Skip to content

About

An assurance practice, not an IT solutions provider

CyberAudit provides independent IT audit, information systems audit and cyber security assurance to regulated organisations in Pakistan and the Gulf.

What we do, stated narrowly

We examine whether technology controls exist, whether they are designed to address the risk they are supposed to address, and whether they actually operate. We report what we find, with evidence, to the people accountable for doing something about it.

That is a deliberately narrow description. We are not a systems integrator, a managed service provider or a software reseller. We do not implement the controls we audit and we do not sell the products we recommend.

Why independence is the whole proposition

A firm that builds your information security management system cannot independently audit it. A firm that configures your ERP cannot objectively assess whether the control design is sound. A firm that earns margin on a security product has an interest in the finding that justifies it.

These are not hypothetical concerns. They are the standard objections a regulator, an external auditor or a competent audit committee will raise about assurance work — and they are raised because the conflict is real and well documented in professional standards.

Our position is simple and we apply it without exception: we do not audit our own work. Where we have provided advisory or implementation support to a client, we do not provide independent assurance over that same scope. We will tell you this at proposal stage, even where it costs us the engagement.

How we run an engagement

1 Plan 2 Walkthrough 3 Design 4 Operating 5 Validate 6 Report Every exception is validated with the control owner before it becomes a finding
Design effectiveness before operating effectiveness. Every exception validated with the control owner before it becomes a finding.

How we work

  • Scope is agreed in writing, including exclusions. An unbounded scope cannot be defended later. What we did not cover is stated as clearly as what we did.
  • Every finding is evidenced. No finding reaches a report without an artefact behind it and a validation conversation with the control owner first.
  • Population completeness is established independently. Sampling from a management-prepared list is not testing.
  • Findings are reported with root cause. A list of instances produces a list of retrospective fixes and the same finding next year.
  • Reports are written for their audience. The audit committee summary is not the technical annex with the diagrams removed.
  • No surprises at closing. Every exception has been discussed before the closing meeting.

Standards we work to

Engagements are conducted in accordance with ISACA's ITAF, the IT audit and assurance framework, and reference the relevant subject-matter framework — COBIT 2019 for governance, ISO/IEC 27001:2022 for information security management, ISO 22301:2019 for continuity, NIST CSF 2.0 for cyber security programme structure, OWASP standards for application testing, and the specific regulatory framework where one applies.

Where we work alongside an internal audit function, we align to the IIA's Global Internal Audit Standards so the work integrates with the function's own quality framework.

Who we work with

Banks, Islamic banks, development finance institutions and microfinance banks under State Bank of Pakistan supervision. Listed companies, insurers and NBFCs under SECP oversight. Payment businesses and fintechs. Telecom operators and technology firms. And, in the Gulf, financial institutions and critical entities subject to SAMA, NCA and UAE requirements.

We work across Pakistan and the Gulf, and scope by sector because the regulatory framing changes everything about how an engagement runs.

Read further

Our methodology sets out how an engagement actually runs — the four practices that separate a defensible working paper file from a weak one, and why population completeness matters more than sample size.

Credentials and accreditations lists what our practitioners hold, and states plainly what the firm does not hold and what we offer instead.

The team names the people who deliver the work. If you are thinking about joining them, we are hiring.

Frequently asked questions

We can advise on remediation approach and we can train your team. What we will not do is implement a control and then provide independent assurance over it for the same client. If you need implementation delivery, we will say so and you should engage someone else for it — that separation is what makes our opinion worth having.

Our focus is Pakistan and the GCC, because that is where our regulatory knowledge is deepest and it is the knowledge, not the control testing, that clients are actually buying. We take work elsewhere selectively and will tell you plainly if a market is outside our competence.

Fixed fee against an agreed scope for most assurance work, and a retained monthly fee for vCISO engagements. We quote after scoping rather than before, because a fee given without understanding the environment is a guess that gets corrected later at your expense.

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top