About
An assurance practice, not an IT solutions provider
CyberAudit provides independent IT audit, information systems audit and cyber security assurance to regulated organisations in Pakistan and the Gulf.
What we do, stated narrowly
We examine whether technology controls exist, whether they are designed to address the risk they are supposed to address, and whether they actually operate. We report what we find, with evidence, to the people accountable for doing something about it.
That is a deliberately narrow description. We are not a systems integrator, a managed service provider or a software reseller. We do not implement the controls we audit and we do not sell the products we recommend.
Why independence is the whole proposition
A firm that builds your information security management system cannot independently audit it. A firm that configures your ERP cannot objectively assess whether the control design is sound. A firm that earns margin on a security product has an interest in the finding that justifies it.
These are not hypothetical concerns. They are the standard objections a regulator, an external auditor or a competent audit committee will raise about assurance work — and they are raised because the conflict is real and well documented in professional standards.
Our position is simple and we apply it without exception: we do not audit our own work. Where we have provided advisory or implementation support to a client, we do not provide independent assurance over that same scope. We will tell you this at proposal stage, even where it costs us the engagement.
How we run an engagement
How we work
- Scope is agreed in writing, including exclusions. An unbounded scope cannot be defended later. What we did not cover is stated as clearly as what we did.
- Every finding is evidenced. No finding reaches a report without an artefact behind it and a validation conversation with the control owner first.
- Population completeness is established independently. Sampling from a management-prepared list is not testing.
- Findings are reported with root cause. A list of instances produces a list of retrospective fixes and the same finding next year.
- Reports are written for their audience. The audit committee summary is not the technical annex with the diagrams removed.
- No surprises at closing. Every exception has been discussed before the closing meeting.
Standards we work to
Engagements are conducted in accordance with ISACA's ITAF, the IT audit and assurance framework, and reference the relevant subject-matter framework — COBIT 2019 for governance, ISO/IEC 27001:2022 for information security management, ISO 22301:2019 for continuity, NIST CSF 2.0 for cyber security programme structure, OWASP standards for application testing, and the specific regulatory framework where one applies.
Where we work alongside an internal audit function, we align to the IIA's Global Internal Audit Standards so the work integrates with the function's own quality framework.
Who we work with
Banks, Islamic banks, development finance institutions and microfinance banks under State Bank of Pakistan supervision. Listed companies, insurers and NBFCs under SECP oversight. Payment businesses and fintechs. Telecom operators and technology firms. And, in the Gulf, financial institutions and critical entities subject to SAMA, NCA and UAE requirements.
We work across Pakistan and the Gulf, and scope by sector because the regulatory framing changes everything about how an engagement runs.
Read further
Our methodology sets out how an engagement actually runs — the four practices that separate a defensible working paper file from a weak one, and why population completeness matters more than sample size.
Credentials and accreditations lists what our practitioners hold, and states plainly what the firm does not hold and what we offer instead.
The team names the people who deliver the work. If you are thinking about joining them, we are hiring.
Frequently asked questions
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal