SECOMPSSECOMPS
Home/Services/Cybersecurity Audit
CMP 06

Cybersecurity audit.

A full-scope review of your security posture against NIST CSF, ending in a prioritised roadmap your board can read and your engineers can execute. Useful when you know something needs to change but not what to do first.

At a glance

Framework
NIST Cybersecurity Framework, CIS Controls on request
Duration
3 to 5 weeks
Output
Maturity scoring plus a prioritised roadmap
Audience
Board, leadership and engineering, in one document
Follow-on
Re-assessment to evidence improvement
01Overview

What this actually is.

This is the engagement to buy when you have no specific certification deadline but a growing sense that your security programme has grown by accretion. It answers three questions: where are we, what matters most, and what should we do in the next two quarters.

02Scope

What we cover.

Governance and risk managementOwnership, risk appetite, board reporting and whether security decisions are actually being made anywhere.
Asset and identity managementWhat you own, who has access to it, and how quickly access is removed when people leave.
Protective controlsEndpoint, network, email, data protection and configuration management, assessed against real threat activity.
Detection capabilityLogging coverage, alerting quality, and whether anyone is watching the alerts you already generate.
Incident response readinessPlans, roles, escalation paths and whether they have ever been exercised under time pressure.
Recovery and resilienceBackup integrity, tested restoration, and continuity assumptions that have never been validated.
Third-party riskVendor inventory, assessment process and concentration risk in your supply chain.
People and processTraining, phishing resilience, joiner-mover-leaver process and secure development practice.
03Fit

Who needs this.

  • Organisations with no formal security programme and growing customer pressure
  • Boards asking for an independent view of security posture
  • Companies after an incident, a near miss or an acquisition
  • Teams choosing between competing security investments with no basis to decide
04Questions

Frequently asked.

Is this the same as a penetration test?

No, and they answer different questions. A penetration test tells you whether a specific system can be broken into. An audit tells you whether your overall programme is capable of preventing, detecting and recovering from attacks. Most organisations benefit from both, in that order.

Why NIST CSF?

It is framework-agnostic, maps cleanly onto SOC 2, ISO 27001 and most regulatory expectations, and produces maturity scoring a non-technical board can follow without pretending to be a certification.

Will you sell us tooling based on the findings?

No. We have no reseller agreements and no product to place, which is precisely why an independent assessment is worth more than one from a vendor whose recommendations conveniently match their catalogue.

What does the output actually look like?

A maturity score per function, a prioritised roadmap with effort and impact for each item, and an executive summary written for people who will not read the appendices.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.