GRC

Security Audits

Framework-based audits that benchmark and prioritize your posture.

What it is

A structured evaluation of your security programme against a recognised framework — policy, process and technical control alike. Where a penetration test asks whether one system can be broken, an audit asks whether your organisation is managing security in a way that holds up to scrutiny.

How we do it

  1. 1

    Framework selection

    We agree the standard to audit against — ISO 27001, SOC 2, NIST CSF or CIS Controls — based on what your customers and regulators actually ask for.

  2. 2

    Documentation review

    Policies, procedures, registers and previous audit results read against the control set.

  3. 3

    Control interviews

    Sessions with the people who operate each control, because documented and actual practice routinely differ.

  4. 4

    Technical verification

    Sampling to confirm controls are implemented as described, not merely written down.

  5. 5

    Gap analysis

    Each control rated, with evidence, and the gap stated in terms of what is missing.

  6. 6

    Roadmap construction

    A sequenced plan to close gaps, ordered by risk reduction and effort.

What's included

  • Audit against your chosen framework
  • Policy and procedure review
  • Interviews with control owners
  • Technical sampling to verify practice
  • Evidence-backed control ratings
  • Prioritised remediation roadmap

Who needs it

  • Organisations preparing for certification or a customer audit
  • Boards wanting independent assurance on security posture
  • Teams inheriting a security programme they did not build

Deliverables

  • Control-by-control assessment with evidence cited
  • Gap register with owners and effort estimates
  • Executive summary written for a board audience
  • Remediation roadmap with sequencing

Compliance relevance

ISO 27001SOC 2NIST CSFCIS Controls

Frequently asked questions

No, and no consultancy can. Certification is issued only by an accredited certification body. What we do is audit you against the standard so you know where you stand before that body arrives.
Typically two to four weeks depending on organisation size and how much documentation already exists. Interviews are the constraint more often than the technical work.
That is a common starting point and worth saying plainly. The audit will show it, and the roadmap becomes a build plan rather than a gap list.

Related services

Compliance Consulting

ISO 27001, SOC 2, PCI DSS, and GDPR readiness and remediation.

Learn More

Risk Assessment

Quantitative and qualitative risk analysis tied to business impact.

Learn More

Vulnerability Assessment

Authenticated scanning and triage that cuts through false positives.

Learn More