Skip to main content

Cyber Security

Cyber security audit

A cyber security audit covering identity and MFA, endpoints, email, backups, network, patching and access, with a prioritised action plan. Fixed-price.

In short

A cyber security audit is a structured review of how well your business is protected against the attacks most likely to hit it: weak identity and MFA, unpatched devices, exposed email, untested backups, open networks and excess access. Dig IT Solutions delivers a report with prioritised, costed actions, so you know what to fix first and why.

When you need this

Signs this is the right conversation

  • We've never had anyone independent look at our security.
  • Our insurer or a client has asked what controls we have and we don't have an answer.
  • We think we're OK but we can't prove it.
  • We inherited our setup from a previous provider and don't know what's in it.
  • Cyber Essentials is on the horizon and we don't know how far off we are.

Scope

What we deliver

  • 01

    Identity and MFA review

    Every account checked for MFA, admin rights, legacy authentication, shared logins, stale users and Conditional Access coverage.

  • 02

    Endpoint review

    Laptops, desktops and servers assessed for patch status, encryption, local admin rights, endpoint protection and supported operating systems.

  • 03

    Email security review

    SPF, DKIM and DMARC records, anti-phishing settings, external forwarding rules, mailbox delegation and safe attachment and link protection.

  • 04

    Backup and recovery check

    What is backed up, how often, where it's stored, whether it's protected from ransomware and when a restore was last tested.

  • 05

    Network and access review

    Firewall configuration, remote access methods, Wi-Fi segregation, open ports, VPN setup and who can reach what.

  • 06

    Prioritised report

    A plain-English report scored by risk, with quick wins, medium-term fixes and larger projects, each with an indicative cost and effort.

  • 07

    Walkthrough meeting

    An hour with your management team to explain the findings and agree what happens next.

Outcomes

What you get out of it

  • A clear, prioritised list rather than a vague sense of unease.
  • Evidence for insurers, clients and boards.
  • A gap analysis against Cyber Essentials if certification is a goal.
  • A baseline to measure improvement against.

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
What is a cyber security audit?
A cyber security audit is an independent review of your technical controls, configuration and processes against known good practice, such as NCSC guidance and the Cyber Essentials controls. It identifies weaknesses an attacker could use, ranks them by likelihood and impact, and recommends fixes. For a small business it is usually a few days' work followed by a written report and a meeting.
How is this different from your IT health check?
The IT health check at the IT health check is a broad, light-touch look at your whole IT setup: support, devices, backups, network and security. A cyber security audit goes deeper on security alone, tests configuration rather than asking about it, and produces a scored report. Many businesses start with the health check and commission an audit if it raises concerns or if certification is planned.
How can I find cyber security weaknesses in my small business?
Start with the areas attackers use most: accounts without MFA, devices missing updates, email domains without SPF, DKIM and DMARC, backups that have never been restored, and staff with more access than their job needs. Checking these properly takes admin access and the right tools, which is where an audit helps. The NCSC Small Business Guide is a good self-assessment starting point.
Does the audit include penetration testing?
No. An audit reviews configuration and controls from the inside with admin access. A penetration test simulates an attacker trying to break in from outside and is carried out by specialist testers. For most businesses of up to 250 people an audit finds the issues that matter, and we can arrange penetration testing through a partner if a client contract or regulator requires it.
How much does a cyber security audit cost?
Audits are quoted fixed-price after a short scoping call, with the figure depending on user count, number of sites, servers and the systems in scope. Remediation is priced separately once you've seen the report, so you decide what to act on. Contact us at the contact page to arrange scoping, or start with the IT health check if you want a broader first look.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us