Audit & Consulting

An audit tells you what to fix, and what to leave alone

A KARIGUARD audit isn’t another report to file. It’s something you can act on: a straight diagnosis, recommendations in priority order, and a clear line between your infrastructure, what the business needs and what the rules require.

Our audits

4 audits, one purpose: decisions you can defend

Network audit

Architecture, topology, redundancy, security and performance. We map what you have, show you where it stands, and set out a target design with projects and budget figures.

Cybersecurity audit

Technical and organisational, following ISO 19011: documentation, technical review (architecture, configurations, vulnerability testing, logs), how you’re organised (governance, incidents, awareness), and the legal side (GDPR, NIS 2, ISO 27001).

Configuration audit

Firewalls, switches, access points, segmentation. We check the rules, the firmware, the config backups and the known vulnerabilities.

Virtual CISO

A security lead on a part-time basis, to manage your strategy, your compliance and your risk — without a full-time hire. Read more.

How it runs

3 phases, and a report you can act on

We audit independently, before any integration project, with a consultant certified ISO/IEC 27001 Auditor.
Audit findings presented to an IT leadership team Presented to the board
  1. 1

    Exploration

    We talk to your IT team, walk the site, and gather what already exists: diagrams, inventory, policies.

  2. 2

    Diagnosis

    We analyse the architecture and the configurations, test for vulnerabilities, weigh up the compliance risk and check it all against what you actually need.

  3. 3

    Findings and what next

    A full report with a maturity score, the gaps and what to improve; an action plan in priority order; a target architecture and costed projects — presented to your leadership team.

What you get

4 things you walk away with

Visibility

A clear view of your network and IT risks, backed by evidence.

Compliance

Where you stand against good practice and the frameworks: ISO, GDPR, NIS 2.

Decisions

Security or modernisation projects, prioritised and costed.

Readiness

A head start on ISO 27001 certification or an external audit.

Virtual CISO

A security lead, without the headcount

Not everyone can justify a full-time security lead. So we give you one part time, or for a specific piece of work.

Delivered with TAVITA Cybersécurité, specialists in security governance, compliance and crisis management across the French overseas territories.

  • Security strategy that lines up with your objectives
  • Regulatory compliance: GDPR, NIS 2, ISO 27001, sector frameworks
  • Risk analysis and management, with action plans
  • Writing and maintaining security policies
  • Staff awareness and training
  • Oversight of security incidents, and crisis management when it counts

Request an audit

Firewall, network architecture or cybersecurity — tell us the scope and we’ll come back with a proposal.

Or call us: 0596 09 09 38