Knowing where your IT stands

It's hard to plan when you can't see where you are. Regular alignment audits measure your setup against best practice, with prioritised findings.

A steel engineer's set square resting flush against a frosted glass block

In short

It is hard to plan when you cannot see where you are. An alignment audit measures your setup against a written standard and returns prioritised findings. The standard is the part that matters: without one, an audit produces opinions rather than a plan.

It is hard to plan well when you cannot clearly see where you are today. Risks and gaps tend to surface only when something breaks, which is the most expensive moment to find them.

An alignment audit measures your environment against a written set of standards and returns a prioritised list of where it differs. That is the whole idea, and the important word is standards.

Why the standard comes first

This is the part most people skip, and skipping it is why so many IT audits produce a document nobody acts on.

Without an agreed standard, an audit becomes one engineer's opinion of what good looks like. Ask three engineers and you get three lists, each defensible, none comparable. Run the exercise again next year with a different engineer and you cannot tell whether anything improved.

With a standard, the audit becomes a measurement. Every item is a specific, written expectation: every server has monitoring; every account has multi-factor authentication; backups are tested to a defined schedule. Each one is either met or not met. The findings are the gaps.

That is also what makes the result repeatable. Two audits six months apart, against the same standard, show movement rather than mood.

What gets measured

The standards set covers the areas where drift causes the most damage:

  • Security controls. Multi-factor authentication coverage, administrative rights, patching currency, endpoint protection.
  • Backup and recovery. Not whether backups run, but whether restores have been tested, and whether the recovery time matches what the business assumes.
  • Lifecycle. Which hardware and operating systems are approaching end of support, and what that means for cost and risk over the next year.
  • Documentation. Whether the environment is recorded well enough that someone other than the usual engineer could work on it.
  • Business continuity. What happens on the bad day: the line, the building, the key system.

Findings ranked by consequence, not severity

A list of two hundred deviations is not a plan. It is a reason to do nothing.

Findings are ranked by business consequence, so the output is a short list of what genuinely matters and a longer list of what to schedule. A missing patch on an isolated test machine is not the same as an untested backup, even if a scanner scores them similarly.

The audit produces the input to a roadmap, not a replacement for one. Once you know the gaps and their consequences, sequencing them by priority and budget is the next conversation, which we cover in an IT plan that runs ahead.

What surprises people

Two things, consistently.

The first is how much has drifted without any decision being made. Nobody chose to leave a service account without MFA or to let a firewall run three firmware versions behind. It happened because there was no mechanism that would notice.

The second is how many findings are free to fix. A significant proportion of every audit is configuration rather than capital: rights that should be removed, settings that should be enabled, accounts that should be closed. The expensive items are usually few, and knowing which they are is what makes the budget conversation straightforward.

How often

Regularly enough to catch drift, which for most businesses means at least annually, with the highest-consequence items checked more frequently.

The findings then feed the quarterly review, so progress against the previous audit is visible rather than asserted. An audit that happens once and is never repeated tells you where you were on one afternoon.

Where it sits in the Technology Success Program

The alignment audit is the measurement step. It establishes where you are, so that planning is grounded in your actual environment rather than in assumptions about it.

For businesses facing NIS2 questions, it also produces the evidence. Article 21 sets ten minimum risk-management measures, and Ireland's NCSC published guidance for boards in July 2026 making clear that senior management are expected to be able to evidence these controls. A standards-based audit with dated findings is exactly that evidence, and it is far easier to produce on a schedule than in response to a customer questionnaire.

To find out where your IT actually stands, get in touch or read about the Technology Success Program.

All field notes

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.