What a New Client Audit Almost Always Turns Up
There’s a moment in almost every new client relationship that goes the same way.
We sit down with a business owner who tells us, reasonably and in good faith, that their technology is in decent shape. They have antivirus. They have spam filtering. They have backups. Nothing has gone seriously wrong. And then we look under the hood, and we find things nobody knew were there.
This isn’t a knock on those owners. In 25 years of onboarding businesses across Greensboro, Winston-Salem, High Point, and the surrounding Triad, our team has learned that these gaps don’t come from carelessness. They come from time passing. A business runs for a year, or three, or ten. People join and leave. Roles change. Tools get added. Nobody sets out to create a problem — it just accumulates quietly while everyone is busy running the company.
Here is what we find most often, and what it means for a business that hasn’t looked recently.
Nobody has audited the subscriptions in over a year
This is the most common finding, and it’s usually the one that surprises owners the most — because it’s the one that costs them money every single month.
Most businesses haven’t done a real review of their software subscriptions and user licenses in well over a year. In that time, employees have come and gone. People have moved into different roles that need different tools. Departments have adopted a platform, used it for a project, and quietly stopped. But the billing never stopped.
So we routinely find companies paying for seats nobody occupies, licenses assigned to people who left months ago, and tools that no longer serve any purpose.
The money matters, and it’s often the thing that gets an owner’s attention first. But the security implication is the part that should concern them more. Every unused account is an open door. A license belonging to a former employee isn’t just a wasted line item — it’s a live set of credentials sitting in your environment with nobody watching it. Every subscription nobody uses is one more system that can be compromised without anyone noticing, because nobody’s looking at something they forgot they had.
Cleaning up subscriptions saves money. It also makes a business meaningfully smaller as a target. Those two things almost never come packaged together, which is why this is usually the first thing we address.
The security stack doesn’t match the actual risk
The second thing we find is a belief that’s genuinely widespread and genuinely wrong: we have antivirus, we have spam protection, we have backups, so we’re covered.
Those three things are worth having. They are not, on their own, business security. They’re roughly what you’d install on a home computer — and a business is not a home computer. A business has multiple people with multiple access levels, financial transactions moving through email, customer and employee data carrying real legal obligations, vendors connecting into the network, and consequences for downtime that a household simply doesn’t face.
What we often find alongside that belief is a company paying for security products that don’t fit its actual risk profile — sometimes overlapping tools doing the same job, sometimes an expensive product solving a problem this business doesn’t have, while a real exposure sits unaddressed.
The layers a business of this size generally needs beyond antivirus and spam filtering include:
- Multi-factor authentication across email and critical systems. Passwords alone are no longer a meaningful barrier — MFA is the single highest-impact protection most businesses are missing.
- Endpoint detection and response, which watches for suspicious behavior rather than only matching known virus signatures. Traditional antivirus catches what’s already been catalogued; modern attacks are built specifically to avoid that.
- Patch and update management on a real schedule. A large share of successful breaches exploit vulnerabilities that were fixed months earlier — the patch existed and simply never got applied.
- Security awareness training for the team. Most incidents start with a person clicking something, not a firewall failing.
- Access controls that match current roles, so people hold the permissions their job requires and nothing more.
The right answer isn’t buying more products. It’s making sure the layers a business actually has line up with the risks that business actually faces — which is a different exercise than adding another subscription.
The backups exist. The recovery plan doesn’t.
We always ask about backups, and the answer is almost always yes. Then we ask what’s actually running, and the picture gets more complicated.
We find aging onsite servers quietly handling backup duty years past the point anyone should be relying on them. We find NAS devices sitting on the network without being properly secured — which means the backup itself is reachable by anything that reaches the network. That matters enormously with ransomware, which specifically looks for connected backups and encrypts those too. A backup an attacker can reach isn’t a backup. It’s another target.
And most significantly: we find businesses with no recovery plan at all.
That distinction is the one worth sitting with. Having backups and being able to recover are two entirely different things. Recovery means someone has tested a restore recently and knows it works. It means someone knows how long the business would actually be down. It means someone knows who does what, in what order, while the phones are ringing and nothing is working.
Without that, a business has data sitting somewhere and a plan to figure it out later — and “later” arrives on the worst day, under maximum pressure, usually with the one person who understood the setup unavailable.
None of this is anyone’s fault
That’s worth saying plainly, because owners sometimes hear this as criticism. It isn’t. These gaps form in well-run businesses with capable people. They form precisely because the business is busy doing the things that make it money.
But they don’t fix themselves, and they don’t stay the same size. Unused accounts accumulate. Security gaps widen as attacks evolve. Aging backup hardware gets older. The distance between what an owner believes about their systems and what’s actually true grows quietly, and the bill for that gap comes due at the least convenient possible moment.
Finding out where you stand doesn’t require a project or a commitment. It requires looking.
That’s what our IT Foundation Check is — a free 15-minute conversation where we walk through subscriptions, security layers, and backup and recovery, and give you a straight answer about what’s solid and what needs attention. No pitch, no overhaul talk. Just a clear picture.
Call our team at (336) 904-9101 or visit solaceits.com to schedule yours.
