Audit
of IT Security

360° · 8 areas · Report in 2 weeks

How do you know that
Is your IT working
the way you think it is?

Engave's IT Security Audit gives you a hard, factual picture of your infrastructure's condition - no assumptions, no guesswork. A report dozens of pages long, with specific recommendations and an action plan.

Who the
IT security audit is for

An IT audit gets commissioned at different moments. But they all share one thing:
the client needs a hard picture of reality, not wishful thinking or guesswork.

FEAR

You've just found out that a company similar to yours paid a ransom to a hacker

A press article, a conversation with a friend, a question from your insurer. Something raised your concern and you want to know - are we actually secure?

Trigger:  an incident at a competitor, a question about cyber insurance, a ransomware attack in the news

COMPLIANCE

You need to prove that you are consciously managing IT security

NIS2, GDPR, KNF, tender requirements, terms of a contract with a corporate partner. You're looking for a document, not a discovery.

Trigger:  the KSC/NIS2 act, a UODO inspection, a corporate client audit, a tender requirement

COST SAVINGS

The CFO wants to know whether the IT budget is being spent optimally

Audit as a cost optimization tool. Licence inventory, unnecessary resources, spending with no value. On average, we uncover 30% of costs that can be cut.

Trigger:  a review of fixed costs, a change on the board, a new investor coming in, pressure on EBITDA

TRANSACTION

The company is planning a sale, merger, IPO, or entry into a corporate partnership

IT audit as part of due diligence. The board wants to know the state of the infrastructure before it reaches the negotiating table. Contract value is the highest of all segments here.

Trigger:  M&A talks, a new investor, joining a capital group, preparing for a public tender

PUBLIC INSTITUTION

A local government unit, hospital, university or agency ahead of a NIK, UODO inspection or tender

Audit as preparation for an external inspection or as part of tender documentation. KSC and NIS2 requirements make regular security reviews mandatory.

Trigger:  announcement of an inspection, tender requirement, KSC/NIS2 implementation, a new IT director with a mandate to clean things up

CHANGE

You've just changed IT providers or a key IT person has left

A new team or new IT partner wants to know what they're actually taking over. What systems are running, where the passwords are, what's configured correctly, and what just "sort of works" because no one has touched it in years.

Trigger:  offboarding of the company's sole IT person, change of IT provider, merger of two environments, new CTO or IT Manager with a mandate to clean things up

  • FEAR
  • COMPLIANCE
  • COST SAVINGS
  • TRANSACTION
  • PUBLIC INSTITUTION
  • CHANGE

OUR CLIENTS

Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient

What companies discover
during the Engave audit

After completing projects, we see the same patterns again and again. Even when they're alarming, they're normal situations for Polish companies that grew faster than their IT.

security risk

A backup that had "worked" for 14 months - hadn't.

A logistics company. Every month, the IT admin looked at the green icons in the dashboard. No one ever tested an actual restore. After the audit, a restore attempt failed - data from the last 14 months was unrecoverable.

Audit Result: Risk of losing 14 months of data discovered and fixed before an incident occurred

hidden cost

Licences paid for employees who left two years ago

A service company, 45 people. During a Microsoft 365 licence inventory, it turned out there were 63 active subscriptions. The company had 45 employees. The difference: 18 licences on accounts that no longer existed.
Cost: PLN 1,800 a month for nothing.

Audit Result: Discovered savings of PLN 21,600 per year - recoverable from next month onward

security risk

Three active VPN accounts of former employees - including one with a conflict

A manufacturing company. Offboarding stopped at collecting the laptop. VPN accounts, ERP system permissions and remote access to the file server stayed active. In one case, it was an employee who left on bad terms.

Audit Result: Three active external accounts identified and shut down the same day as the report

compliance

No IT procedure documentation whatsoever - the company would not have passed a UODO audit

A healthcare company (special-category GDPR data). When we asked about procedures - backup, access management, incident handling, updates - it turned out there was no written procedure at all. All the knowledge lived in one person's head.

Audit Result: A full set of IT procedures developed by Engave as part of the report - ready for UODO

security risk

A server from 2011. 47 outstanding security updates. Still in production the entire time.

A law firm. The infrastructure "worked". An external IT contractor handled day-to-day matters. The file server was never covered by an update policy because "it always worked". CVEs from 2019-2023 left unpatched.

Audit Result: 47 critical security vulnerabilities found - prioritization and a modernization plan included in the report

hidden cost

Four SaaS subscriptions for the same tools - different departments, no coordination

An e-commerce company, 80 people. Marketing, sales, customer service and IT each used a different project management tool. Four subscriptions, no integration, data scattered across four places.

Audit Result: Consolidation onto a single platform: savings of PLN 3,400/month plus the benefit of integrated data

SCOPE

8 areas. Full picture.
No blind spots.

The audit covers the entire IT infrastructure - from physical security to regulatory compliance. We can also narrow the scope to selected areas or expand it to cover specific applications and systems.

Physical security

Head office & server room

🟡 Server room access control
🟡 Emergency power (UPS)
🟡 Air conditioning and cooling

LAN/WAN Network

Network topology and security

🟡 Topology and VLANs
🟡 Firewall and IDS/IPS
🟡 Link redundancy
🟡 Configuration currency

IT Procedures

Documentation and security policies

🟡 Backup and testing policy
🟡 Access management
🟡 Incident handling
🟡 Update procedures

Server environment

Physical and virtual servers

🟡 System status and currency
🟡 Backup and DR
🟡 Permissions and accounts
🟡 Virtualization (VMware)

Workstations

User computers and devices

🟡 System and patch currency
🟡 Antivirus and EDR
🟡 Disk encryption
🟡 Security configurations

Software licenses

Inventory and optimization

🟡 Full license inventory
🟡 Contract compliance
🟡 Unused subscriptions
🟡 Cost optimization

Mobile devices
and peripherals

Phones, printers, IoT

🟡 MDM and mobile device management
🟡 Printers and scanners
🟡 IoT devices on the network
🟡 BYOD - rules and risks

Regulatory compliance

NIS2, GDPR and sector standards

🟡 NIS2 compliance assessment
🟡 GDPR - data protection
🟡 Sector standards (KNF, KSC)
🟡 UODO audit readiness

The audit doesn't end with the report.
This is just the beginning of the fix

Engave can implement every recommendation from the report.
We don't leave clients alone with a document dozens of pages long and no help putting it into practice.

The natural next step after an audit is Comprehensive IT Care IT or Digital Bunker - depending on what we find and what you expect from us. All of it done with respect for your time and without pushing unnecessary costs on you.

ISO Certificates

ISO certifications are a global standard of excellence, guaranteeing that our company operates effectively, efficiently, and in compliance with regulations.

It's proof that our organization is committed to continuous improvement, taking both quality and customer satisfaction seriously.

WE WORK WITH THE BEST

Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient

Testimonials

What our clients say about us

"Given Engave S.A.'s high level of professionalism, we can wholeheartedly recommend their IT services to other companies. Throughout our cooperation, the company's employees have proven to be top-class, well-organized specialists. The quality of the services provided, along with their understanding of our needs, directly contributed to a significant improvement in our operations."

- HUBIX SP. Z O.O.

"Over the course of eighteen months of cooperation, Engave proved to be a reliable, flexible and results-oriented partner. We had the opportunity to get to know Engave's competencies and working methods over an extended period, both at the process management and operational level. That is why we confidently recommend them as a trustworthy partner for delivering complex organizational and technological projects."

- Medical University of Łódź

"Working with Engave gave us reliable, comprehensive insight into the state of our IT infrastructure. The audit was carried out professionally, and its results were presented in well-substantiated documentation that now serves as our roadmap for further development. Engave is a partner able to translate complex technical issues into the language of business benefits. We recommend their services to any organization for which IT security is a priority."

- ApartHotel Termy Uniejów

"Man Truck BUS Polska Sp. z o.o. commissioned Engave S.A. to supply, deploy, and configure a ManageEngine solution for monitoring networks, servers, and database virtualization across its IT systems, as well as for mobile device management. The scope of the contract was completed and delivered on time and with due diligence."

- MAN TRUCK BUS POLSKA

"The International Institute of Molecular and Cell Biology in Warsaw confirms that Engave supplied and deployed, with due diligence, computer hardware for a shared next-generation DNA sequencing platform. The order was completed on time and properly."

- International Institute of Molecular and Cell Biology

"The Digital Bunker at ZUS is a project that is changing the way public administration thinks about data protection - shifting from reactive response to proactive resilience. In delivering this implementation, Engave S.A. proved that Polish technological expertise can meet the most demanding security standards of public institutions. ZUS confirms the contract was properly performed."

- Zakład Ubezpieczeń Społecznych

"We hereby confirm that Engave S.A. delivered to Fujitsu Technology Solutions spółka z o.o. IT hardware and software licenses along with support. We recommend Engave S.A. as a trusted and proven partner."

- FUJITSU TECHNOLOGY SOLUTIONS

"Engave S.A. provided a service covering the deployment of VMware virtualization software, installation and configuration of the virtualization platform, reconfiguration of the LAN and security layers, installation, configuration and maintenance of the backup environment, repairs to the backup system, deployment of DR mechanisms, and more. All work was carried out with due diligence and with a very high level of commitment from the contractor."

- PGW Wody Polskie and the Institute of Meteorology and Water Management

"The IT Department of Miejskie Zakłady Autobusowe Sp. z o.o. confirms that, as part of the modernization of the central backup system, Engave supplied and deployed a data protection management system. The delivery was carried out in accordance with the contract. The entire scope of the contract was completed with due diligence and within the specified deadline."

- Miejskie Zakłady Autobusowe SP. Z O.O.

"The order carried out by Engave was completed on time, in full, with due diligence, and in compliance with all requirements set out in the contract."

- IT Department of the Capital City of Warsaw

"The service delivered by Engave S.A. was completed on time and with due diligence, with tremendous commitment and professionalism on the part of the contractor. The reliability and accuracy of the valuation and documentation prepared (...) was confirmed by a team of researchers in computer science and economics."

- Narodowy Fundusz Zdrowia

"All work was carried out properly, in accordance with the agreed scope, on time, and with due diligence. We have no reservations about the quality of the services provided."

- ENAMOR SP. Z O.O.

"Engave provided the mounting, installation, and commissioning of the array in a way that enabled full native-mode interoperability with all servers. Tests were carried out confirming the correct operation of the expanded arrays and the correct connection to the client's environment. The upgraded environment was brought back to full functionality as it was before the expansion. All work was carried out correctly and in accordance with the terms of the contract."

- Narodowy Fundusz Zdrowia


360° Audit

Watch the free webinar and find out how much you really know about your company's health

Contact us
with Engave

Cybersecurity, IT care, digitalisation - whatever the topic, we're happy to talk. Describe your need and the right specialist will get back to you within 24 business hours.

CONTACT:

biuro@engave.pl
+22 863 13 90
Technical support: +48 604 470 151
16 Czarodzieja St., 03-116 Warsaw, Poland

The controller of your personal data is Engave S.A., headquartered in Warsaw. Information on data processing principles is available in the Privacy Policy. Consent may be withdrawn at any time, without affecting prior processing, by contacting: biuro@engave.pl