An honest picture of where you stand, with the gaps identified and a list of actions ordered by what genuinely matters first.
An audit doesn't have to end in a certificate. Most of the time it serves something more immediate: putting in writing what exists, what works and what is missing, before committing budget in the wrong direction.
I work with the frameworks the sector already uses, and also with tailored reviews when none of them quite fits what the organisation needs to look at. The framework is the measuring stick, not the objective.
A client, the parent company or a contract has asked about your security level, and there is no answer in writing that holds up.
You can invest, but nobody can say what comes first. Without an assessment, the shopping list ends up being written by whichever salesperson called last.
Before starting on ISO 27001, ENS or TISAX it pays to know how much ground is already covered. It is usually more than people think, and in different places.
For companies with fewer than 100 employees that want to know where they stand before investing. Three audit days covering the full framework of your choice, with no areas left out. If none fits, the review is built around your own risks.
Not includedReviews of Microsoft environments (Microsoft 365, Entra ID or Azure), penetration testing, certification and implementing the improvements. If you need any of them, they are quoted separately.
The scope is agreed with you before starting. These are the usual blocks: the ones that apply are taken, the ones that don't are left out.
Where the organisation stands and who decides on security.
What can go wrong and what is in place today to prevent it.
The exact distance between where you are and where you need to be.
Four phases. The duration depends on scope and size, and is agreed before starting rather than as we go.
What gets audited, against which framework, who needs interviewing and what is out of scope. In writing and approved before anything is touched.
Interviews with the areas involved, document review, and checking in the systems what was said in the interviews.
Comparison against the framework, assessment of each gap by impact and effort, and ordering all of it by priority.
Presentation of results to the board and to IT, questions answered, and handover of the report and the action plan.
Documents that can actually be used: one to decide with, one to work from.
Scope of the serviceThe work runs up to the assessment and the action plan. Certification is issued by an accredited, independent body, and implementing whatever comes out is treated as a separate project —I can do it, or your team can, with the report in hand. If what you are after is a penetration test, that is a different kind of engagement and I will point you to who does it.
No. Only an accredited body can certify, and it cannot be the same one that prepared you. What this audit does is tell you how far you are from passing that certification and in what order to close the distance, which is exactly what you need to know before booking it.
The initial assessment has a fixed price: €1,075 excl. VAT when you request it through this website (the standard rate is €1,500). It is for companies with fewer than 100 employees and consists of three audit days against the framework of your choice: ISO/IEC 27001 and 27002, ENS (Spain's National Security Framework), NIS2, TISAX, ISO/IEC 42001, NIST CSF 2.0, CIS Controls or a custom review. For organisations with 100 or more employees, or if Microsoft environments need reviewing, the price comes from the number of days needed, and you get it fixed before we start.
It depends on the scope and the size of the organisation. A review of a small or mid-sized company usually runs two to four weeks of calendar time, counting interviews, checks and writing. You get person-days and a deadline agreed before we start; if a quote doesn't say how many days it includes, it isn't telling you the price.
It works just the same. An ad-hoc audit starts from your context and your risks, without the straitjacket of a framework that doesn't apply to you. Plenty of organisations don't need to certify against anything: they need to know where they are weak.
No. The work is hour-long interviews with the relevant people and read-only access to verify what was described. The load on your team is real but bounded, and it gets planned with you.
Not with the same independence, and I will say so before you have to ask. If I implemented something, reviewing that part loses impartiality. When it happens I flag it in the report, or we bring in someone external for that block.
Yes, and it is free. If NIS2 is the worry, the checklist tells you whether it applies to you and how you score on 16 controls. If the topic is Microsoft 365, the Purview simulator tells you which capabilities you are already paying for. With that in hand, the first conversation is much shorter.
To connect these controls with identities, applications, data and exceptions, read the Microsoft 365 security assessment guide. It explains which evidence to review and how to prioritise improvements.
Tell me what you are being asked for, what you have in place and what worries you. Out of that comes the scope of the audit —or the conclusion that you don't need one yet. Both answers are useful.
I reply personally within 24 working hours · No commitment