Most small and medium businesses in Johannesburg have never had a proper IT audit. Things “mostly work,” so nobody looks under the hood — until a laptop is stolen, ransomware hits, or a software vendor sends a licensing bill nobody expected. An IT audit is simply a structured look at what you have, what’s at risk, and what it’s costing you. You don’t need a consultant to start. Below is the same checklist framework our team uses on a first engagement. Work through it honestly and you’ll surface most of the issues that quietly drain money and create risk.
1. Asset inventory
You can’t secure or budget for what you can’t see. List every device (laptops, desktops, servers, phones, network gear), who uses it, its age, and its warranty status. Anything older than 4–5 years is a replacement risk. No inventory at all? That’s your first finding.
2. Security basics
Is there endpoint protection on every device — not just “Windows Defender is probably on”? Is multi-factor authentication (MFA) enabled on email and any admin accounts? Are staff local admins on their own machines (they shouldn’t be)? Is there a firewall, and does anyone check its logs? Most SME breaches exploit basics, not exotic zero-days.
3. Backups — and restores
Backups that have never been test-restored are hope, not a plan. Confirm: what’s backed up, how often, where it lives (a second location or cloud, not just the same building), and when a restore was last tested. If load-shedding or a fire took out your office tonight, how many days of data would you lose?
4. Software and licensing
List your key software and how it’s licensed. Unlicensed or over-deployed software is a compliance and audit risk; forgotten subscriptions are pure waste. Note renewal dates so nothing auto-bills at a bad rate.
5. Cloud and email
Where does your email and file storage live (Microsoft 365, Google Workspace, on-prem)? Who has access to what? Are ex-employees fully deprovisioned? Cloud sprawl and stale accounts are common, cheap-to-fix findings.
6. Network and connectivity
Do you have a business-grade connection with failover, or one line that takes the whole office down when it drops? Is your Wi-Fi segmented (guests separate from business systems)? For Johannesburg businesses, factor in load-shedding: does critical gear have UPS/inverter backup?
7. POPIA and data
What personal information do you hold (customers, staff), and can you say where it lives and who can access it? POPIA compliance starts with knowing your data. See our POPIA compliance checklist for SMEs for the detail.
8. Documentation and continuity
If your “IT person” (internal or external) vanished tomorrow, could someone else pick up? Passwords, vendor contacts, network diagrams and licence records should live somewhere the business controls — not in one person’s head.
How to score it
For each area, mark green (fine), amber (needs attention) or red (urgent risk). Two or more reds means you’re carrying real, avoidable exposure. The point isn’t perfection — it’s knowing where you stand and fixing the reds first.
Want a second pair of eyes? African Vanilla offers a free IT audit for Johannesburg and Gauteng businesses — we run this checklist properly, then hand you a prioritised, no-obligation report. Book your free IT audit.
Explore our managed IT services and cybersecurity and POPIA compliance support to close the gaps your audit uncovers.
Looking for the service behind this insight?
- Infrastructure & Cloud → — Scalable, resilient architectures on AWS and Azure. Migration, optimization, hybrid-cloud management and ongoing support.