Adobe Commerce certified developers · Nearshore teams available within 2 weeks

Find out what you actually have

You cannot fix what nobody has written down.

Most IT estates are understood in fragments: one person knows the servers, another knows the ERP, and the contract for the thing nobody has logged into since 2021 renews automatically. An audit puts all of it in one document — what you run, what it costs, what is exposed, what is undocumented, and what would happen if the person who set it up left tomorrow.

Technologies

Infrastructure reviewApplication & code reviewSecurity postureBackup & recovery testingLicence & cost analysisAccess & identity reviewDelivery process reviewRisk registerISO 27001 gap analysis

01Capabilities

01

Independent, and paid for as such

The audit is a fixed-price engagement with its own deliverable. We are not auditing our way into a rebuild — plenty of audits end with "this is in better shape than you think, fix these four things".

02

Evidence, not opinion

Every finding cites what it is based on: a configuration file, a scan result, a log sample, an invoice, an interview. You can hand the report to another supplier and they can verify it.

03

Severity and cost, not a list

Findings are rated by likelihood and impact, each with an owner, an estimated effort and a cost. A report that does not help you decide what to do on Monday has not finished the job.

04

The bus-factor questions

Who is the only person who can deploy? Which system has no documented recovery? Which licence renews without anyone approving it? These are the findings that cost the most and appear in the fewest reports.

02Scope

What is included

  • Infrastructure inventory: servers, services, domains, certificates, dependencies
  • Application and codebase review, including inherited and legacy systems
  • Security posture assessment against OWASP and CIS benchmarks
  • Backup, restore and disaster-recovery verification — including an actual restore
  • Identity and access review across systems, with orphaned account discovery
  • Licence, subscription and cloud cost analysis with waste identified
  • Delivery process review: environments, releases, testing, code review
  • Vendor and supplier dependency mapping
  • Documentation and knowledge-transfer gap analysis
  • Risk register with likelihood, impact, owner and remediation cost
  • Prioritised remediation roadmap, phased over three to twelve months
  • ISO 27001 or NIS2 gap analysis where certification is the goal

03How it runs

Four weeks, three of them ours

A typical audit for a mid-sized estate. Larger or more fragmented environments run longer, and we say so before starting rather than halfway through.

01week 1

Scope and access

We agree what is in scope, sign the NDA, and get read access to what we need. Read-only throughout: an audit should not be able to change the thing it is measuring.

02weeks 1–2

Collection

Configuration review, automated scanning, log sampling, licence and invoice review, and interviews with the people who actually operate each system. The interviews find what the tooling cannot.

03week 3

Verification

Findings are reproduced before they are written down, and a restore is tested from a real backup. An untested backup is the single most common false assumption we find.

04week 4

Report and walkthrough

A written report, an executive summary for people who will not read it, and a session where we walk your team through every finding and take challenges to them.

04What we usually find

The same five things, in most estates

Backups that have never been restored. They run, they report success, and nobody has proven a restore produces a working system. We test one during the audit, and it is the finding that changes the most minds.

Access that outlived the person. Accounts for people who left, shared credentials in a spreadsheet, a former supplier whose VPN certificate still works. Nearly every estate has at least one.

A system with one owner. One person who can deploy, or who understands the integration everything depends on. Not a security problem until they are on holiday during an incident.

Spend nobody approved. Duplicate SaaS subscriptions, oversized instances left from a migration, a licence tier bought for a headcount you no longer have. This routinely funds the remediation work.

Undocumented business logic. Rules that exist only in code — how a discount is applied, when an order is held — that nobody can state without reading it. This is the one that makes every future project more expensive.

05Questions

Frequently asked questions

Is an audit the same as a penetration test?

No, and anyone conflating them is selling you one and charging for the other. An audit is a broad review with access and cooperation — infrastructure, applications, process, cost and risk. A penetration test is a narrow adversarial exercise against a defined target. The audit tells you whether you need a pen test and what it should cover; where a certified test is required for compliance, we will say so and help you scope it.

Will you need production access?

Read-only, and only where a finding cannot be established otherwise. Most of an audit runs on configuration, documentation, logs, scan output and conversation. We work under your access control, with an account you can revoke, and everything we touch is logged.

What does it cost?

It is fixed-price, quoted after a short scoping call, and it depends mostly on how many distinct systems are in scope rather than on their size. We would rather quote a narrower scope you actually act on than a broad one that produces a document nobody reads.

Do we have to use you for the remediation?

No, and the report is written on that assumption. Findings are specific enough for your own team or another supplier to act on, and we will say when a fix is routine enough that it does not need us. We are happy to quote for the work, but an audit that only makes sense if you buy the follow-up is not an independent audit.

What if the audit finds something serious mid-way?

You hear about it that day, not in four weeks. Anything actively exploitable or actively losing data is reported immediately with a suggested containment step, and then written up properly afterwards.

What we do

IT Audit

An independent review of your infrastructure, applications, security posture, costs and delivery process — delivered as a written report with severities, owners and a costed plan.