360° · 8 areas · Report in 2 weeks
Engave's IT Security Audit gives you a hard, factual picture of your infrastructure's condition - no assumptions, no guesswork. A report dozens of pages long, with specific recommendations and an action plan.
FEAR
A press article, a conversation with a friend, a question from your insurer. Something raised your concern and you want to know - are we actually secure?
Trigger: an incident at a competitor, a question about cyber insurance, a ransomware attack in the news
COMPLIANCE
NIS2, GDPR, KNF, tender requirements, terms of a contract with a corporate partner. You're looking for a document, not a discovery.
Trigger: the KSC/NIS2 act, a UODO inspection, a corporate client audit, a tender requirement
COST SAVINGS
Audit as a cost optimization tool. Licence inventory, unnecessary resources, spending with no value. On average, we uncover 30% of costs that can be cut.
Trigger: a review of fixed costs, a change on the board, a new investor coming in, pressure on EBITDA
TRANSACTION
IT audit as part of due diligence. The board wants to know the state of the infrastructure before it reaches the negotiating table. Contract value is the highest of all segments here.
Trigger: M&A talks, a new investor, joining a capital group, preparing for a public tender
PUBLIC INSTITUTION
Audit as preparation for an external inspection or as part of tender documentation. KSC and NIS2 requirements make regular security reviews mandatory.
Trigger: announcement of an inspection, tender requirement, KSC/NIS2 implementation, a new IT director with a mandate to clean things up
CHANGE
A new team or new IT partner wants to know what they're actually taking over. What systems are running, where the passwords are, what's configured correctly, and what just "sort of works" because no one has touched it in years.
Trigger: offboarding of the company's sole IT person, change of IT provider, merger of two environments, new CTO or IT Manager with a mandate to clean things up
After completing projects, we see the same patterns again and again. Even when they're alarming, they're normal situations for Polish companies that grew faster than their IT.
security risk
A logistics company. Every month, the IT admin looked at the green icons in the dashboard. No one ever tested an actual restore. After the audit, a restore attempt failed - data from the last 14 months was unrecoverable.
Audit Result: Risk of losing 14 months of data discovered and fixed before an incident occurred
hidden cost
A service company, 45 people. During a Microsoft 365 licence inventory, it turned out there were 63 active subscriptions. The company had 45 employees. The difference: 18 licences on accounts that no longer existed.
Cost: PLN 1,800 a month for nothing.
Audit Result: Discovered savings of PLN 21,600 per year - recoverable from next month onward
security risk
A manufacturing company. Offboarding stopped at collecting the laptop. VPN accounts, ERP system permissions and remote access to the file server stayed active. In one case, it was an employee who left on bad terms.
Audit Result: Three active external accounts identified and shut down the same day as the report
compliance
A healthcare company (special-category GDPR data). When we asked about procedures - backup, access management, incident handling, updates - it turned out there was no written procedure at all. All the knowledge lived in one person's head.
Audit Result: A full set of IT procedures developed by Engave as part of the report - ready for UODO
security risk
A law firm. The infrastructure "worked". An external IT contractor handled day-to-day matters. The file server was never covered by an update policy because "it always worked". CVEs from 2019-2023 left unpatched.
Audit Result: 47 critical security vulnerabilities found - prioritization and a modernization plan included in the report
hidden cost
An e-commerce company, 80 people. Marketing, sales, customer service and IT each used a different project management tool. Four subscriptions, no integration, data scattered across four places.
Audit Result: Consolidation onto a single platform: savings of PLN 3,400/month plus the benefit of integrated data
SCOPE
The audit covers the entire IT infrastructure - from physical security to regulatory compliance. We can also narrow the scope to selected areas or expand it to cover specific applications and systems.
Head office & server room
🟡 Server room access control
🟡 Emergency power (UPS)
🟡 Air conditioning and cooling
Network topology and security
🟡 Topology and VLANs
🟡 Firewall and IDS/IPS
🟡 Link redundancy
🟡 Configuration currency
Documentation and security policies
🟡 Backup and testing policy
🟡 Access management
🟡 Incident handling
🟡 Update procedures
Physical and virtual servers
🟡 System status and currency
🟡 Backup and DR
🟡 Permissions and accounts
🟡 Virtualization (VMware)
User computers and devices
🟡 System and patch currency
🟡 Antivirus and EDR
🟡 Disk encryption
🟡 Security configurations
Inventory and optimization
🟡 Full license inventory
🟡 Contract compliance
🟡 Unused subscriptions
🟡 Cost optimization
Phones, printers, IoT
🟡 MDM and mobile device management
🟡 Printers and scanners
🟡 IoT devices on the network
🟡 BYOD - rules and risks
NIS2, GDPR and sector standards
🟡 NIS2 compliance assessment
🟡 GDPR - data protection
🟡 Sector standards (KNF, KSC)
🟡 UODO audit readiness
Engave can implement every recommendation from the report.
We don't leave clients alone with a document dozens of pages long and no help putting it into practice.
The natural next step after an audit is Comprehensive IT Care IT or Digital Bunker - depending on what we find and what you expect from us. All of it done with respect for your time and without pushing unnecessary costs on you.
ISO certifications are a global standard of excellence, guaranteeing that our company operates effectively, efficiently, and in compliance with regulations.
It's proof that our organization is committed to continuous improvement, taking both quality and customer satisfaction seriously.
360° Audit
Cybersecurity, IT care, digitalisation - whatever the topic, we're happy to talk. Describe your need and the right specialist will get back to you within 24 business hours.
CONTACT:
biuro@engave.pl
+22 863 13 90
Technical support: +48 604 470 151
16 Czarodzieja St., 03-116 Warsaw, Poland