Service

Cybersecurity audit

An audit is an independent, structured assessment of how far your organisation meets the requirements that apply to it, from regulatory obligations to voluntary norms and standards. We check the actual state, identify gaps and show what to do to close them. We work in an advisory capacity, independent of vendors. Our auditors hold the certificates required to carry out a KSC audit, listed in the relevant register, and we provide the specific certificates of individual people on request.

Does KSC apply to you?

A belief has grown up around KSC that small organisations are beyond the reach of the new obligations. That is a myth. Company size is not an automatic exemption.

The competent authority for cybersecurity may, by decision, recognise an entity as key or important regardless of its size, if its role or the services it provides are of significant importance. This means even a small organisation may be brought under KSC obligations directly.

Obligations can also reach you through the supply chain. A key or important entity that is your client is obliged to manage the security of its suppliers, so security requirements will flow down to you through contracts and procurement processes, even if you do not appear on any register yourself.

If you are not sure whether it applies to you, it is better to check than to be caught out. A preparatory audit answers that question before a regulator or client answers it for you.

  • Sector and role

    You operate in an area covered by the regulation or perform a function important to how it operates.

  • Authority decision

    The competent authority may recognise your entity as key or important regardless of company size, if your role is of significant importance.

  • Supply chain

    Requirements may flow down to you from a client that is a key or important entity, even if you are not directly subject to the regulation.

Types of audit we carry out

Regulatory audits

  • Statutory audit

    Assessment of compliance with the requirements of NIS2 and its Polish implementation (KSC), for entities that it applies to. Carried out by auditors holding the certificates required by law.

  • Preparatory audit

    Checking compliance with the requirements of NIS2 and KSC even if you are not formally subject to them or are not sure. It lets you understand your own situation and prepare before an obligation becomes a problem.

Voluntary audits, against norms and standards

  • Compliance audit against ISO/IEC 27001 and ISO 22301

    Assessment of how far your management system meets the requirements of recognised international standards, in the area of information security (ISO/IEC 27001) and business continuity (ISO 22301). This is an assessment audit that identifies gaps, not a certification audit. 

  • Compliance audit against a standard

    Assessment against a chosen security standard, matched to your organisation and sector. We select the standard to fit what you actually need, or what your client or market requires of you.

For an audit against ISO standards, we prepare the organisation for certification but do not carry it out ourselves. A certificate can only be issued by an accredited certification body, which we are not.

For a compliance audit against a standard, we work with, among others, recognised frameworks and norms, chosen to fit the organisation's context. We use CIS Controls and NIST, widely used sets of safeguards and good practices that any organisation may adopt voluntarily. For industrial environments, automation and medical devices, we draw on IEC 62443, an international security standard for such systems.

A separate case is HIPAA, the US requirements for protecting health data. In Europe it is sometimes applied voluntarily as a recognised benchmark, similar to NIST, particularly by healthcare organisations with exposure to the US market, for example in research, R&D, laboratories or medtech. If your organisation applies HIPAA to data subject to US jurisdiction, we assess compliance with its requirements and set them against the obligations arising from NIS2, showing where they overlap and where gaps remain to be closed.

Healthcare, moreover, is not only hospitals and clinics but also laboratories, research and R&D units, manufacturers of medical devices and technology, and suppliers of services to the sector. Each of these entities operates in a different regulatory environment and requires a different choice of standards, which we take into account when setting the scope of the audit.

How we work

We run the audit in a structured, predictable way, so as to place as little burden on your team as possible. The process runs in four stages:

  1. Step 1: Scope and context

    We establish which requirements apply to you and exactly what we are assessing.

  2. Step 2: Gathering information

    Review of documentation, conversations with responsible people and verification of the actual state.

  3. Step 3: Assessment and gap analysis

    We compare the actual state against the requirements and identify discrepancies.

  4. Step 4: Report and recommendations

    We deliver findings and recommendations and discuss them with you, so the conclusions are clear and actionable.

What you receive

The audit results in concrete documents and findings that you can work with further. We do not leave you with just a list of shortcomings, we show the way to close them.

  • Audit report

    A description of the state of compliance and findings, with specific conclusions.

  • Gap analysis

    Identification of discrepancies against the requirements that need to be addressed.

  • Roadmap

    Priorities and sequencing of actions, matched to your scale and resources.

Related services

An audit is a starting point. It is naturally followed by building the team's competence and ensuring ongoing security oversight.