Know where to focus your cybersecurity efforts.
You have tools, practices and questions. A clearly defined assessment helps you move from a sense of risk to well-founded actions.
Define the question before the checks.
The need may concern access, workstations, a site or a wider organisation. We specify the systems involved, the objectives and the authorisations required. A documentation audit, a configuration review and a penetration test are different services.
Compare what exists with how it is used.
The documents available, discussions with your contacts and the agreed checks make it possible to describe the situation. Findings must stay tied to the scope observed: anything that has not been checked is not considered secure by default.
Prioritise the next steps.
The deliverable agreed at the scoping stage should separate findings, limits and recommendations. We link the proposed actions to their impact, their dependencies and the people needed to move forward. A useful plan should be something you can discuss with senior management.
Plan how fixes will be validated.
Fixing an issue and checking that it is resolved are two separate steps. How follow-up or re-testing will work should be set out in the proposal. The audit is not a guarantee against every attack, nor a general regulatory attestation.
Your questions
Can you test a system without permission?
No. Any intrusive check requires an explicit scope and authorisation.
Is the audit free?
The scope and commercial terms are agreed with you before the work starts.
Further reading
Got a digital issue? You don’t have to work out who should handle it.
Describe your situation in your own words. The Skill Group team will get back to you to talk it through.