Security & Compliance

Security Audits & Risk Assessments

An independent view of your security position, expressed as risk the board can weigh rather than findings it cannot.

Overview

Boards and executives do not need a control matrix; they need to know which risks are unacceptable, what it would cost to reduce them, and which ones the organisation is consciously choosing to carry.

We audit technical controls, process and governance together, then express the result in business terms — likelihood, impact, current controls and the cost of improvement — so the decisions can be made by the people accountable for them.

What you get

Independent perspective

An outside review that is not invested in defending decisions made previously.

Risk in business terms

Findings translated into likelihood and consequence rather than left as technical control gaps.

A costed roadmap

Remediation sequenced across quarters with effort and cost attached to each item.

Evidence for others

Documentation you can put in front of insurers, customers and your own board.

How we work

  1. 01

    Scope

    Systems, processes and the framework being assessed against are agreed with the sponsor.

  2. 02

    Examine

    Technical review, documentation review and interviews with the people who operate the controls daily.

  3. 03

    Assess

    Each risk rated on likelihood and impact, accounting for controls that genuinely work as intended.

  4. 04

    Report

    A board-ready summary and a technical appendix, with a remediation roadmap and clear ownership.

Common questions

Is this a certification audit?

No. We prepare organisations for certification and identify gaps, but formal ISO 27001 or SOC 2 certification must be issued by an accredited body.

How long does it take?

Typically three to five weeks depending on scope and how quickly interviews can be arranged.

Can you help fix what you find?

Yes. Where full independence is required for a certification path, we will tell you plainly which work we should not perform ourselves.

Often paired with

Security & Compliance

Cloud Security

Posture review and hardening across AWS, Azure and GCP, ending in a prioritised remediation plan.

Read more

Ready to talk about security audits & risk assessments?

We will tell you what we would do, roughly what it costs, and whether it is worth doing yet.

Book a meeting