Security audit
Know exactly where your business is exposed
Penetration testing, configurations, email, access and backups: we test your information system the way an attacker would, then hand you a clear action plan.
- Penetration testing
- Executive report
- Prioritized action plan
A team on watch
At the first sign, our engineers take action
Attacks now target businesses of every size, with booby-trapped emails that look perfectly genuine. Our engineers monitor your domains, your email, your workstations and your servers around the clock, and respond to every alert with method.
A domain imitating yours has just been registered to deceive your customers.
We spot it the moment it is registered, alert you and start the takedown process with the registry and the hosting provider.
An employee entered their password on a fake login page.
We close their sessions, renew their credentials and check that no forwarding rule has been set up on their mailbox.
A laptop has been lost or stolen.
Its access is revoked and its data wiped remotely; its encrypted drive stays unreadable.
A critical vulnerability is published for software you use.
We identify the workstations and servers affected, deploy the patch as a priority and report back to you.
What we audit
Your entire information system, thoroughly examined
Penetration testing
We attack your websites, your applications and your remote access using attackers' methods, within a framework agreed with you.
Exposed surface
Domains, subdomains, internet-facing services and certificates: everything an attacker can see of you, inventoried.
Domain authentication, filtering, forwarding rules and phishing resilience, checked one by one.
Accounts and access
Passwords, two-factor authentication, privileged accounts and contractor access, reviewed in detail.
Workstations and servers
Patches, encryption, antivirus, configurations and outdated software, recorded on every machine.
Backup and recovery
We verify that your data truly restores, and how long it takes.
Human factor
A simulated phishing campaign and interviews, to measure your teams' reflexes.
Compliance
Your practices measured against data protection requirements and the standards of your sector.
How the audit unfolds
Three steps, a report that reads clearly
-
Scoping
Together we define the scope, the schedule and the rules of engagement for the penetration test.
-
Investigation
Our engineers analyze, test and document every weakness, with proof of how it can be exploited.
-
Findings
You receive an executive summary, a detailed technical report and an action plan ranked by priority, presented to your teams.
Our cybersecurity services
Three services, one team
Managed cybersecurity
Continuous monitoring, authenticated email, lookalike domain watch and incident response.
Explore managed cybersecuritySecurity audit
Penetration testing and a full review of your information system, with a prioritized action plan.
You are hereIT fleet management
Workstations, servers, phones and an encrypted private network, managed and secured by our engineers.
Explore IT fleet managementFrequently asked questions
Your questions about the security audit
How long does a security audit take?
From a few days to a few weeks, depending on the scope. The schedule is set during scoping, and tests are planned to keep your business running smoothly.
How does the penetration test fit around our operations?
Tests take place within a written framework, at times agreed with you. The most sensitive trials are run outside production hours or on a staging environment.
What does the audit report contain?
An executive summary that ranks risks by severity; a technical report that describes each weakness, its proof and its fix; and a dated action plan.
Can you fix the vulnerabilities you find?
Yes. Our engineers carry out the action plan, then run a follow-up audit to confirm that every weakness is fixed. Protection then continues with our managed cybersecurity.
Is our information kept confidential?
Yes. The audit is covered by a confidentiality agreement signed before the first test, and the material collected is encrypted, then destroyed at the end of the engagement.
How is the audit priced?
On a quote basis, according to the scope defined during scoping: websites, applications, workstations, servers and interviews.
Let's talk about your company's security
Tell us about your business and your IT: we will propose the assessment, audit or managed service that suits you.