AU · 03
IT Security Audit
A complete picture of your organisation's security posture and maturity.
What you get
- Maturity score and benchmark against recognised frameworks
- Gap analysis with clear priorities
- A phased action plan with cost estimates
- Management presentation of the findings
IT Security Audit
01Overview
What it is and why it matters
An IT security audit gives you a comprehensive, independent picture of your organisation's security posture, from technology through processes to people. We show where you stand, against what, and the most efficient path to a higher maturity level.
What we cover
- Access management, privileges and identity
- Network and system security configuration
- Backup, recovery and business continuity practices
- Logging, monitoring and incident response
- Policies, procedures and documentation
02Process
A transparent process, usable results
01
Scoping
A short workshop: environment, risks, goals.
02
Testing
Manual and automated testing, like a real attacker.
03
Reporting
A prioritised report for leadership and developers.
04
Re-test
A free verification after remediation.
03FAQ
Frequently asked questions
Which framework do you audit against?
We adapt to your needs: typically based on ISO 27001, the NIST CSF and CIS Controls, plus any sector-specific regulations that apply to you.
How long does an audit take?
Depending on the size of the organisation, typically 1–4 weeks. We provide a precise schedule after scoping.
Is the audit also a certification?
No. This is an independent assessment. If you are preparing for certification, our ISO 27001 lead audit service is built specifically for that.
Curious where the gaps are in your systems?
Book a free, no-obligation consultation. We reply within 24 hours.