Finding the source of the problem

Company IT hardware audit checklist

Almost all companies with more than ten workstations have equipment that no one quite knows what is for, user accounts belonging to people who have already left, and a backup that “must be working”. An audit of the IT infrastructure doesn't need an external consultant or a week's work: it needs a list, two or three hours, and honest answers. This is the list we use when we go into a new company. You can use it yourself or ask us to do it with you.

Before we begin: what is an IT infrastructure audit?

It is a systematic inventory of what the company has (equipment, software, accounts, connections), the state it is in and what is missing to work securely. It is not a technical vulnerability report — it is a snapshot that a manager can read and that serves as a basis for deciding where to invest. If the answer to a question is “I don't know”, note it down as it is: that is the useful information.

Equipment inventory

  • List of all computers, laptops, servers, printers, switches, access points and firewalls, with make, model, serial number and location.
  • Age of each piece of equipment. Rule of thumb: laptops and workstations over 5 years old and servers over 6 are candidates for planned replacement, not urgent repair.
  • Equipment under warranty or with a manufacturer support contract — and the date they expire.
  • Equipment that physically exists but doesn't appear on any list. It always appears.

2. Operating systems and software

  • Operating system version on each workstation and server. Workstations still running Windows 10 have been without free security updates since October 2025 — see what to do in our article on the end of Windows 10 support.
  • Servers on unsupported versions (Windows Server 2012 and earlier, or 2016 reaching end of support in January 2027).
  • Licensing: what Microsoft 365, antivirus, management software and other licences exist, how many are assigned and how many are being paid for without being used.
  • Software installed by users without authorization (remote access tools, personal cloud file managers, online converters).

3. Backups

  • What is backed up: servers, workstations, Microsoft 365 email and files, and management software databases.
  • How often, where and how many versions are kept. If there is only one copy in the same building, there is no backup.
  • Date of the last successful restoration test. If it has never been done, mark it as the first item to resolve.
  • Who receives the alert when a backup fails — and whether anyone reads it.

If this block had weak answers, start here: see how the managed backup with restore testing.

4. Accounts and logins

  • List of active users in the domain and in Microsoft 365. Compare it with the list of current employees: the differences are accounts to be deactivated today.
  • Who has administrator permissions on the workstations, servers and in Microsoft 365. This should be a small and known number.
  • Multi-factor authentication active on all accounts with email and file access — no exceptions for management.
  • Shared accounts (the “reception account”, the “shop user”) and who knows their passwords.
  • External supplier access: who enters your network, with what credentials and whether they still need to do so.

5. Network and internet connection

  • Network diagram, even if hand-drawn: where the rack is, what switches exist, how the Internet arrives and where the Wi-Fi goes through.
  • Tidy and labelled rack, or a tangle of cables nobody wants to touch. The answer says a lot about how long a fault takes to resolve.
  • Visitor network separated from the company network. Sensitive equipment (servers, cameras, POS terminals) on dedicated segments.
  • Internet connection: provider, contracted bandwidth, whether there is a backup secondary connection and how long the company can survive without the internet.

6. Security

  • Firewall: make, model, whether it is up to date, who manages it and when the configuration was last reviewed.
  • Endpoint and server protection: which product, whether it is active on all devices and who receives the alerts.
  • Email protection against phishing and altered invoices — the most common type of fraud in Portuguese companies.
  • Incident response plan: if a workstation is encrypted by ransomware at 9am on Monday, who does what in the first 30 minutes?

To delve deeper into this block, use our cyber security checklist for SMEs.

7. Documentation and contracts

  • Administrative passwords for the equipment (firewall, switches, servers, operator router) stored in a secure location known to more than one person.
  • Active contracts: Internet service provider, licences, IT support. Deadlines, lock-in periods, and what is and isn't included.
  • If IT is provided by an external supplier: is there a written SLA? Do you know what happens if they disappear tomorrow? Look at what require in an IT contract.

8. People

  • Who is the internal point of contact for IT and what happens when they are on holiday.
  • When was the last phishing and security awareness session? If the answer is “never”, it is the cheapest investment with the best return on the list.
  • Employee onboarding and offboarding procedure: create and deactivate accounts, collect equipment, revoke access.

What to do with the result

Order the flaws into three groups: what exposes the company to a shutdown (untested backups, unsupported server, a single internet connection), what exposes the company to an attack (no MFA, active old accounts, unmanaged firewall), and what wastes money with no return (excess licences, equipment to repair instead of replace). The first two groups can be resolved in weeks; the third pays for the rest. If you prefer us to carry out the audit with you, this is exactly what our IT consultancy for businessessite visit and written report with priorities, before any proposal.

Frequently Asked Questions

How long does an IT audit take?

For a company with between 10 and 50 workstations, the on-site assessment takes half a day and the report is ready in a few days. Companies with multiple offices or their own servers may require more visits.

Do I need any special tools?

Not to start with. A spreadsheet and access to the equipment are enough. Automated inventory tools help with large estates, but they don't replace asking questions about backups, access and contracts.

How often should it be repeated?

At least once a year, and whenever there is a major change: office relocation, new management software, merger, departure of the IT manager. In a managed IT contract, the inventory is kept continuously up to date.

Is auditing the same as a security audit?

No. A security audit (penetration testing, vulnerability analysis) is deeper and more technical. This checklist is the previous step: knowing what exists and what state it is in. Without it, the security audit remains incomplete.

Do you want the survey done by someone who does this every week?

We visit your company, go through this list with you and deliver a written report detailing what is at risk and the order in which to resolve it. No obligation. See our IT consultancy for businesses or call 211 459 950.

Read more articles ...

Find out about some of the companies that have already chosen and opted for our IT services

Talk to Us now

Contact Form

Request a quote from DataRoad. We’ll take care of the rest with a prompt and clear response to support your business’s needs.

Tell us what you need. IT support, network installation, cyber security, an office move or simply a second opinion on your IT infrastructure — we’re here to help.

Please fill in the form and a specialist technician will contact you on the same day.

    B2B only, always on contract. We do not do one-off jobs or subcontracting.

    A reply on the same working day. No obligation.

    DataRoad — IT services for businesses
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.