IT security audit for businesses

We assess how your business protects accounts, email, devices, networks and data. We identify genuine risks, set clear priorities and prepare an action plan that can be implemented in stages.

Configuration and access assessmentEmail, network and device analysisRisk and priority reportProtection improvement plan

Problems we help solve

A security audit is valuable when a business is unsure whether its core safeguards are configured correctly or whether it could respond effectively to an incident.

  • There is no clear record of who has administrative privileges or remote access.
  • The business uses Microsoft 365 but has no consistent approach to MFA and email protection.
  • The firewall, VPN, Wi-Fi and network devices have not been reviewed since implementation.
  • There is no response procedure for phishing, account takeover or a lost device.
  • A supplier audit, migration or customer security requirement is approaching.

Who is a security audit for?

Businesses without an in-house IT team

They receive an independent assessment of the most important safeguards and a prioritised list of actions.

Businesses with an administrator

The audit provides a second opinion, clarifies risks and supports modernisation planning without undermining the team's work.

Remote and hybrid businesses

We review internet-facing access, MFA, devices, email and data-sharing practices.

Businesses following an incident

We help identify areas for improvement and prepare the environment for similar events in future.

What does a security audit cover?

Identity and access

We review accounts, roles and the way permissions are granted.

  • administrative accounts and MFA,
  • Active Directory and Entra ID,
  • VPN, guest and third-party service access.

Email and Microsoft 365

We assess communication security and exposure to phishing.

  • SPF, DKIM and DMARC,
  • Conditional Access policies,
  • file sharing and administrator accounts.

Network and devices

We review the core layers of infrastructure security.

  • firewall, VPN, VLAN and Wi-Fi,
  • device configuration and updates,
  • protection of computers and servers.

Logs and incident response

We assess whether the business can detect and handle suspicious events.

  • monitoring and log analysis,
  • procedures for phishing and account takeover,
  • sequence of actions, contacts and record-keeping.

What will you receive after the audit?

  • a description of the areas reviewed and the assumptions made,
  • a prioritised list of identified risks,
  • technical and organisational recommendations,
  • an action plan that can be implemented in stages,
  • a review of the findings with those responsible for security.

The report does not replace certification or a formal compliance assessment, but it provides a practical basis for improving your business's protection.

How is the service delivered?

  1. Discovery. We identify the systems, locations, accounts and audit scope.
  2. Configuration review. We analyse settings, access and documentation.
  3. Risk assessment. We relate our findings to their impact on day-to-day operations.
  4. Report. We present priorities, recommendations and the limitations of the analysis.
  5. Review and plan. We agree the sequence of actions and any implementation support required.

How can we work together?

One-off audit

For a company that needs an independent assessment and report with recommendations.

Audit before change

Before migration, security implementation, supplier change or contractor requirements.

Audit with configuration improvement

Following the report, we can help you carry out the agreed corrective actions.

Support for existing IT

As a second line, consultation or independent review of the team's plan.

How do we carry out the work?

  • We agree the scope and data sources before the analysis begins.
  • We limit administrative access to the minimum necessary.
  • We do not carry out potentially disruptive tests without prior agreement.
  • We document the findings together with limitations and confidence levels.
  • We explain recommendations in terms of business impact, not technology alone.

What might require additional work?

A basic audit includes configuration analysis and report preparation. Full penetration testing, phishing testing, computer forensics, certification, 24/7 SOC implementation and partner work may require separate scope, approvals and pricing.

What determines the audit price?

The price depends on the number of users, devices, locations and systems; the availability of documentation; the depth of analysis; the scope of testing; and whether support is required to implement the recommendations.

Frequently asked questions

Does the security audit include penetration testing?

Not necessarily. Penetration testing is a separate, controlled engagement. We can assess configuration and risks or arrange the involvement of a specialist partner.

Can the audit be performed remotely?

Yes, provided that the required information and secure access to the configuration are available. Physical infrastructure may require an on-site visit.

Do you assess compliance with ISO 27001 or GDPR?

We can identify technical areas for improvement, but formal certification and a full legal assessment require a separate scope.

Is an audit worthwhile after security controls have been implemented?

Yes. Configurations and risks change as users, devices and services change.

Can you help after the audit?

Yes. We can plan and implement the agreed improvements or support your internal team.

Want to assess your business's level of protection?

Tell us about your current situation. We will determine an appropriate audit scope and propose the next steps.

Book a free consultation