Assurance & compliance

Security Audit

A review rather than an attack. We assess your controls, architecture, process and documentation against a recognised framework, interview the people who operate them, and report where practice diverges from what is written down. The output is a gap list with an achievable order, not a maturity score.

At a glance

Timeline

Three to six weeks depending on scope and how quickly interviews can be scheduled — availability of your people is almost always the constraint, not our analysis.

You get

  • Control-by-control assessment against the agreed framework
  • Evidence and observations behind each finding
  • Executive summary written for a board, not for engineers
Who needs this

If any of these is your week, this is the service.

You do not know where you stand

Security has been done well in places and not at all in others, and nobody has ever assembled the whole picture.

What we do

A baseline assessment across every control domain, with the gaps ranked by risk rather than listed alphabetically.

A customer sent a 300-question security questionnaire

Answering it honestly requires knowing things nobody has written down, and answering it optimistically is a liability.

What we do

A documented control set and evidence pack, so the next questionnaire is an export rather than a fortnight.

You have grown faster than your process

Controls that worked at fifteen people quietly stopped working at a hundred and fifty, and nobody noticed the transition.

What we do

A review of what is actually being done against what is documented, and what has to change at your current size.

How it works

Every step, and what leaves our hands at the end of it.

  1. 01

    Frame

    Agree the framework and the scope — which entities, systems and control domains are in, and which are deliberately out.

    → Agreed scope & framework

  2. 02

    Collect

    Documentation review and interviews with the people who actually operate each control, not only the people who own it.

  3. 03

    Assess

    Test each control against the standard, and against what we observe happening — the gap between the two is the finding.

    → Control-by-control assessment

  4. 04

    Report

    Findings with evidence, risk-rated, plus an executive summary that says plainly where you stand.

    → Audit report

  5. 05

    Roadmap

    The gaps sequenced into an order you can actually execute, with effort estimates and owners.

    → Prioritised remediation roadmap

What you get

Deliverables.

  • Control-by-control assessment against the agreed framework
  • Evidence and observations behind each finding
  • Executive summary written for a board, not for engineers
  • A prioritised remediation roadmap with effort estimates
  • A documented control set you can reuse to answer questionnaires
  • A re-assessment of remediated gaps within twelve months
What we need

Before we can quote.

  • 01Which framework you want to be measured against, if you have a preference
  • 02Existing policies, procedures and architecture documentation
  • 03Access to the people who operate each control, for interviews
  • 04Your asset inventory and data flows, in whatever state they exist
  • 05Any prior audit, assessment or questionnaire response

Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.

Questions

Security Audit, answered.

Is this the same as a certification audit?

No. We are not a certification body and cannot issue a certificate. This is the assessment you do before that one, so the certification audit does not surface surprises.

What if our documentation is a mess?

That is the normal starting point and it is itself a finding. We assess what is actually being done; the documentation gap goes in the roadmap rather than stopping the engagement.

Do you test anything technically?

Lightly — enough to check a control does what it claims. If you want depth on the technical side, pair this with VAPT; the two reports are designed to be read together.

Next step

Scope a Security Audit.

Security Audit is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.

Scope a Security Audit1 business day

By submitting you agree to be contacted about your enquiry. We never share your details.