Digital Partner Original research

How we onboard a new client: the technical audit, step by step

What happens in the first two weeks with a new client: the audit of accounts, site, security, speed and data that decides the first quarter's work.

4 minread 818words last updated

The short answer

The first two weeks with a new client are an audit, not a list of changes. Before anything is touched we establish what exists, who owns it, what is at risk, what is slow, what is measured and what is not. Six areas: accounts and ownership, the site and its stack, security, performance and search, forms and data flows, and monitoring and backups. The first week is about control: ownership confirmed or transferred, a copy of what exists secured and a route back proven, the deploy path understood. The second week produces a written report with findings ranked by risk and value. The first quarter’s improvement list comes from that report, which means the first quarter’s work is the right work rather than the loudest.

The six areas

AreaWhat we checkTypical findings
Accounts and ownershipRegistrar, DNS, hosting, repository, analytics, Search Console, Business Profile, email sending, integrations: whose name, who has access, two-factorDomain in an agency’s name; former staff with admin; no two-factor anywhere
Site and stackPlatform, theme or code, dependencies and their age, deploy path, documentationPlugins years behind; edits made on the live site; no repository
SecurityHeaders, HTTPS configuration, exposed secrets, admin exposure, dependency advisories, scan resultsMissing headers; a key in the front end; an admin panel on the default path
Performance and searchReal-user speed on top templates; images; scripts; indexing coverage; structured data; redirectsOversized images; a dozen tags; pages dropped from the index
Forms and data flowsEvery form tested end to end; where submissions go; what third parties receive personal dataA form that stopped delivering; submissions in three tools nobody chose
Monitoring and backupsWhat is monitored, who is alerted; backups: schedule, location, last restoreNothing monitored; a backup that has never been restored

We check links in a real browser rather than by status code. In our own audit of 242 external sources, 58 of them, 24 percent, could not be judged any other way: most refused a plain request, and the rest only showed their title once scripts had run.

The two weeks

  1. Day one: a conversation about the business, the site’s purpose, what has gone wrong before, and who holds what.
  2. Week one, control: access gathered; ownership confirmed or transfers started; a backup taken and restored somewhere; monitoring switched on; the deploy path understood.
  3. Week one and two, audit: the six areas checked with tools and by hand; every form submitted; every account listed.
  4. Week two, report: findings ranked by risk and value, each with what it costs to fix and what it costs to leave; a proposed first-quarter list.
  5. Review together: the client decides the list from the report; the first quarter begins.

What the report looks like

One page of summary: the state of ownership, the largest risks, the largest opportunities, the proposed first quarter. Then the findings by area, each with severity, evidence, the fix and the cost of leaving it. Then the inventory: every account, every service, every form, who holds what. The report becomes the first version of the setup document, and the inventory becomes the access list reviewed every quarter thereafter.

What this means for you

Expect the first two weeks with a new partner to be control, then audit, then a ranked report from which the first quarter’s work is chosen. Provide access, or the names of who has it, and an hour for the conversation. The audit finds what an inherited site is hiding before it costs you, and it turns the first quarter from a reaction to the loudest problem into a plan for the most important ones.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Why audit first instead of fixing the obvious problems?

Because the obvious problems are rarely the most important ones, and because changing a site before you own the accounts, have a backup and know how it deploys is how a fix becomes an outage. The audit takes two weeks, secures control in the first, and produces a ranked list that makes the first quarter's work the right work rather than the loudest.

What do we need to provide for the audit?

Access, or the names of who has it: domain registrar, DNS, hosting, the site's admin or repository, analytics, Search Console, Business Profile, email sending, any integrations. And an hour of your time to explain the business, what the site is for and what has gone wrong before. A good part of any audit is discovering who holds what.

What if the audit finds serious problems?

Then you know, in writing, ranked, with what each would cost to fix and what it costs to leave. Serious findings are common on inherited sites: unowned domains, no backups, plugins years behind, exposed keys, forms that do not deliver. The audit's job is to find them before they find you, and the first quarter's list starts with the ones that matter most.