Security audit, Sydney

Cyber security audit for your business

An assessment of what a business actually runs, against a scope agreed in writing before it starts. You get findings you can act on, and a plain statement of what was left out.

Output
A written findings report
Scope
Agreed in writing first
Rate
$1,000 a day, plus GST
Reply
Within one business day

What gets looked at

The scope is set with you before the audit starts, so this list is a starting point rather than a fixed menu. What ends up in scope is written down, and so is what does not.

Exposure

What answers from outside

The services reachable from the internet, what they give away about themselves, and which of them nobody meant to leave open.

Access

Who can reach what

Accounts and permissions across the systems in scope, and how far a single taken account would get before something stopped it.

Backups

Whether a restore works

Whether backups run is only half of it. Whether anyone has restored from one, how long that took, and what the backup leaves out.

Records

What would be left to look at

The logs and records the systems keep, and how far back they go. If an incident happened last month, this decides whether it can still be traced.

Scope. Look. Verify. Report.

Nothing is changed during the audit. It reads, it checks, and it writes down what it found.

  1. Scope

    What is in, what is out, what may be touched and what must not be. Agreed in writing before the first check runs.

  2. Look

    Configuration, exposure, accounts and records are reviewed against the scope, using your own access where it is needed.

  3. Verify

    Anything that looks wrong is confirmed before it is written up, so the report carries findings and not guesses.

  4. Report

    One written report: what was checked, what was found, what to fix first, and what the audit did not cover.

What an audit is not

Worth saying up front, because a reader who assumes otherwise has bought the wrong thing.

An audit reports against a framework. It does not certify compliance with one, and nothing in the report should be read as a certificate.

An audit finds what is in scope on the day it runs. It is not proof that nothing else exists, and it says nothing about the state of a system a week later.

An audit is a review. Fixing what it finds is a separate decision, and the report is written so you can hand it to your own people or to anyone else.

What it costs, and how to start

Every audit is quoted before it starts, from a rate of $1,000 a day. All prices are in AUD, plus GST. How long an audit takes is set by how much you put in scope, which is why the scope is agreed first.

Reply within one business day. Say what the business runs and what you are worried about, and the scope comes back in writing.

Questions to ask before booking an audit

Does the audit certify us as compliant?

No. The report describes what was found against whatever framework you name. It does not certify compliance, and no certification is issued or implied by this work.

Do you change anything during the audit?

No. The audit reads, tests what you have agreed can be tested, and reports. Fixing what it finds is a separate decision, and the report is written so you can hand it to your own people or to anyone else.

How long does an audit take?

It depends on how much is in scope. Scope is agreed and the matter quoted before anything starts, built from a rate of $1,000 a day, plus GST.

What is in the report?

What was checked, what was found, how it was found, and what to do about it. Findings are ordered by what to fix first. Anything checked and found sound is listed too, so the report shows its own coverage.

What are the limits of an audit?

An audit finds what is in scope on the day it runs. It is not proof that nothing else exists, it does not cover what you keep out of scope, and it says nothing about the state of a system a week later.

Find out what is open before someone else does.