Home / Services / Security audit & reporting

Security audit & reporting

Security audit & reporting evidence UK reviewers keep.

Two documents, one re-test, optional letter of attestation. Mapped to OWASP, ISO 27001 and NCSC CAF outcomes — without claiming a certification we do not hold.

Working the findings into something a director and a developer can both use.
Working the findings into something a director and a developer can both use.

Coverage

What we will not put on the PDF

Executive summary

Risk in English. Severity mix. What to tell the board this month versus next quarter.

BoardRisk

Technical volume

Each finding: CVSS v3.1, affected asset, steps, evidence, fix, references.

CVSSPoC

Control mapping

OWASP, ISO/IEC 27001 Annex A, NCSC CAF objectives — applied where they are honest, omitted where they are not.

CAFISO 27001

Re-test & attestation

Free verification of confirmed issues. Optional letter stating independent VAPT was performed, with dates and scope.

Re-testAttestation

No CREST logo. No fake CHECK number. If a tender requires CREST or NCSC CHECK, say so on the scoping call and we will tell you we are not the supplier.

Ready to scope a UK engagement?

A thirty-minute call. Assets, timeline, a quote in pounds sterling.

Request a quote