Security Baseline Audit · USD 89
Better than you expected, with two gaps that matter
Eleven control areas reviewed from supplied evidence. Nine are in reasonable shape for your size. Two are not.
You came in expecting to be told everything was wrong. It is not. For a 19 person company that has never done this, the baseline is better than most, and this audit is short because there is not much to say about the parts that work. Two findings are genuinely serious and both are fixable this month.
Offboarding and backup restore testing are the two real gaps. Nobody has ever tested whether your backups restore, and three former contractors still have active access to production tooling. Everything else is proportionate to your size and stage.
Scope
What was reviewed, and what was not
| Evidence supplied | Reviewed | Gap |
|---|---|---|
| Identity provider user and group export | Yes | None |
| Cloud IAM policy export | Yes | None |
| Backup configuration screenshots | Yes | No restore evidence |
| Device management report | Yes | None |
| Vendor list with data categories | Yes | None |
| Incident response document | Yes | None |
| Secrets management description | Yes | None |
| Logging and alerting config | Partial | Retention period not stated |
| Network architecture | Described only | No diagram supplied |
Summary
Control areas at a glance
| State | Priority | |
|---|---|---|
| Multi-factor authentication | Enforced everywhere | None |
| Password and secrets management | Managed, adopted | None |
| Device encryption | All 21 devices | None |
| Production access control | Role based, sensible | None |
| Offboarding | No process exists | Critical |
| Backup configuration | Configured correctly | None |
| Backup restore testing | Never performed | Critical |
| Logging and retention | Logging on, retention unclear | High |
| Vendor review | Informal | Medium |
| Incident response | Document exists, untested | Medium |
| Security training | None | Low at this size |
Six areas need nothing. That is unusual for a first audit and worth saying plainly: whoever set up your identity and device management did it properly, and you should keep doing whatever that was.
Findings
The two that matter
| # | Finding | Why it matters | Severity |
|---|---|---|---|
| F1 | Three former contractors retain active accounts, two with production database read access. Last active 4, 7 and 11 months ago. | Access that nobody is monitoring, held by people with no current relationship and no contractual obligation to you. | Critical |
| F2 | Backups are configured and have never been restored. No documented restore procedure and no recorded restore time. | An untested backup is an assumption. The failure mode is discovering during an incident that the restore does not work or takes two days. | Critical |
| F3 | Log retention period not documented and appears to default to 30 days in two systems | Thirty days is shorter than the typical time to discover an incident. You would have no record of how it started. | High |
| F4 | No vendor review before adopting tools that process customer data. Eleven such vendors identified. | Common at your size and increasingly asked about by enterprise customers during procurement. | Medium |
| F5 | Incident response document names a person who left in March | The document is otherwise sound. It has simply not been read since it was written. | Medium |
F1 and F2 together are the whole urgency of this report. Both can be closed in a working day, and neither requires a budget.
Remediation
Ninety days, in priority order
- This week
Revoke the three contractor accounts
Check access logs for the last 12 months on all three before revoking, so you know whether anything was accessed after the engagement ended. Then revoke, and record that you did.
- This week
Write a four line offboarding checklist
Identity provider, cloud console, code repository, password manager. Four lines in a shared document, triggered by anyone leaving. This is the whole fix for F1 recurring.
- Within two weeks
Restore a backup to a scratch environment
Actually do it, time it, and write down how long it took and what broke. Until this has been done once, your recovery position is unknown rather than good.
- Within a month
Set and document log retention
Twelve months where the cost allows, ninety days as a minimum. Write the number down so the next audit has something to check against.
- Within 90 days
One page vendor review, applied to new tools only
Do not try to retrospectively review eleven vendors. Apply it from now on and pick up the existing ones at renewal.
- Within 90 days
Read the incident document aloud in a meeting
Thirty minutes, whole team. Fix the names as you go. A tabletop exercise is the grown-up version and this is the version a 19 person company will actually do.