Cyber Security Audit and Risk Assessment
Technology is only part of your risk. An audit looks at the whole picture — controls, policies, people, suppliers and recovery capability — and gives you a costed plan you can take to a board or an insurer.
What is a cyber security audit?
A cyber security audit is an independent review of an organisation's security controls, policies, processes and technology against a recognised standard. It establishes where you are today, where the gaps are, and what it will cost to close them — producing a costed, prioritised roadmap rather than a pass or fail.
Why an audit comes before buying anything
Businesses routinely buy security products before they know what they are defending or against what. The result is a firewall that duplicates something the router already did, an endpoint product nobody monitors, and a genuine gap — often backups, or offboarding leavers — left completely open.
An audit fixes the sequencing. It establishes what you actually have, what you actually hold, and which controls are missing, so that every subsequent pound is spent on a known gap. For most clients the audit pays for itself in the software renewals it cancels.
What we examine
We work through five domains. Governance covers who is accountable, what policies exist and whether anyone follows them. Identity and access covers accounts, privileges, multi-factor authentication and — the perennial weak point — what happens when someone leaves. Technical controls cover patching, endpoint protection, network segmentation, email filtering and encryption.
Data covers what personal, financial or health information you hold, where it is, how long you keep it and your lawful basis under UK GDPR. Resilience covers backups, recovery times, and whether anyone has ever actually restored from a backup — which, in our experience, is roughly half of the businesses we assess.
- Governance — policies, ownership, training records, incident procedures
- Identity and access — accounts, privileges, MFA coverage, joiner/mover/leaver process
- Technical controls — patching, endpoint protection, segmentation, email security
- Data — inventory, classification, retention, UK GDPR lawful basis
- Resilience — backup design, tested restore, documented recovery objectives
- Suppliers — who has access to your data and what their security posture is
The roadmap you get at the end
The deliverable is deliberately practical: a table of gaps, each with a risk rating, a recommended action, an estimated cost, an estimated effort and a suggested owner, sequenced across twelve months. Quick wins that cost nothing sit at the top — they usually include enforcing MFA, removing dormant accounts and turning on features you already pay for.
That document is directly usable in a board paper, an insurance application, a client security questionnaire, or a grant or funding application.
- Phase 1 (0-30 days) — no-cost and low-cost fixes that remove the largest risks
- Phase 2 (1-3 months) — configuration and process changes, policy adoption
- Phase 3 (3-12 months) — certification, investment decisions, maturity building
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Master Services Agreement (MSA)
The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.
UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified
Cyber Security Audit — your questions answered
What is the difference between a cyber security audit and a vulnerability assessment?
How long does a cyber security audit take?
Which standard should we be audited against?
Will an audit help with our cyber insurance?
Do you write the policies for us, or just tell us they are missing?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about cyber security audit?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.