Information Security Audits

We measure your true level of compliance, map controls to NIS2, ISO 27001 and DORA, identify the critical risks and give you a prioritised action plan — with owners and deadlines.

What we assess

Types of audits and assessments

From a quick diagnosis (gap assessment) to framework-based audits — we pick exactly what you need to be ready.

GDPR gap assessment

Where you stand against GDPR requirements — processes, documentation, internal practices and your relationship with suppliers.

NIS2 compliance audit

Applicability, minimum security measures, governance and your incident reporting capability.

ISO 27001 audit

A review of the 93 controls and the Statement of Applicability (SoA), ahead of certification or surveillance.

ICT risk assessment

Identifying, evaluating and prioritising risks, with a treatment plan and recommended controls.

DPIA, LIA & TIA

Impact assessments for high-risk processing, legitimate interests analysis and transfer impact assessments.

Testing & verification

We check whether the measures actually work in practice, not just on paper — and we document the evidence.

Our process

How an audit unfolds

1

Scope & context

We set the objective of the audit, the relevant frameworks and the perimeter.

2

Evidence gathering

Documents, interviews, configurations and data flows.

3

Analysis & mapping

We map controls to frameworks and identify non-conformities.

4

Report & plan

A clear report with prioritised risks, owners and deadlines.

5

Remediation

We support you in closing the gaps, step by step.

6

Re-assessment

We check progress and keep the evidence in the askGDPR platform.

What you get

A report you can actually use

Not a document that gathers dust — but a concrete roadmap to compliance.

Request an audit
Let's talk

Start with a clear assessment

Find out where you stand and what you need to do — with no surprises at your next inspection.