Cyber Security
Cyber security audit
A cyber security audit covering identity and MFA, endpoints, email, backups, network, patching and access, with a prioritised action plan. Fixed-price.
In short
A cyber security audit is a structured review of how well your business is protected against the attacks most likely to hit it: weak identity and MFA, unpatched devices, exposed email, untested backups, open networks and excess access. Dig IT Solutions delivers a report with prioritised, costed actions, so you know what to fix first and why.
When you need this
Signs this is the right conversation
- We've never had anyone independent look at our security.
- Our insurer or a client has asked what controls we have and we don't have an answer.
- We think we're OK but we can't prove it.
- We inherited our setup from a previous provider and don't know what's in it.
- Cyber Essentials is on the horizon and we don't know how far off we are.
Scope
What we deliver
Identity and MFA review
Every account checked for MFA, admin rights, legacy authentication, shared logins, stale users and Conditional Access coverage.
Endpoint review
Laptops, desktops and servers assessed for patch status, encryption, local admin rights, endpoint protection and supported operating systems.
Email security review
SPF, DKIM and DMARC records, anti-phishing settings, external forwarding rules, mailbox delegation and safe attachment and link protection.
Backup and recovery check
What is backed up, how often, where it's stored, whether it's protected from ransomware and when a restore was last tested.
Network and access review
Firewall configuration, remote access methods, Wi-Fi segregation, open ports, VPN setup and who can reach what.
Prioritised report
A plain-English report scored by risk, with quick wins, medium-term fixes and larger projects, each with an indicative cost and effort.
Walkthrough meeting
An hour with your management team to explain the findings and agree what happens next.
Outcomes
What you get out of it
- A clear, prioritised list rather than a vague sense of unease.
- Evidence for insurers, clients and boards.
- A gap analysis against Cyber Essentials if certification is a goal.
- A baseline to measure improvement against.
FAQ
Questions we are asked
What is a cyber security audit?
How is this different from your IT health check?
How can I find cyber security weaknesses in my small business?
Does the audit include penetration testing?
How much does a cyber security audit cost?
Insights
Further reading
Guides & Checklists
What is an IT audit? What it checks, what it usually finds and how often to do one
What a business IT audit covers, the risks it typically finds (untested backups, leavers with access, ageing kit) and how often UK SMEs should audit their IT.
Cyber Security
How to find the cyber security weaknesses in your small business
A cyber security self-assessment for UK small businesses built on the five Cyber Essentials controls plus backups, people and suppliers, with a fix for each.
Cyber Security
What is Cyber Essentials? (And does your business need it?)
Cyber Essentials explained for UK small businesses: the five controls, Cyber Essentials vs Plus, who requires it, and the process, timeline and cost.
Next step
Talk to an engineer, not a sales script
Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

