Skip to main content
Loyca
Service reference 04Audit & AssuranceACTIVE PRACTICE PROTOCOL

Cybersecurity Audit

Do your controls do what you think they do?

Control-by-control audit of your security programme against ISO 27001, NIST CSF, or sector regulator guidance.

PROTOCOL OVERVIEW

Executive Context & Technical Scope

We test the security controls you have documented and the ones you have not. Each control is assessed for design and operating effectiveness — not just whether a policy exists, but whether it was followed last month. Output maps directly to whichever framework you are being measured against.

TARGET PROFILES

Who Requires This Protocol

Organisations preparing for certification or supervisory review
Companies asked for security assurance by a large customer
Security teams that want an honest baseline

ENGAGEMENT ARTIFACTS

Verifiable Outputs & Deliverables

Control-by-control assessment with maturity scoring

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Evidence pack per control tested

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Gap analysis against the target framework

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Prioritised remediation plan with effort estimates

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

PRACTITIONER FAQ

Frequently Asked Scoping Questions

Is this the same as a penetration test?
No. An audit examines controls and evidence; a penetration test attacks systems. Most organisations need both, and the audit usually tells you where to point the test.
Does a clean audit mean we are secure?
It means your controls worked as designed during the period examined. That is valuable and it is not the same thing.
PRACTICE CONTINUUM

INTELLIGENCE WITHOUT LIMITS

Scope Cybersecurity Audit for your organization.

Get a fixed-scope proposal, verifiable deliverables list, and exact timeline for cybersecurity audit.

Direct Hotline:+254 740 658 068
NO-OBLIGATION GUARANTEE

What to expect in your scoping call

  • Direct Senior Lead

    You talk to a seasoned cybersecurity consultant, never a sales script.

  • Strict Confidentiality

    We operate under mutual NDA before discussing sensitive architecture.

  • Actionable Next Steps

    Immediate priorities and costed options, whether you engage us or not.

Message Loyca on WhatsApp