
Find out what you actually have
You cannot fix what nobody has written down.
Most IT estates are understood in fragments: one person knows the servers, another knows the ERP, and the contract for the thing nobody has logged into since 2021 renews automatically. An audit puts all of it in one document — what you run, what it costs, what is exposed, what is undocumented, and what would happen if the person who set it up left tomorrow.
Technologies
01Capabilities
Independent, and paid for as such
The audit is a fixed-price engagement with its own deliverable. We are not auditing our way into a rebuild — plenty of audits end with "this is in better shape than you think, fix these four things".
Evidence, not opinion
Every finding cites what it is based on: a configuration file, a scan result, a log sample, an invoice, an interview. You can hand the report to another supplier and they can verify it.
Severity and cost, not a list
Findings are rated by likelihood and impact, each with an owner, an estimated effort and a cost. A report that does not help you decide what to do on Monday has not finished the job.
The bus-factor questions
Who is the only person who can deploy? Which system has no documented recovery? Which licence renews without anyone approving it? These are the findings that cost the most and appear in the fewest reports.
02Scope
What is included
- Infrastructure inventory: servers, services, domains, certificates, dependencies
- Application and codebase review, including inherited and legacy systems
- Security posture assessment against OWASP and CIS benchmarks
- Backup, restore and disaster-recovery verification — including an actual restore
- Identity and access review across systems, with orphaned account discovery
- Licence, subscription and cloud cost analysis with waste identified
- Delivery process review: environments, releases, testing, code review
- Vendor and supplier dependency mapping
- Documentation and knowledge-transfer gap analysis
- Risk register with likelihood, impact, owner and remediation cost
- Prioritised remediation roadmap, phased over three to twelve months
- ISO 27001 or NIS2 gap analysis where certification is the goal
03How it runs
Four weeks, three of them ours
A typical audit for a mid-sized estate. Larger or more fragmented environments run longer, and we say so before starting rather than halfway through.
Scope and access
We agree what is in scope, sign the NDA, and get read access to what we need. Read-only throughout: an audit should not be able to change the thing it is measuring.
Collection
Configuration review, automated scanning, log sampling, licence and invoice review, and interviews with the people who actually operate each system. The interviews find what the tooling cannot.
Verification
Findings are reproduced before they are written down, and a restore is tested from a real backup. An untested backup is the single most common false assumption we find.
Report and walkthrough
A written report, an executive summary for people who will not read it, and a session where we walk your team through every finding and take challenges to them.
04What we usually find
The same five things, in most estates
Backups that have never been restored. They run, they report success, and nobody has proven a restore produces a working system. We test one during the audit, and it is the finding that changes the most minds.
Access that outlived the person. Accounts for people who left, shared credentials in a spreadsheet, a former supplier whose VPN certificate still works. Nearly every estate has at least one.
A system with one owner. One person who can deploy, or who understands the integration everything depends on. Not a security problem until they are on holiday during an incident.
Spend nobody approved. Duplicate SaaS subscriptions, oversized instances left from a migration, a licence tier bought for a headcount you no longer have. This routinely funds the remediation work.
Undocumented business logic. Rules that exist only in code — how a discount is applied, when an order is held — that nobody can state without reading it. This is the one that makes every future project more expensive.
05Questions
Frequently asked questions
Is an audit the same as a penetration test?
No, and anyone conflating them is selling you one and charging for the other. An audit is a broad review with access and cooperation — infrastructure, applications, process, cost and risk. A penetration test is a narrow adversarial exercise against a defined target. The audit tells you whether you need a pen test and what it should cover; where a certified test is required for compliance, we will say so and help you scope it.
Will you need production access?
Read-only, and only where a finding cannot be established otherwise. Most of an audit runs on configuration, documentation, logs, scan output and conversation. We work under your access control, with an account you can revoke, and everything we touch is logged.
What does it cost?
It is fixed-price, quoted after a short scoping call, and it depends mostly on how many distinct systems are in scope rather than on their size. We would rather quote a narrower scope you actually act on than a broad one that produces a document nobody reads.
Do we have to use you for the remediation?
No, and the report is written on that assumption. Findings are specific enough for your own team or another supplier to act on, and we will say when a fix is routine enough that it does not need us. We are happy to quote for the work, but an audit that only makes sense if you buy the follow-up is not an independent audit.
What if the audit finds something serious mid-way?
You hear about it that day, not in four weeks. Anything actively exploitable or actively losing data is reported immediately with a suggested containment step, and then written up properly afterwards.
06Nearby
Related services
Cyber Security
Hardening, identity, patching, monitoring, backup verification and incident response — run as an ongoing discipline against ISO 27001 and NIS2, not as a product you switch on.
Infrastructure & DevOpsDevOps, Linux Servers & Managed Hosting
Linux server configuration, hardening, Docker deployments, CI/CD pipelines, monitoring and managed hosting — the infrastructure work most agencies quietly outsource.
Infrastructure & DevOpsWeb Security & Compliance
Security audits, hardening, incident recovery and the practical side of GDPR, PCI DSS and NIS2 — for teams that would rather not learn this during a breach.
What we do
IT Audit
An independent review of your infrastructure, applications, security posture, costs and delivery process — delivered as a written report with severities, owners and a costed plan.
