised over three, six and twelve months.

Allow about a week between the visit and the delivery of the report. Your teams keep working: any test likely to get in the way is run outside opening hours.

We travel to Nice, Sophia Antipolis, Cannes, Antibes, Grasse, Menton and Monaco. The visit fits your diary, not ours.

What does the audit report contain?

An inventory, a list of risks and an action plan — in that order, and nothing superfluous. The inventory records what actually exists, including the machines nobody claims any more. The risk list ranks each finding by severity and by the cost of correcting it, in plain language, without jargon. The action plan spreads the fixes over three, six and twelve months, separating what is essential from what is merely comfortable.

We also hand you the list of fixes you can apply yourself, without us. That is our way of leaving you the choice: an audit that served only to sell the next stage would be worth nothing.

Which weaknesses do we find most often?

Always the same three. In very nearly every estate we audit on the Côte d'Azur we find remote access open to the internet without two-factor authentication, backups stored on the same network as the data — and therefore encrypted along with everything else in an attack — and accounts belonging to former employees that were never disabled.

The good news fits in one sentence: these open doors are few, and they close quickly. None of the three is expensive to fix. That is precisely what the audit is there to establish before a penny is spent.

Recurring findings recorded during our audits in Nice and the Alpes-Maritimes.

How much does an IT security audit cost?

The budget depends on the number of workstations and servers, not on the length of the report. For a small business in the Alpes-Maritimes with ten to thirty workstations, the quotation covers a full security audit — with the first audit still free. The initial remediation that follows, a one-off engagement that closes the weaknesses identified and puts the backups back on a proper footing, is costed after the same survey.

The final figure depends on three factors only: the number of workstations and servers, whether or not there is a file server to secure, and the level of monitoring you want. No three-year lock-in, and no surprise invoices.

Every quotation separates what is essential from what is merely comfortable, so that you can spread the investment across several financial years if you need to.

Frequently asked questions

Security audit: what we get asked

How long does a security audit take for a firm with twenty workstations?

Half a day on site, then two to three days of analysis and a one-hour debrief. Allow about a week between our visit and the delivery of the written report. Your teams keep working: any test that might get in the way is run outside opening hours.

Are anti-virus and a backup enough to protect a small business?

No, but they are the foundation. Anti-virus does not stop a stolen password, and a backup left permanently connected to the same network is encrypted along with everything else. You need to add two-factor authentication on remote access and on email, an offline or offsite backup that is tested regularly, and the removal of unused accounts.

Is the report ours if we do not carry on with you?

Yes. The audit report is yours, including the list of fixes you can apply yourself or hand to another supplier. We keep nothing back that would stop you having the work done elsewhere.

Do you work in Monaco and across the rest of the Alpes-Maritimes?

Yes. We travel to Nice, Sophia Antipolis, Cannes, Antibes, Grasse, Menton and Monaco. Emergency call-outs in Nice and its immediate surroundings are handled the same day as far as our availability allows; elsewhere in the department, within 24 to 48 hours.

Where does your IT security actually stand?

A free audit, with no obligation, on site in Nice, Sophia Antipolis, Cannes or Monaco. You leave with a written stock-take; what you do next is up to you.