After participating in IT audits at dozens of international subsidiaries in Mexico, the same 15 findings keep cropping up over and over again—almost never due to negligence, but because no one has had time to review them since the office was set up. See also: What an IT audit is and what it should include.
Security and Access
- Un MFA d administrative accounts — the most common and most critical finding: full access to servers protected only by a password.
- Former employees with active access — accounts belonging to employees who left the company months ago but were never deactivated.
- Passwords shared among multiple users — it's impossible to know who did what when something goes wrong.
- No network segmentation —the printer and the payroll server are on the same flat network.
- Unreviewed authentication logs — they exist, but no one looks at them until something has already happened.
Software and Licenses
- Unlicensed software or software with expired licenses — a direct legal risk, often discovered only during an audit.
- Inventory of Outdated Software — The document says one thing, but the computers show another.
- Versions that have not been patched for more than 90 days — vulnerabilities that are known and have already been fixed by the manufacturer, but have never been applied.
- Redundant tools — two or three solutions that do the same thing, purchased at different times by different people.
Continuity and Backups
- Backups that were never tested for restoration — the classic scenario: the copy exists, but no one knows if it works until it's too late.
- No documented disaster recovery plan —the knowledge exists only in one person's head.
- Insufficient backup retention — less than the recommended minimum of 90 days needed to recover previous versions.
Documentation and Processes
- No change history for the infrastructure —no one can say what changed last week or who did it.
- Non-existent or outdated IT policies — nothing in writing that the parent company can review during a due diligence process.
- Manual processes that should be automated — manually adding and removing users, without a checklist or log.
None of these 15 findings is, on its own, catastrophic. The real risk lies in their accumulation: a subsidiary that has 6 or 7 of them without a remediation plan is the one that ends up with a serious incident—or with a parent company that loses confidence in the local report.
Keptos Identify and prioritize these findings in each audit — see the details of the IT audit service for companies in Mexico.