Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Security Audit

Organizations required by a client, regulator, or insurer to prove a state of security, without a documented baseline to show.

Last updatedAugust 22, 2026

The problem this solves

A client, regulator, or insurer demands proof of your security posture, and you have nothing documented to present. The absence of a formalized baseline turns every such request into an unplanned emergency.

What's included

Organizational and physical audit (governance, policies, physical access controls)

Architecture audit (segmentation, data flows, exposure points)

Configuration audit (hardening of systems, equipment, services)

Penetration testing (operational validation of identified vulnerabilities)

Source code audit (review of sensitive application points)

Industrial systems audit (OT/SCADA environments)

Frameworks applied

ISO/IEC 27001:2022ISO/IEC 19011NIST SP 800-115CIS BenchmarksDGSSI security audit guideTRACE methodology

Deliverables

Detailed technical report with evidence (screenshots, configuration excerpts, test results)

Non-technical executive summary for leadership

Remediation plan prioritized by risk and effort

Post-fix counter-verification after identified gaps are corrected

Varies by domain: configuration audit 3-5 days, architecture audit 5-8 days, organizational audit 8-15 days

Typical duration

Client prerequisites

  • A designated contact authorized to grant access to the relevant systems and documents
  • A scope validated in writing before kickoff
  • Availability of internal technical teams during interview and collection phases
  • Formal authorization covering intrusive activities where applicable (penetration testing within scope)

Frequently asked questions

Do all six domains need to be audited every time?

No. The scope is defined based on your actual needs — contractual requirement, regulatory obligation, or voluntary initiative. A single domain can be sufficient.

What is the TRACE methodology referenced among the applied frameworks?

TRACE is our proprietary audit-conduct methodology. It is detailed on our dedicated approach page.

Can the report be used with a regulator or insurer?

Yes, the technical report and executive summary are built to be shared with a third party (regulator, insurer, client) without further rework.

Is counter-verification systematic?

It is offered after the remediation plan has been implemented, to confirm identified gaps are actually fixed. It is not automatically included in every audit format — it is specified at contracting.

Does a configuration audit replace a penetration test?

No. The configuration audit checks settings against a reference baseline; the penetration test validates, through actual exploitation, whether vulnerabilities are exploitable in your specific context.

Get in touch