Skip to content
GlabIT
GlabIT

Assessment · evidence-based · read-only

IT audit and infrastructure assessment

Evidence-based IT audit services in Romania covering infrastructure, identity, cloud, backups, operations and controls, with a risk-ranked remediation roadmap.

In one sentence

An evidence-based review of your IT environment, operations and controls that identifies material risks, verifies whether expected safeguards are actually working, and provides a prioritised remediation roadmap.

Who it is for

  • Companies without a current, evidence-based view of their IT estate and operational risks
  • Businesses preparing for customer, insurer, board, investor or regulatory scrutiny
  • Organisations preparing for ISO/IEC 27001, NIS2 or DORA work that need a technical baseline before remediation starts
  • Companies changing MSPs, moving to cloud services, integrating an acquisition or preparing for IT due diligence
  • Organisations concerned about identity, backups, unsupported systems, configuration drift or unclear ownership

What the audit is — and is not

An IT audit from GlabIT is a practical technical and operational assessment. We look at what is actually in place, gather evidence that it works (or does not), and tell you what matters most and in what order to fix it. It is not a statutory financial audit, not an ISO certification audit, not a legal opinion, and not a guarantee of compliance or of the absence of undiscovered issues. Where a finding is verified — we saw the configuration, we watched the restore, we checked the account list — the report says so, and “verified” means verified only for the stated evidence, sample, system and date; where we are recommending on the basis of interviews or documents alone, the report says that too.

Areas reviewed

Scope is agreed before the engagement and can cover:

  • IT governance. Ownership, policies, risk management, decision-making
  • Asset inventory. Hardware, software, cloud subscriptions and services; what exists, who owns it, what is unsupported
  • Identity and access management. Directory, MFA coverage, privileged and service accounts, joiner–mover–leaver processes
  • Microsoft 365, Google Workspace and cloud configuration where applicable
  • Endpoint, server and network management. Build standards, management tooling, coverage
  • Patch management and vulnerability handling, including unsupported systems and exceptions
  • Network architecture. Segmentation, firewalls, VPN and remote access
  • Backups. Coverage, immutability, recovery objectives, and evidence of restore testing
  • Logging, monitoring, alert handling and incident-response readiness
  • Change and configuration management
  • Business continuity, disaster recovery and operational dependencies
  • Third parties. MSP oversight, technology suppliers, contractual and access controls
  • Data handling and access controls relevant to the agreed scope

How the evidence is gathered

Depending on scope, the work combines interviews with the people who run the systems, review of policies, contracts and runbooks, configuration sampling from consoles and exports, read-only technical inspection, and validation of selected controls — for example a restore test, an MFA coverage check, a review of privileged group membership. Where sampling is used the report states the sample and does not imply exhaustive testing.

Methodology and frameworks

The review is structured around control areas that are mapped to, or informed by, ISO/IEC 27001 and ISO/IEC 27002, the CIS Controls and relevant CIS Benchmarks, the NIST Cybersecurity Framework, NIS2 Article 21 measures where applicable, DORA requirements where they apply to the client, and the client’s own policies, contracts and control requirements. Which of these are used — and how deep the mapping goes — is agreed in the scope; we do not reproduce the standards themselves, and a mapping in our report is not a certification, accreditation or regulatory decision.

Where it fits

An IT audit is usually the assess stage of an engagement: it gives you the baseline before a compliance programme, before an ISO/IEC 27001 project, before changing providers, or after an acquisition. Its findings can be tested further with a penetration test and fixed through Cybersecurity-as-a-Service or Secure Engineering.

Scope note: findings and recommendations are based on the agreed scope and the evidence made available during the engagement. Regulatory and framework mappings are provided only where included in scope. Certification decisions remain with an accredited certification body where applicable.

Deliverables

What you receive

  • Executive summary

    Material risks, business impact, the overall themes, and the decisions management needs to make — a few pages, written for the board.

  • Detailed findings register

    Each finding with the affected systems or processes, the evidence we saw, the risk, a priority and a specific recommended action. Verified findings are kept separate from recommendations.

  • Risk-ranked remediation roadmap

    Immediate actions plus suggested short- and medium-term priorities, with dependencies; accountable owners are agreed with you, not assigned by us.

  • Control or framework mapping

    Where included in scope, an appendix mapping findings to the agreed framework (ISO/IEC 27001/27002 control areas, CIS Controls, NIST CSF, NIS2 Article 21, DORA). A mapping, not a certification.

  • Architecture and resilience observations

    Diagrams where useful, single points of failure, backup and recovery concerns, and the operational dependencies we found.

  • Closing workshop

    A walkthrough with management and technical teams — priorities, questions, and what happens next.

Engagement model

How it runs

Model
Fixed-price where the estate and evidence scope can be defined; scope, systems, evidence access, interview participants and exclusions agreed in writing. Read-only access by default; no production configuration changes during the audit unless separately authorised.
Typical timeline
Depends on estate size and evidence availability — typically two to four weeks for a single-entity organisation, not a guarantee. Findings are reviewed with you for factual accuracy before the final report.
  1. 01

    Scope

    Which entities, systems, providers and processes are in; which evidence you can give us; who we interview; what is excluded. Written and signed.

  2. 02

    Collect

    Interviews, document review, configuration sampling and read-only technical inspection, per scope. Where we sample, the report says so.

  3. 03

    Verify and draft

    Selected controls are validated rather than taken on trust — does the backup actually restore, does MFA actually cover the admins. Draft findings go to you for a factual-accuracy check.

  4. 04

    Report and workshop

    Final report, roadmap and framework mapping (where in scope), then the closing workshop. Remediation is a separate decision.

FAQ

Questions a sceptical CISO asks

What is the difference between an IT audit and a penetration test?

An IT audit reviews governance, architecture, operations, configurations and the evidence that controls exist and work. A penetration test actively tries to exploit scoped systems to prove what an attacker could do. A compliance gap assessment focuses on the requirements of one named regulation or standard. They can be combined and often are, but they answer different questions and are not interchangeable.

Is this an ISO certification audit?

No. We are not a certification body and this is not a certification, accreditation or statutory audit. Where ISO/IEC 27001 is in scope we map findings to its control areas so you know where you stand before a certification project; the certification decision itself remains with an accredited certification body.

Which standards or frameworks can the audit be mapped to?

By agreement per engagement — ISO/IEC 27001 and 27002 control areas, CIS Controls and relevant CIS Benchmarks, the NIST Cybersecurity Framework, NIS2 Article 21 measures, DORA requirements where they apply to you, and your own policies and contractual control requirements. Not every audit includes every framework; the mapping is defined in the scope.

Will you need administrator access?

Usually read-only or auditor roles are enough — read access to identity, cloud and management consoles, exported configurations, and screen-sharing sessions with your administrators for the rest. Where read-only access is not possible we sample with your staff at the keyboard. Any access is agreed in the scope and removed at the end.

Will the audit interrupt production systems?

It is designed not to. Work is read-only by default and we make no configuration changes during the audit unless something is separately authorised in writing. Restore tests and similar validations are scheduled with you and run against copies or test targets where possible.

Can you work with our MSP or internal IT team?

Yes, and we prefer to — they hold the evidence. We agree up front who provides what, we keep the tone factual, and findings about a provider's work are stated as findings about the estate, not as blame. Where MSP oversight itself is in scope, we say so in the report.

Can GlabIT also remediate the findings?

Yes, as a separate decision after the report — through Cybersecurity-as-a-Service for ongoing security work or Secure Engineering for build and configuration changes. You are equally free to remediate with your own team or provider; the roadmap is written to be usable either way.

How long does an IT audit take?

It depends on the size of the estate and how quickly evidence and people are available. A single-entity organisation with a cooperative IT team typically takes two to four weeks from kick-off to final report; larger or multi-entity estates take longer. We give you a date range in the proposal, not a promise.

Get an evidence-based view of your IT estate

The first step is a scoping call — your estate, the business concerns behind the request, the evidence you can make available, and why you want the audit now. From that we return a written scope and, where the scope can be defined, a fixed price.