Jelia.nyc

Jelia.nyc / What I do / Infrastructure & security audit

WHAT I DO ยท AUDIT

Find out what you are actually running

A fixed-price look at your infrastructure, your security and your spend. You get a written list of findings, each with a severity and an effort, so you know what to fix first.

What it is

An audit is me looking at the estate as it really is, not as the diagram from three years ago says it is. Servers, domains, certificates, accounts, subscriptions, backups, monitoring, and the people who hold the keys to all of it.

It ends in a written, prioritised list of findings. Every finding says what is wrong, how I know, how bad it is and how much work it is to fix. That list is the product. There is no slide deck, and no recommendation that amounts to "buy more of something".

Why it matters

Most estates are not badly run. They are run by busy people who inherited decisions they did not make. The failures I see are rarely exotic:

  • Nobody has a complete list of what is running, so nobody can say what it costs or what is exposed.
  • A certificate, a domain or a licence renews on a card belonging to someone who left.
  • Former staff still have working accounts on the one system that was never connected to anything else.
  • Backups run every night and have never been restored.
  • Monitoring says a site is up because it returns a page, even when that page is an error.
  • One person knows how the important thing works, and that person is planning a holiday.

None of these show up until the day they do. An audit finds them on a quiet Tuesday instead.

How I do it

  1. Inventory. Every server, service, domain, certificate and paid subscription, with an owner against each. Where the records and reality disagree, reality wins and the gap becomes a finding.
  2. Cost. What each thing costs, who pays for it, and whether anyone still uses it. Duplicated tools and forgotten renewals are common and cheap to fix.
  3. Exposure. What can be reached from the internet, what should not be, and what is being patched. Mail authentication, TLS, admin access, shared passwords.
  4. Identity and access. Who can log in to what, how they are removed when they leave, and which accounts nobody can explain.
  5. Resilience. Whether backups restore, whether monitoring checks real content, and whether alerts reach a human who can act on them.
  6. Key-person risk. What breaks, and for how long, if the person who built it is unavailable. Undocumented systems are a finding in their own right.

What you get

A findings list you own outright, whether or not you hire me to fix any of it. Each entry carries:

  • The finding, in plain language a manager can read.
  • The evidence, so your own team can check it rather than take my word for it.
  • Severity, from critical to low, judged on what actually happens if it goes wrong.
  • Effort, roughly hours, days or weeks, so quick wins are visible next to the big jobs.
  • A recommended fix, and where there is a reasonable alternative, that too.

Alongside it: the inventory itself, which is often the most useful thing an organisation has never had, and a short summary for whoever signs the cheques. I walk you through all of it before I call the job done.

In my own estate

I run the same checks on my own infrastructure every day. A scripted health check runs dozens of tests that look for real page content, not status codes. A daily sweep checks every TLS certificate for expiry. Uptime Kuma probes every site and alerts a person through Slack. Database dumps are pulled off the server every night to separate storage, with weekly full-disk snapshots on top.

39Domains under management
156Hosts behind one edge
5 minBetween content checks on every site
DailyCertificate expiry sweep

Questions people ask

Will you change anything while you audit?

No. The audit is read-only. If I find something urgent, I tell you the same day and you decide what happens next. It does not wait for the report.

We have almost no documentation. Is that a problem?

It is normal, and it is part of what the audit produces. Missing documentation goes on the list like anything else, with a severity and an effort.

Do we have to hire you for the fixes?

No. The list is written so your own team, or anyone else, can work from it. If you want me to do the work, that is the next step, scoped from the findings.

How is this different from a vulnerability scan?

A scan is one input. It tells you about software versions on the hosts it can see. It does not tell you about the renewal on a former employee's card, the backup nobody has restored, or the system only one person understands.