A walk-through, not a scan
Anyone can run a vulnerability scanner and hand you four hundred pages of findings sorted by a severity score that means nothing to your business. We do run the scanner. Then a person reads the results, walks around your office, asks awkward questions, and gives you a list short enough to finish.
What we look at
People and accounts
- Who has administrator rights, and why
- Accounts belonging to people who have left
- Multi-factor coverage, including the exceptions
- Shared mailboxes and their forwarding rules
Machines and network
- What is reachable from the internet
- Patch levels, including firmware
- Wi-Fi, guest access and the device nobody recognizes
- Whether a backup can really be restored
How it runs
- Kick-off call. Thirty minutes. We agree scope and you tell us what keeps you up.
- Two days on site. Scanning, interviews, and looking in cupboards.
- Draft findings. Within a week. You correct anything we have misunderstood.
- Walk-through. We present the final report to whoever needs to hear it, and answer questions until there are none left.
Filling in a cyber insurance form?
The audit report is written to map directly onto the questions insurers ask. Most clients attach it to the renewal and stop there. There is more on this in our note on insurance questionnaires.