Skip to content

Services

What we audit

Assurance, advisory and technical testing. Every engagement is scoped in writing, evidenced, and reported to whoever is accountable for acting on it.

Choosing the right engagement

If you are not sure which of these you need, describe the problem rather than the solution when you get in touch. The most common mistake we see is an organisation commissioning a penetration test when the actual question their board asked was about governance — two very different engagements, and only one of them answers it.

How our engagements run

1 Plan 2 Walkthrough 3 Design 4 Operating 5 Validate 6 Report Every exception is validated with the control owner before it becomes a finding
The same six-stage shape across every assurance engagement, scaled to the scope.

Audit and assurance

Independent examination of whether controls exist, are well designed, and actually operate.

Advisory and technical testing

Where the need is to build or to test rather than to assure.

Frameworks and standards we audit against

ISACA ITAF COBIT 2019 ISO/IEC 27001:2022 ISO 22301:2019 NIST CSF 2.0 OWASP ASVS PCI DSS IIA Standards

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top