Cybersecurity Auditing

A cybersecurity audit exists to answer one very specific question: how would they get in? And to answer it you have to look in the right place, at the right depth. Reviewing a web application is not the same as reviewing an industrial network or a wireless one.

Choose by what you want to test

Perimeter and systemsPenetration testingWe genuinely exploit the vulnerabilities in your external and internal infrastructure until the real impact is demonstrated.View service →Full adversaryRed Team operationsA specific objective, by any route, also measuring whether your team detects it and how long it takes.View service →Periodic coverageVulnerability assessmentRecurring sweep of your whole surface, manually triaged and prioritised by real exposure.View service →SoftwareApplication and API auditingBusiness logic, authorisation and everything an automated scanner does not find.View service →WirelessWiFi network auditingThe only part of your perimeter that leaves the building, guest network included.View service →Physical accessRFID, NFC and BluetoothThe cards that open your doors and the devices talking over radio inside your premises.View service →AvailabilityStress testingHow much your platform takes, how it breaks and how it recovers.View service →CloudSecure cloud infrastructureIdentities, permissions, exposure and escalation paths inside the provider itself.View service →Plant floorIndustrial cybersecurityOT environments, with a method that does not put production at risk.View service →

What they all have in common

Scope and rules in writing before we start, with windows, contacts and stop criteria.
Manual verification of every relevant finding. No dumping a tool’s output.
Two reports: an executive one for management and a technical one for whoever fixes it.
A walkthrough session with your team, because a report emailed over gets half read.
Retest included for the fixed findings.
A format valid as evidence for ISO 27001, the ENS, DORA, PCI DSS and NIS2.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Which one should I start with?
If you have never audited anything, an external perimeter penetration test and an internal vulnerability assessment. Together they cover around 80% of the real entry routes and produce the map for deciding what comes next.
What does it cost?
It depends on scope, and scope is agreed in a half-hour conversation. After that you get a proposal with a fixed price and duration, not a range.
Does it work for a tender or a vendor assessment?
Yes. We issue reports with the traceability and format that auditors and large clients’ assessment questionnaires ask for.
How often?
A full audit annually, vulnerability assessment quarterly, and a targeted review after any significant architecture change.
Half an hour to decide what to audit
We tell you which type of audit answers the question you have, and which one you do not need yet.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES