SECURITY AUDIT

Cybersecurity audit

A security audit answers a different question from a penetration test. A pentest asks can this be broken into. An audit asks is this managed properly — and produces the evidence to prove it.

We assess your technical configuration, your processes and your controls against the standard that applies to you, and hand you a prioritised, costed remediation plan.

THEY TRUST US

Raiffeisen Processing Centre Logo
Penta Hospitals Logo
Pixel Federation Logo
Ministry Of Finance - Slovakia Logo
DanubePay Logo
Alison Logo
Ditec Logo
Sanaclis Logo
Piano Logo
Ultima Payments Logo
Amerge Logo
Digital Systems Logo

SECURITY AUDIT

Audit or penetration test?

The two are complementary and clients frequently need both. The distinction matters when you are scoping, so here it is plainly:

If you are not sure which you need, tell us what triggered the question — a customer questionnaire, an auditor, a board request — and we will tell you honestly which one answers it.

What the two deliver

Security auditPenetration test
Question answeredAre the right controls in place and operating?Can an attacker actually get in?
MethodConfiguration review, process review, interviews, evidence samplingActive exploitation from an attacker perspective
OutputGap analysis against a standard, prioritised remediation planExploited findings with proof and reproduction steps
Best forCertification, regulatory evidence, due diligenceProving real-world exposure, validating fixes

Most regulated clients run an audit to find the gaps and a penetration test to prove which of them are actually exploitable.

How an audit runs

Typically two to four weeks depending on scope and how readily documentation is available.

1

Scoping and standard selection

We agree which framework applies — ISO 27001, NIS2, PCI DSS, SOC 2 or your own internal policy — and what is in scope.

2

Evidence gathering

Configuration exports, policy documents, architecture diagrams and short interviews with the people who actually operate the systems.

3

Technical review

Hardening, identity and access, network segmentation, logging and monitoring, backup and recovery, cloud configuration.

4

Gap analysis

Every gap rated by risk and effort, mapped to the clause or control it fails, with a concrete remediation.

5

Report and debrief

A written report plus a call with your team, so the findings land with the people who have to act on them.

What we assess

A full audit covers the areas below; we can also scope to a subset if you have a specific concern.

Identity, access control and privilege management

System hardening and configuration baselines

Network architecture and segmentation

Cloud configuration across AWS, Azure and GCP

Logging, monitoring and alerting coverage

Backup, recovery and business continuity

Policies, procedures and their actual operation

Third-party and supply chain risk

TESTIMONIALS

What our clients say about us

Security audit — common questions

01 What is the difference between an audit and a penetration test?

An audit assesses whether the right controls exist and operate correctly, against a standard. A penetration test attacks the system to prove what is actually exploitable. An audit gives you breadth and evidence; a pentest gives you depth and proof. Regulated organisations usually need both.

02 Which standard do you audit against?

Most commonly ISO 27001 and NIS2, and PCI DSS for payment environments. We can also audit against SOC 2 criteria or your own internal policy set. If a customer has sent you a security questionnaire, we can audit against that directly.

03 Do you issue a certificate?

No — certification has to come from an accredited certification body, and no consultancy that also does the remediation work should be issuing it. What we produce is the independent assessment and evidence pack that certification depends on.

04 How much does a security audit cost?

It depends on scope and how much documentation already exists. A focused audit of a single environment starts from around €2,000; a full ISMS-scope audit runs considerably more. We quote a fixed price after a scoping call.

05 Will you also fix what you find?

We advise on remediation and will happily walk your team through it, but we do not sell the implementation of our own findings. That separation is what keeps the audit independent and worth something to your auditor.

Find out where the gaps are

A scoping call establishes which standard applies, what needs assessing and what it costs. NIS2 · ISO 27001 · Vulnerability assessment · Consulting and hardening

Book a free audit scoping call