What this page covers
The audit service page explains what an audit finds and why it matters. This page is about the process: what is agreed, what access I need, how it runs from start to finish, and what you are left holding at the end.
Scope, agreed in writing
Before anything starts, we agree on paper what the audit covers and what it does not. Typically that is a list of systems, sites or domains, the questions you most want answered, and anything specifically out of bounds. The price is fixed against that scope.
If I find something important outside the scope, I tell you it exists. I do not quietly expand the job, and I do not quietly ignore it either. You decide whether it is added.
Access I need
- Read-only wherever possible. The audit looks; it does not change anything.
- A named account for me, not a shared admin login. It makes my activity traceable, and it is good practice you can keep.
- Time-boxed. Access is switched off at the end of the audit, and removing it is on the checklist.
- Someone who knows the history. An hour or two with whoever runs things day to day saves days of guessing.
- Whatever paperwork exists. Diagrams, old handover notes, a list of subscriptions and renewals, invoices. If there is none, that is normal.
I never ask you to send credentials by email. We agree a secure way to share access at the start.
The shape of it
The length depends on the size of the estate, and I tell you how long before you agree to the price. The shape is always the same:
- Kick-off. Confirm scope, set up access, agree who I talk to and how urgent findings are reported.
- Discovery. Inventory from the systems themselves: servers, services, domains, certificates, accounts, subscriptions, backups, monitoring.
- Conversations. Short sessions with the people who run and depend on the estate. Most key-person risk is found here.
- Verification. Each finding is checked and its evidence recorded, so your team can confirm it without me.
- Write-up. The prioritised findings list, the inventory and a short summary.
- Walkthrough. I take you through every finding, answer questions and adjust anything I have misjudged about how your organisation works.
- Close. My access is removed, and that is confirmed in writing.
Anything urgent, such as an exposed admin panel or an expiring certificate, is reported the same day it is found. It does not wait for the write-up.
The findings list, and why you own it
Each finding states what is wrong, the evidence, a severity, an effort estimate and a recommended fix. The list is ordered so that the most serious and the quickest wins sit at the top.
It is yours outright. Give it to your own team, to your current provider, or to another consultant. It is written to be acted on by whoever you choose, and it does not assume that person is me. An audit that only makes sense if you hire the auditor is a sales document.
Questions people ask
Why a fixed price rather than hourly?
Because you should know the cost before you commit, and because it puts the risk of the work taking longer on me, which is where it belongs.
Will the audit disrupt our systems?
It should not. It is read-only, and anything that could have an effect, such as an active test, is agreed with you first and scheduled.
What if the findings are embarrassing for our team?
The list is about systems, not people. Most problems are inherited, and I write them up that way.
What comes after?
If you want me to do the work, it is scoped from the findings. If not, you have the list and we part on good terms.