SECURITY AUDIT
Cybersecurity audit
A security audit answers a different question from a penetration test. A pentest asks can this be broken into. An audit asks is this managed properly — and produces the evidence to prove it.
We assess your technical configuration, your processes and your controls against the standard that applies to you, and hand you a prioritised, costed remediation plan.
THEY TRUST US
SECURITY AUDIT
Audit or penetration test?
The two are complementary and clients frequently need both. The distinction matters when you are scoping, so here it is plainly:
If you are not sure which you need, tell us what triggered the question — a customer questionnaire, an auditor, a board request — and we will tell you honestly which one answers it.
What the two deliver
| Security audit | Penetration test | |
|---|---|---|
| Question answered | Are the right controls in place and operating? | Can an attacker actually get in? |
| Method | Configuration review, process review, interviews, evidence sampling | Active exploitation from an attacker perspective |
| Output | Gap analysis against a standard, prioritised remediation plan | Exploited findings with proof and reproduction steps |
| Best for | Certification, regulatory evidence, due diligence | Proving real-world exposure, validating fixes |
Most regulated clients run an audit to find the gaps and a penetration test to prove which of them are actually exploitable.
How an audit runs
Typically two to four weeks depending on scope and how readily documentation is available.
Scoping and standard selection
We agree which framework applies — ISO 27001, NIS2, PCI DSS, SOC 2 or your own internal policy — and what is in scope.
Evidence gathering
Configuration exports, policy documents, architecture diagrams and short interviews with the people who actually operate the systems.
Technical review
Hardening, identity and access, network segmentation, logging and monitoring, backup and recovery, cloud configuration.
Gap analysis
Every gap rated by risk and effort, mapped to the clause or control it fails, with a concrete remediation.
Report and debrief
A written report plus a call with your team, so the findings land with the people who have to act on them.
What we assess
A full audit covers the areas below; we can also scope to a subset if you have a specific concern.
Identity, access control and privilege management
System hardening and configuration baselines
Network architecture and segmentation
Cloud configuration across AWS, Azure and GCP
Logging, monitoring and alerting coverage
Backup, recovery and business continuity
Policies, procedures and their actual operation
Third-party and supply chain risk
TESTIMONIALS
What our clients say about us
Security audit — common questions
01 What is the difference between an audit and a penetration test?
An audit assesses whether the right controls exist and operate correctly, against a standard. A penetration test attacks the system to prove what is actually exploitable. An audit gives you breadth and evidence; a pentest gives you depth and proof. Regulated organisations usually need both.
02 Which standard do you audit against?
Most commonly ISO 27001 and NIS2, and PCI DSS for payment environments. We can also audit against SOC 2 criteria or your own internal policy set. If a customer has sent you a security questionnaire, we can audit against that directly.
03 Do you issue a certificate?
No — certification has to come from an accredited certification body, and no consultancy that also does the remediation work should be issuing it. What we produce is the independent assessment and evidence pack that certification depends on.
04 How much does a security audit cost?
It depends on scope and how much documentation already exists. A focused audit of a single environment starts from around €2,000; a full ISMS-scope audit runs considerably more. We quote a fixed price after a scoping call.
05 Will you also fix what you find?
We advise on remediation and will happily walk your team through it, but we do not sell the implementation of our own findings. That separation is what keeps the audit independent and worth something to your auditor.
Find out where the gaps are
A scoping call establishes which standard applies, what needs assessing and what it costs. NIS2 · ISO 27001 · Vulnerability assessment · Consulting and hardening
Book a free audit scoping call