Services

Cyber Security Audit and Risk Assessment

Technology is only part of your risk. An audit looks at the whole picture — controls, policies, people, suppliers and recovery capability — and gives you a costed plan you can take to a board or an insurer.

BENCHMARKS
Cyber Essentials, ISO 27001, NCSC 10 Steps
COVERS
People, Process, Technology, Suppliers
OUTPUT
Costed 12-Month Roadmap
DURATION
Typically 1-2 Weeks
In short

What is a cyber security audit?

A cyber security audit is an independent review of an organisation's security controls, policies, processes and technology against a recognised standard. It establishes where you are today, where the gaps are, and what it will cost to close them — producing a costed, prioritised roadmap rather than a pass or fail.

Why an audit comes before buying anything

Businesses routinely buy security products before they know what they are defending or against what. The result is a firewall that duplicates something the router already did, an endpoint product nobody monitors, and a genuine gap — often backups, or offboarding leavers — left completely open.

An audit fixes the sequencing. It establishes what you actually have, what you actually hold, and which controls are missing, so that every subsequent pound is spent on a known gap. For most clients the audit pays for itself in the software renewals it cancels.

What we examine

We work through five domains. Governance covers who is accountable, what policies exist and whether anyone follows them. Identity and access covers accounts, privileges, multi-factor authentication and — the perennial weak point — what happens when someone leaves. Technical controls cover patching, endpoint protection, network segmentation, email filtering and encryption.

Data covers what personal, financial or health information you hold, where it is, how long you keep it and your lawful basis under UK GDPR. Resilience covers backups, recovery times, and whether anyone has ever actually restored from a backup — which, in our experience, is roughly half of the businesses we assess.

  • Governance — policies, ownership, training records, incident procedures
  • Identity and access — accounts, privileges, MFA coverage, joiner/mover/leaver process
  • Technical controls — patching, endpoint protection, segmentation, email security
  • Data — inventory, classification, retention, UK GDPR lawful basis
  • Resilience — backup design, tested restore, documented recovery objectives
  • Suppliers — who has access to your data and what their security posture is

The roadmap you get at the end

The deliverable is deliberately practical: a table of gaps, each with a risk rating, a recommended action, an estimated cost, an estimated effort and a suggested owner, sequenced across twelve months. Quick wins that cost nothing sit at the top — they usually include enforcing MFA, removing dormant accounts and turning on features you already pay for.

That document is directly usable in a board paper, an insurance application, a client security questionnaire, or a grant or funding application.

  • Phase 1 (0-30 days) — no-cost and low-cost fixes that remove the largest risks
  • Phase 2 (1-3 months) — configuration and process changes, policy adoption
  • Phase 3 (3-12 months) — certification, investment decisions, maturity building
What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Agreement Ready

Master Services Agreement (MSA)

The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.

UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified

Request This Agreement →
Frequently asked questions

Cyber Security Audit — your questions answered

What is the difference between a cyber security audit and a vulnerability assessment?
A vulnerability assessment is technical and finds weaknesses in systems. An audit is broader: it reviews policies, people, processes, suppliers and recovery capability alongside technology, and measures all of it against a recognised standard. Many clients commission both, with the assessment feeding into the audit.
How long does a cyber security audit take?
For a typical SME, one to two weeks including interviews, evidence review and report writing. Time on your side is usually three to five hours of interviews plus supplying documentation.
Which standard should we be audited against?
For most UK SMEs, Cyber Essentials is the right starting benchmark and the NCSC 10 Steps a good broader frame. If you sell to enterprise or public sector clients who ask for it, ISO 27001 Annex A is the benchmark to use.
Will an audit help with our cyber insurance?
Usually, yes. Insurers increasingly ask specific control questions — MFA coverage, backup regime, patching cadence, endpoint protection. An audit gives you documented evidence for those questions, and closing the gaps it identifies can affect both premium and whether cover is offered at all.
Do you write the policies for us, or just tell us they are missing?
We draft them. Audit clients receive practical, UK-appropriate policy documents tailored to how the business actually operates, rather than a generic template pack nobody reads.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about cyber security audit?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.