Guide · Networks
What does a network audit check, and what does the report contain?
A network audit is a survey of a company's network as it really is: the cabling, switches, Wi-Fi, firewall and addressing, and the way traffic flows between them. It establishes whether the network is documented, segmented, up to date and sized for its use, and where it can fail. The result is a report with a drawing, an inventory and a list of risks in order of seriousness, each with a recommendation.
What is checked in a network audit?
- Inventory. Every switch, access point, router and firewall, with model, firmware version and age, and whether the maker still supports it.
- Cabling and cabinets. Cable category, labelling, patching, power supply and protection against power cuts.
- Addressing. The address plan, DHCP and DNS, conflicts, and devices nobody can identify.
- Switches. VLANs, uplinks, loops and ports that report errors.
- Firewall. The rules, including forgotten ones, the ports open to the internet, and remote access.
- Administration. Default passwords, shared accounts, who has access, and whether the configurations are backed up.
- Internet line. Capacity against measured use, and what happens when the line fails.
- Monitoring. Whether anyone would notice a failing component before the users do.
How is the Wi-Fi assessed?
By measuring on site, not from a floor plan.
- Signal strength in every room where people work.
- Channels, and interference from neighbours and from your own access points.
- The number of devices per access point: coverage is not capacity.
- Roaming: whether a call survives a walk down the corridor.
- How the access points are connected: by cable, or by relaying each other's signal.
- Security: the encryption in use, one shared password or a login per user, and a guest network that is truly separate.
The same measurement precedes a new business Wi-Fi installation. The number and position of the access points follow from the walls, the use and the number of devices, not from floor area alone.
What is network segmentation, and why is it checked?
Segmentation divides the network into zones, such as staff, servers, guests, printers, cameras, telephony and machines, and allows between them only the traffic that is needed. In a network without it, every device can reach every other, so one infected laptop or one poorly secured camera opens the way to everything.
The audit checks whether zones exist, and whether there are real rules between them: VLANs that are routed to each other without restriction separate nothing. It also checks whether a guest can reach internal systems, and whether the management interfaces of the equipment have their own zone.
What does the report contain?
- A drawing of the network: where the equipment is and how it is connected.
- The inventory, with the support status of each item.
- The address and VLAN plan as found.
- Findings in order of risk, each with what was found, what it can lead to and what to do.
- A split between what can be fixed at once and what needs investment or planning.
- A summary in plain language for the management.
How does the audit take place?
With a site visit, read access to the configuration of the equipment, measurements, and a conversation with whoever looks after IT day to day.
The audit is the first step in our LAN infrastructure work. If the question is how to link several locations, see SD-WAN or site-to-site VPN.
Frequently asked questions
Will the audit disrupt our work?
Normally not. An audit reads configurations and measures; it changes nothing. If a test could interrupt something, such as pulling a line to check the fall-back, it is agreed beforehand and done outside working hours.
What do you need from us?
Access to the premises and the cabinets, administrator access to the equipment or someone who can sign in for us, a floor plan, and whatever documentation and contracts exist. If there is none, that is a finding in itself, not an obstacle.
Is a network audit the same as a penetration test?
No. An audit examines how the network is built and configured, with your cooperation. A penetration test actively tries to break in, as an attacker would. The audit usually comes first, because it removes the weaknesses a test would find straight away.
Do we have to replace our equipment afterwards?
Only what holds the network back or is no longer supported by its maker. Many findings are matters of configuration: zones, passwords, firmware, labelling. The report says for each item whether it can be kept, and why.
Let's talk about your project.
Tell us where you are and where you want to be. We'll come back within one working day with a first view. A person reads your message and answers it.