Cybersecurity audit.
A full-scope review of your security posture against NIST CSF, ending in a prioritised roadmap your board can read and your engineers can execute. Useful when you know something needs to change but not what to do first.
At a glance
- Framework
- NIST Cybersecurity Framework, CIS Controls on request
- Duration
- 3 to 5 weeks
- Output
- Maturity scoring plus a prioritised roadmap
- Audience
- Board, leadership and engineering, in one document
- Follow-on
- Re-assessment to evidence improvement
What this actually is.
This is the engagement to buy when you have no specific certification deadline but a growing sense that your security programme has grown by accretion. It answers three questions: where are we, what matters most, and what should we do in the next two quarters.
What we cover.
Who needs this.
- Organisations with no formal security programme and growing customer pressure
- Boards asking for an independent view of security posture
- Companies after an incident, a near miss or an acquisition
- Teams choosing between competing security investments with no basis to decide
Frequently asked.
Is this the same as a penetration test?
No, and they answer different questions. A penetration test tells you whether a specific system can be broken into. An audit tells you whether your overall programme is capable of preventing, detecting and recovering from attacks. Most organisations benefit from both, in that order.
Why NIST CSF?
It is framework-agnostic, maps cleanly onto SOC 2, ISO 27001 and most regulatory expectations, and produces maturity scoring a non-technical board can follow without pretending to be a certification.
Will you sell us tooling based on the findings?
No. We have no reseller agreements and no product to place, which is precisely why an independent assessment is worth more than one from a vendor whose recommendations conveniently match their catalogue.
What does the output actually look like?
A maturity score per function, a prioritised roadmap with effort and impact for each item, and an executive summary written for people who will not read the appendices.
Related services.
The perimeter is one phishing email deep. We test what an attacker reaches from outside, and separately what they achieve once they are already inside.
CMP 02ISO 27001The international standard for information security management. Heavier than SOC 2 up front, more durable afterwards, and the one European and Asian enterprise buyers recognise immediately.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.