# Cyber security audits.

> Independent cyber security and IT security audits in London. We check your controls, network and policies against how they really work.

Canonical: https://cybersecuritylondon.com/security-audits


An independent check of the controls you already have. We compare what is configured, what is written down and what actually happens day to day, then show you where they differ.

Covers: IT security audit, Network security audit, Policy review, Evidence for clients.

## Overview

Policies and settings drift over time. People leave but keep access, firewall rules pile up, and documents describe processes nobody follows any more. An audit finds those gaps.

We review your controls against good practice and any standard you work to, then give you clear findings and evidence you can share with clients, insurers and auditors.

### A good fit if

- Clients or insurers ask for evidence of your security
- You have never had an independent review
- You have changed IT provider or grown quickly
- You are preparing for ISO 27001 or a regulatory review

## What's included

- **Access review**: Who has access to what, including leavers, admin rights and shared accounts.
- **Network security audit**: Firewall rules, segmentation, remote access and wireless setup.
- **Configuration review**: Servers, laptops, Microsoft 365 or Google Workspace settings.
- **Policy and process review**: Whether documents match what people actually do.
- **Backup and recovery check**: Whether backups exist, are protected, and can be restored.
- **Audit report**: Findings, evidence and recommendations in a clear, shareable format.

## How it works

1. **Plan**: Agree the scope and any standard to audit against.
2. **Review**: Examine settings, records and documents.
3. **Verify**: Interview staff and sample real activity.
4. **Report**: Findings, evidence and recommended fixes.

## Audit types

- **IT security audit**: A broad review of your IT controls, accounts, devices and cloud services.
- **Network security audit**: A focused review of firewalls, network design and remote access.
- **Cloud and Microsoft 365 audit**: Security settings, sharing and identity configuration in your cloud tenancy.
- **Compliance audit**: A review against a specific standard such as ISO 27001, Cyber Essentials or PCI DSS.

## What affects the cost

- **Scope**: A focused network audit is quicker than a full IT security audit.
- **Standards**: Auditing against a formal standard adds evidence gathering.
- **Sites and systems**: The number of locations, networks and platforms involved.
- **Reporting needs**: Whether the report needs to be shared with third parties.

Every audit is quoted at a fixed price once the scope is agreed.

## Frequently asked questions

### What is a cyber security audit?

It is an independent review of your security controls, checking that they are set up correctly, documented and working as intended.

### What is the difference between an audit and an assessment?

An assessment looks at risk and what could go wrong. An audit checks your existing controls against a defined standard or policy and records the evidence.

### How often should we audit our IT security?

Once a year is a sensible baseline, with additional reviews after major changes such as a new IT provider or office move.

### Will we get something we can show clients?

Yes. The report includes a summary suitable for sharing with clients, insurers or auditors.

## Related services

- [Cyber Security Assessments](https://cybersecuritylondon.com/cyber-security-assessments)
- [ISO 27001](https://cybersecuritylondon.com/iso-27001)
- [Penetration Testing](https://cybersecuritylondon.com/penetration-testing)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
