Cybersecurity verification

Independent cybersecurity audits for Toronto businesses.

actually. examines the evidence behind your cybersecurity controls and reports findings to business leadership. We agree what to check, assess what the evidence supports and identify the questions that remain. Your IT team or provider continues to operate the systems and carry out changes.

Editorial illustration of a small yellow figure at the centre of concentric rings, casting a shadow across every ring
Every layer, checked from the inside.

What does an independent cybersecurity audit examine?

Cybersecurity verification is an independent check of whether the security controls a business believes it has are actually present, correctly configured, monitored and governed. It is carried out by a firm that does not sell or manage those controls. Findings explain what the evidence supports within the agreed scope and period, and what remains unverified.

The distinction that matters

Bought, deployed, configured, verified.

An invoice, an installation and a configuration each tell you something different. An audit examines what those records establish.

01

Bought

The tool appears on the invoice and in the provider's stack diagram. That is a purchase, not a protection.

02

Deployed

The tool is installed, but coverage may be partial: the exceptions, the service accounts and the executives are often the gaps.

03

Configured

Settings describe how a control is intended to work. Changes, exceptions and actual use still need to be examined.

04

Verified

An independent examination establishes what the evidence supports, for a defined scope and period, and records what remains unverified.

What we verify

The controls a business actually depends on.

The agreed scope may cover the areas below. We examine their configuration, coverage, monitoring and governance, and report findings and limitations. These are controls we audit, not IT operations we take over.

Multi-factor authentication
Privileged access
Endpoint protection
Email security
Conditional access
Vulnerability and patch management
Security monitoring
Incident response
Cybersecurity policies
Security awareness
Third-party access
Insurance readiness
Data protection
Employee onboarding and offboarding
The outcome

A prioritized view of cybersecurity risk written for business leadership, not only for technical teams.

Cybersecurity is one part of a wider picture. More on technology as a concentrated business risk.

Evidence and its limits

What we examine, and what it can tell us.

These examples show how we frame a check. The engagement defines the actual systems, accounts, period and validation in scope.

Identity and access

Evidence to examine
Account inventories, access policies, exceptions and selected sign-in or offboarding records.
The audit question
Do the records and agreed checks support the reported access controls for the accounts in scope?
What remains to be established
A policy document alone does not establish enforcement. An account sample does not establish coverage of every account.

Backup and recovery

Evidence to examine
Backup coverage, job reports, restoration records and the business's agreed recovery requirements.
The audit question
What has been restored and checked, and how does that evidence relate to the recovery requirement?
What remains to be established
Successful backup jobs alone do not establish recoverability. One restoration does not validate every recovery scenario.

Provider follow-through

Evidence to examine
The agreed scope, reported actions, selected tickets and records of the checks used to close them.
The audit question
Does the evidence support the work reported as complete, and which commitments remain unresolved?
What remains to be established
A closed ticket records a status. It does not, by itself, establish that the underlying issue was resolved.

How the audit works

How our cybersecurity audit works.

01

Agree the scope

Identify the business question, systems, period, criteria and access. Record any exclusions before the examination.

02

Examine and validate

Review records, discuss the controls with the responsible people and carry out the agreed sampling or validation.

03

Report the findings

Explain what was examined, what the evidence supports, what remains uncertain and which actions leadership should prioritize.

04

Verify follow-up

Your team or provider implements changes. A follow-up engagement can examine the evidence that an identified finding has been addressed.

You receive a plain-language assessment with findings, business implications and prioritized recommendations. See an illustrative audit finding, including the evidence limits and follow-up question.

The questions we answer

Questions that benefit from an independent check.

Is multi-factor authentication actually enforced on every account, including the exceptions?
Have the backups been restored, not just reported as successful?
Were former employees fully removed, everywhere?
Is anyone actually reading the security alerts?
Are systems actually patched, or only scheduled to be?
Does the evidence support the control statements on your cyber-insurance application?

We do not sell security tools and we take no vendor commissions, so we have no stake in the answer. That is what makes the answer worth having. More on what independence means here.

Choose the right examination

What this engagement covers.

Independent control verification

We examine controls and their supporting evidence within an agreed scope. Findings give leadership a basis for decisions and a discussion with the responsible provider.

Specialist testing

Penetration testing is not included in a standard review. Where it is appropriate, we can help define the scope, coordinate a qualified independent specialist and interpret the findings.

Framework-specific work

A standard review does not issue a SOC 2 report or ISO certification. If a regulator, customer or contract requires a particular examination, establish that requirement before agreeing the engagement.

For insurance questions, we examine the evidence behind control statements. We do not determine coverage or claim outcomes. The cyber-insurance questionnaire guide explains where to start.

Before the engagement

Scope, access, cost and timing.

Start with the decision leadership needs to make. We agree what the audit will examine before the work begins.

What access will you need?

We agree access before the engagement begins. The starting point may be interviews, reports, contracts and documentation. Verification may also require read-only or supervised access to selected systems and configurations. The scope identifies what we can examine and what remains outside the review.

How much does an independent audit cost?

The fee is quoted before work begins. It depends on the agreed scope, the size and complexity of the environment, and the evidence and validation required. Tell us the question you need answered so we can explain what the work would involve.

How long will the work take?

Timing depends on scope, the availability of evidence and the interviews or validation required. We discuss those requirements when scoping the engagement. A focused control review and a review of the wider technology environment require different amounts of work.

What happens to our existing IT provider?

Your provider or internal team continues to operate your systems and carry out changes. actually. examines the evidence, reports findings and can verify remediation. An audit can inform a decision to retain or change a provider; we do not take over IT delivery.

Read more about what determines an independent IT audit's cost, or discuss the question you need examined.

Before commissioning anything, you can ask for the evidence yourself. Ten questions to ask your IT provider is a free checklist covering backups, access, patching and alerting, with evidence to request and questions to follow up.

Find out what is actually protecting you.

An independent verification of the controls your business depends on, reported in language leadership can act on.