Security audit, Sydney
Cyber security audit for your business
An assessment of what a business actually runs, against a scope agreed in writing before it starts. You get findings you can act on, and a plain statement of what was left out.
- Output
- A written findings report
- Scope
- Agreed in writing first
- Rate
- $1,000 a day, plus GST
- Reply
- Within one business day
What gets looked at
The scope is set with you before the audit starts, so this list is a starting point rather than a fixed menu. What ends up in scope is written down, and so is what does not.
What answers from outside
The services reachable from the internet, what they give away about themselves, and which of them nobody meant to leave open.
Who can reach what
Accounts and permissions across the systems in scope, and how far a single taken account would get before something stopped it.
Whether a restore works
Whether backups run is only half of it. Whether anyone has restored from one, how long that took, and what the backup leaves out.
What would be left to look at
The logs and records the systems keep, and how far back they go. If an incident happened last month, this decides whether it can still be traced.
Scope. Look. Verify. Report.
Nothing is changed during the audit. It reads, it checks, and it writes down what it found.
Scope
What is in, what is out, what may be touched and what must not be. Agreed in writing before the first check runs.
Look
Configuration, exposure, accounts and records are reviewed against the scope, using your own access where it is needed.
Verify
Anything that looks wrong is confirmed before it is written up, so the report carries findings and not guesses.
Report
One written report: what was checked, what was found, what to fix first, and what the audit did not cover.
What an audit is not
Worth saying up front, because a reader who assumes otherwise has bought the wrong thing.
An audit reports against a framework. It does not certify compliance with one, and nothing in the report should be read as a certificate.
An audit finds what is in scope on the day it runs. It is not proof that nothing else exists, and it says nothing about the state of a system a week later.
An audit is a review. Fixing what it finds is a separate decision, and the report is written so you can hand it to your own people or to anyone else.
What it costs, and how to start
Every audit is quoted before it starts, from a rate of $1,000 a day. All prices are in AUD, plus GST. How long an audit takes is set by how much you put in scope, which is why the scope is agreed first.
Reply within one business day. Say what the business runs and what you are worried about, and the scope comes back in writing.
Questions to ask before booking an audit
Does the audit certify us as compliant?
No. The report describes what was found against whatever framework you name. It does not certify compliance, and no certification is issued or implied by this work.
Do you change anything during the audit?
No. The audit reads, tests what you have agreed can be tested, and reports. Fixing what it finds is a separate decision, and the report is written so you can hand it to your own people or to anyone else.
How long does an audit take?
It depends on how much is in scope. Scope is agreed and the matter quoted before anything starts, built from a rate of $1,000 a day, plus GST.
What is in the report?
What was checked, what was found, how it was found, and what to do about it. Findings are ordered by what to fix first. Anything checked and found sound is listed too, so the report shows its own coverage.
What are the limits of an audit?
An audit finds what is in scope on the day it runs. It is not proof that nothing else exists, it does not cover what you keep out of scope, and it says nothing about the state of a system a week later.