A clear-eyed assessment of where you stand: policies, configurations, access, and backups measured against recognised frameworks, delivered as a scorecard and a prioritised plan you can actually action.
What gets reviewed
An audit covers the areas where problems actually originate, rather than everything that could theoretically be examined.
- Identity and access. Who can log in to what, how they prove it, what happens when they leave, and how much damage one compromised account does.
- Devices and patching. What is managed, what is current, and what is quietly running an operating system that stopped getting fixes.
- Data and backups. Where your important data lives, who can reach it, whether backups exist, and whether anybody has ever restored one.
- Email and collaboration. Microsoft 365 or Google Workspace configuration, email authentication, and the sharing settings nobody revisits after setup.
- Cloud and network. What is exposed, how it is segmented, and whether the defaults from three years ago are still in place.
- Process and policy. What happens when something goes wrong, and whether anybody other than the person who wrote it down knows.
What you get back
Two documents and a conversation.
The scorecard rates each control area against the framework, with the evidence behind each rating. It is deliberately specific: “MFA is enforced for administrators but not for the 34 standard accounts” is useful, “identity management: amber” is not.
The roadmap turns the gaps into a sequence. Each item carries an estimate of effort, an indication of cost, and what it actually reduces. Items are ordered so that the cheap, high-impact work comes first, which in most engagements means the first three items cost very little and close most of the real exposure.
The walkthrough is where the value usually lands. You get to ask why something is rated the way it is, push back where you have context we do not, and leave knowing which two things you are doing this quarter.
What an audit is honest about
Most audits of businesses that have never had one find the same handful of things: incomplete MFA, backups nobody has tested, more administrators than anyone expected, old accounts still active, and one system everybody has quietly been afraid to touch since the person who set it up left.
If that is you, the audit will not be a surprise so much as a confirmation with a price tag attached, and that is its value. The hard part of security spending is rarely knowing that something is wrong. It is being able to say what, specifically, in an order somebody can fund.
We also report what you are doing well. A report with nothing but failures in it is easy to write and easy to dismiss, and it makes the genuinely urgent items harder to see rather than easier.