
Do you really know where your IT is vulnerable?
Find vulnerabilities before attackers do
A comprehensive analysis of your IT infrastructure for security gaps — from network and applications to endpoints. With a detailed action plan.
Anonymized reference caseTax advisory firm · Frankfurt, 28 employees+
Starting point
Client data on outdated servers, no active security monitoring, NIS2 obligations unclear.
Solution & result
A complete IT security audit: network, endpoints, applications and a social engineering test.
19 critical vulnerabilities found and fixed, NIS2 readiness achieved, cyber insurance policy taken out.
Unknown vulnerabilities are the biggest security risk
- Most attacks exploit known, unpatched vulnerabilities — most companies don’t know they are affected
- NIS2 and ISO 27001 require regular security audits — without proof, fines of up to €10 million are possible
- Cyber insurers increasingly require audit evidence — without it, there is no coverage
A systematic audit — find, prioritize and fix vulnerabilities
- A complete analysis of all systems: network, endpoints, cloud, applications and human factors
- CVSS-based risk assessment: you know exactly which gaps are critical and what can wait
- A detailed action plan with responsibilities and schedule — no loose ends
Scope of services
What IT Security Audit does for you
Network Scan
Automated and manual analysis of all network components, open ports and exposed services.
Application Audit
Security review of your web and business applications for known vulnerabilities (OWASP Top 10).
Endpoint Analysis
Review of the security configuration of all endpoints, operating systems and installed software.
Social Engineering Test
Simulated phishing attacks and social engineering tests to assess security awareness.
Vulnerability Report
A detailed report of all vulnerabilities found, with CVSS scores and risk ratings.
Action Plan
A prioritized action plan for fixing all security gaps, with schedule and responsibilities.
Approach
How we work
Scope Definition
Joint definition of the audit scope, objectives and legal authorizations.
Technical Analysis
Automated scans and manual security checks of all agreed systems.
Report & Assessment
Preparation of the audit report with risk assessment and concrete recommendations.
Follow-Up
Review of the implemented measures and an optional retest for verification.
The audit found 19 critical gaps we knew nothing about. Three of them would have given attackers full access to our client data. It was a wake-up call.
Typical Findings
What we find in every second audit
We find these vulnerabilities regularly — even at companies with an active IT department. Most of them have gone undetected for years.
Admin ports exposed to the internet
Network
Unpatched operating systems
Endpoints
Default passwords on devices
Passwords
Missing SPF/DKIM/DMARC records
Public storage buckets
Cloud
Outdated web applications
Application

Our Methodology
Systematic. Complete. Documented.
Our audit process is based on OWASP, NIST, and ISO 27001 — with proven effectiveness.
Reconnaissance
OSINT analysis, footprinting of all external systems, DNS enumeration, Shodan check — exactly how an attacker would proceed.
Vulnerability Scanning
Automated scans with Nessus, OpenVAS, and proprietary tools. OWASP Top 10 for web applications. CVE database matching.
Manual Analysis
Experienced security experts manually check what scanners miss: logic errors, misconfigured permissions, business logic flaws.
Report & Handover
CVSS-scored report: management summary plus a detailed technical section. Closing meeting with a prioritized action plan.
Your Results
Two reports — for two audiences
Management and the IT team have different needs. You get both: a clear risk assessment for management and technical details for your IT team.
Free initial consultation- Executive summary in plain language — for managing directors and insurers
- Detailed technical report with a CVSS score for every vulnerability
- Prioritized action plan: Critical → High → Medium → Low
- Timeline and responsibilities for all measures
- Compliance evidence for NIS2, ISO 27001, and cyber insurance
- Free retest after 60–90 days for verification
Frequently asked questions
Everything you need to know about IT Security Audit at a glance.
01How much does an IT security audit cost?+
An audit for SMEs with 10–50 employees starts at a fixed price of €3,500. For larger infrastructures (50–200 employees), expect €8,000–20,000. After a free initial consultation, you receive a binding quote.
02How long does an IT security audit take?+
The active testing phase takes 3–10 days, depending on scope. Allow 4 weeks from kick-off to final report. Operations continue normally during the audit — no downtime.
03What exactly is tested?+
The standard scope covers all network components, firewalls, servers, endpoints, cloud services and web applications. On request, we add social engineering tests (simulated phishing attacks) and physical security checks.
04Does the audit meet NIS2 and ISO 27001 requirements?+
Yes. Our audit process is fully ISO 27001-compliant. The final report is recognized as NIS2 evidence and by cyber insurers. You receive a signed audit log.
05What happens after the audit?+
You receive a prioritized action plan. Optionally, we support you in fixing all vulnerabilities and carry out a free retest after 60–90 days to verify implementation.
06Do the tests disrupt ongoing operations?+
No. Automated scans run outside production hours. All tests are configured so that no service goes down. We have never caused a business interruption in any audit.
Free assessment workshop — no obligation
In 60 minutes, we analyze your current situation and show you exactly which solution makes sense for your business — with a binding quote within 5 business days.