Security & Continuity

Cybersecurity Audit

From $7,000.00 one-time, per audit

One-time project fee — no recurring charges.

A structured assessment of your network, cloud accounts and policies, ending in a prioritized remediation plan your team can act on.

About this service

  • External vulnerability scanning and internal network assessment
  • Microsoft 365 or Google Workspace security configuration review
  • Findings mapped to CIS Controls v8 and NIST CSF 2.0
  • Executive summary plus a detailed technical report with remediation steps
  • Live findings walkthrough, with retesting on Professional and Enterprise

Plans at a glance

Compare all features

About Cybersecurity Audit

Cyber insurers, enterprise customers and boards increasingly ask the same question: how do you know your company is secure? A Cybersecurity Audit gives you an evidence-based answer. We test your external exposure, scan internal systems, review Microsoft 365 or Google Workspace security settings and examine the policies behind them.

Findings are rated by risk and effort and mapped to widely used frameworks — CIS Critical Security Controls v8 and the NIST Cybersecurity Framework 2.0 — so your remediation plan speaks the same language as insurance questionnaires and customer security reviews. You receive an executive summary for leadership, a technical report for IT and a live walkthrough of the results.

The audit is a point-in-time assessment, not a certification. Professional and Enterprise include a retest of critical and high findings so you can show they were fixed.

Compare plans

All prices in USD, one-time per audit. Swipe the table sideways to see every plan.

Plan comparison for Cybersecurity Audit
Feature Business Professional Recommended Enterprise
Price $7,000.00 one-time, per audit $38,000.00 one-time, per audit
Best for A baseline security assessment for small organizations. Broad assessment covering applications, cloud and people.
What’s included
  • External vulnerability scan of up to 8 public IP addresses
  • Internal vulnerability scan of up to 100 hosts
  • Microsoft 365 or Google Workspace security review
  • MFA, password and backup policy review
  • Prioritized remediation plan and 1-hour readout
  • Up to 1,000 internal hosts and 64 public IP addresses
  • Everything in Professional
  • Authenticated web application testing (up to 2 applications)
  • AWS, Azure or Google Cloud configuration review
  • Simulated phishing campaign with awareness results
  • Board-level presentation of results
Order
Customize term & quantity for the Business plan
Customize term & quantity for the Enterprise plan

Specifications

Specifications for Cybersecurity Audit
SKUTS-SEC-503
CategorySecurity & Continuity
PricingOne-time fee, per audit
BillingOne-time project fee
ScopeUp to 100 / 250 / 1,000 internal hosts depending on tier
TestingVulnerability scanning; penetration testing on higher tiers
FrameworksCIS Controls v8, NIST CSF 2.0
DeliverablesExecutive summary, technical report, remediation roadmap
DurationTypically 2 to 6 weeks from kickoff
ConfidentialityMutual NDA signed before any testing
Lead timeKickoff within 10 business days

Frequently asked questions

Will the audit disrupt our operations?

Testing is planned with you in advance, and anything that could affect production, such as penetration testing, is scheduled in agreed windows. We stop immediately if we observe any impact.

Does this certify us for SOC 2, ISO 27001 or HIPAA?

No. The audit is an independent technical and policy assessment. Its findings help you prepare for a formal certification or compliance audit, which must be performed by a qualified auditing firm.

Who sees our results?

Only the contacts you designate. Reports are delivered through an encrypted share, and testing data is deleted 90 days after the final report unless you ask us to keep it for the retest.

What do we need to provide?

A technical contact, network diagrams if available, a list of in-scope systems and, for internal testing, either remote access or a small virtual appliance that we provide.

Have another question? Ask a solutions architect