BUILD · Security Audit

Know exactly where your security stands.

We score the controls that matter, then rank what to fix before a customer, insurer, or incident forces the issue.

Security baseline

Sample scope

73

foundational controls

8

security domains

01Cloud and network
02Identity and access
03Data and secrets
04Logging and response
05Backup and resilience
06Security governance
07Third-party and SaaS
08AI governance

Framework mapping

ISO 27001 + NIST CSF

Rating band

Critical to Foundational

Is this for you?

Quick read before you invest 30 minutes.

When this works

  • Sensitive data affects trust and revenue

    You handle customer or sensitive data, and a breach or failed security review would directly affect the business.

  • An external requirement is getting closer

    A customer questionnaire, insurer, SOC 2 goal, or ISO 27001 goal is pushing security up the list.

  • You need a baseline before a security hire

    You are roughly 10-250 people with real exposure, but no full in-house security function yet.

When it is not the right call

  • You need a penetration test or active exploitation. This is a controls and configuration baseline.

  • You already have a mature in-house security function and a formal audit program.

  • You need a compliance certificate issued now. This prepares you for a certifying audit, but it is not the certification itself.

Everything in the $500 audit

A security score

See your overall rating and domain-by-domain position across about 73 foundational controls in eight security areas.

A plain-English report

Understand what is working, where the gaps are, and what each finding means without translating security jargon.

A prioritized action list

Get every finding ranked by priority and effort so your team or IT provider can start with the right fixes.

A shareable summary

Use a one-page summary with customers, your board, or your insurer when they ask how security is managed.

Two support calls

Walk through the report and implementation questions with us. Your IT provider can join, and calls remain available for three months.

Evidence, priorities, and a clear next move

A usable baseline for the people who need answers and the people who will fix the gaps.

$500

one fixed fee

73

foundational controls

8

security domains

2-4 wks

from start to report

A clear rating from Critical through Foundational

A fix list ranked by risk and implementation effort

A one-page summary for customers, boards, and insurers

Evidence handled under a mutual NDA and deleted when the work ends

One path from uncertainty to action.

See the full path before the work starts. Each stage stays focused, predictable, and lightweight for your team.

  1. Prepare

    Set a clean baseline

    We agree the boundaries before you share evidence, so the review stays focused and predictable.

    • Intro call

      We understand the business, the trigger, and what the audit will and will not cover.

    • Agreement and NDA

      Scope, fee, timeline, evidence access, and deletion terms are agreed in writing.

    • Short questionnaire

      You outline the company, customers, systems, and obligations so the review fits your reality.

    ISO 27001NIST CSF
  2. Review

    Turn evidence into a score

    The review maps practical controls to recognized frameworks without turning the work into a certification exercise.

    • Tailored audit

      Questions draw from ISO 27001 and the NIST Cybersecurity Framework, translated into plain English.

    • Domain-by-domain assessment

      We examine the evidence across eight security areas and identify gaps that need attention.

    • Report and score

      Every finding is explained, rated, and ranked by priority and implementation effort.

    ISO 27001NIST CSF
  3. Act

    Move from findings to fixes

    You leave with a practical order of operations, not a report that sits unread in a shared drive.

    • Prioritized action list

      Your team can separate quick wins from deeper remediation and start with the highest-risk gaps.

    • Shareable summary

      Use a one-page view with customers, your board, or your insurer when security questions arrive.

    • Two support calls

      Your team or IT provider can work through recommendations with us for up to three months.

    ISO 27001NIST CSF

Common gaps in a first baseline.

Each example shows why a control that looks present may still leave the business exposed.

  1. MFA is not enforced everywhere

    A few privileged platforms still rely on a password alone, leaving the most valuable accounts with weaker protection.

  2. Secrets are stored in source control

    Credentials or API keys can remain in Git history even after the visible file is changed or deleted.

  3. Audit logging is incomplete

    Cloud or workspace events are not retained consistently enough to investigate suspicious activity with confidence.

  4. Backups have never been restored

    A backup is only dependable after the team has confirmed that the data can be recovered within an acceptable timeframe.

  5. Incident ownership is unclear

    There is no written contact and escalation path for the first hours after a suspected security event.

Engagement

Start with one fixed-price audit.

Add remediation only if you want it. Nothing renews automatically.

Full baseline

The Security Audit

$500

one fixed fee

Baseline and report

  • Tailored review across about 73 controls
  • Overall score and rating by domain
  • Plain-English report and shareable summary

Action and support

  • Fix list ranked by priority and effort
  • Two support calls within three months
  • Mutual NDA and evidence deletion

2-4 weeks, about 10 hours from your team

Book a free intro call

Quoted separately

Remediation and hardening

Hands-on help to fix specific findings with your IT provider, plus optional hardening or a later re-audit.

Book a free intro call

Tailored scope

Custom plan

For larger organizations, multiple entities, deeper control coverage, or a specific compliance-readiness target.

Book a free intro call

Frequently asked

Is this a penetration test?

No. It is a controls and configuration baseline mapped to ISO 27001 and the NIST Cybersecurity Framework. Nothing on your systems is tested or touched without written approval. If you need a pentest, we can point you in the right direction.

Why does the price seem low?

This is a deliberately accessible, productized baseline with a fixed scope. The goal is to give you a real score and a fix list without an enterprise consulting invoice. Deeper remediation and hardening are quoted separately.

What access do you need?

We start with a questionnaire and evidence you choose to share. Any requested access is read-only where possible, agreed in writing, covered by the NDA, and removed when the engagement ends.

Will this get us SOC 2 or ISO 27001 certified?

Not on its own. Certification is a separate formal audit. This review maps the gaps and priorities so you can approach a certifier or customer questionnaire with fewer surprises.

How much of our time does it take?

Plan for about 10 hours in total, mostly for the questionnaire and evidence gathering, spread across one or two weeks. The two support calls are included.

What happens after the report?

The engagement ends. Nothing renews automatically. You can implement the fixes internally or ask us to quote remediation, extra support, or a later re-audit.

See where you stand before someone else asks.

Get a scored baseline and ranked fix list for $500 and about 10 hours of your team's time.