Security Audit
A review rather than an attack. We assess your controls, architecture, process and documentation against a recognised framework, interview the people who operate them, and report where practice diverges from what is written down. The output is a gap list with an achievable order, not a maturity score.
Timeline
Three to six weeks depending on scope and how quickly interviews can be scheduled — availability of your people is almost always the constraint, not our analysis.
You get
- Control-by-control assessment against the agreed framework
- Evidence and observations behind each finding
- Executive summary written for a board, not for engineers
If any of these is your week, this is the service.
You do not know where you stand
Security has been done well in places and not at all in others, and nobody has ever assembled the whole picture.
What we do
A baseline assessment across every control domain, with the gaps ranked by risk rather than listed alphabetically.
A customer sent a 300-question security questionnaire
Answering it honestly requires knowing things nobody has written down, and answering it optimistically is a liability.
What we do
A documented control set and evidence pack, so the next questionnaire is an export rather than a fortnight.
You have grown faster than your process
Controls that worked at fifteen people quietly stopped working at a hundred and fifty, and nobody noticed the transition.
What we do
A review of what is actually being done against what is documented, and what has to change at your current size.
Every step, and what leaves our hands at the end of it.
- 01
Frame
Agree the framework and the scope — which entities, systems and control domains are in, and which are deliberately out.
→ Agreed scope & framework
- 02
Collect
Documentation review and interviews with the people who actually operate each control, not only the people who own it.
- 03
Assess
Test each control against the standard, and against what we observe happening — the gap between the two is the finding.
→ Control-by-control assessment
- 04
Report
Findings with evidence, risk-rated, plus an executive summary that says plainly where you stand.
→ Audit report
- 05
Roadmap
The gaps sequenced into an order you can actually execute, with effort estimates and owners.
→ Prioritised remediation roadmap
Deliverables.
- Control-by-control assessment against the agreed framework
- Evidence and observations behind each finding
- Executive summary written for a board, not for engineers
- A prioritised remediation roadmap with effort estimates
- A documented control set you can reuse to answer questionnaires
- A re-assessment of remediated gaps within twelve months
Before we can quote.
- 01Which framework you want to be measured against, if you have a preference
- 02Existing policies, procedures and architecture documentation
- 03Access to the people who operate each control, for interviews
- 04Your asset inventory and data flows, in whatever state they exist
- 05Any prior audit, assessment or questionnaire response
Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.
Security Audit, answered.
Is this the same as a certification audit?
No. We are not a certification body and cannot issue a certificate. This is the assessment you do before that one, so the certification audit does not surface surprises.
What if our documentation is a mess?
That is the normal starting point and it is itself a finding. We assess what is actually being done; the documentation gap goes in the roadmap rather than stopping the engagement.
Do you test anything technically?
Lightly — enough to check a control does what it claims. If you want depth on the technical side, pair this with VAPT; the two reports are designed to be read together.
Scope a Security Audit.
Security Audit is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.