Cybersecurity audits

A cybersecurity audit for a fixed fee, against a written scope.

You receive a written report, a findings register with owners and dates, and a debrief with the consultant who did the work. The scope and the fee are put in writing after we have seen your environment, and nothing starts until you have approved them.

Built for South African-regulated sectors - finance, legal, and healthcare. Senior consultants run the audit.

Speak to the consultant
What you receive

What you hold when the audit is done

The product of an audit is a set of documents with dates on them. These are the ones you keep.

The written scope

A high-level scope and a fixed-fee quote, written after a discovery meeting in which we establish which systems are in scope. Nothing starts until you have approved it.

The report

An executive summary and the technical detail behind it, in one written document.

The findings register

Every finding is entered with an owner and a date. A findings register with owners and dates is the part you can put in front of an insurer, a client or a regulator.

The debrief

A live session with the consultant who ran the assessment.

The remediation roadmap

A prioritised plan for closing the findings.

The fee

How the fee works

The audit is a fixed fee against a written scope. There is no figure on this page, because the fee depends on the size of the firm, the resources involved and the technology in scope, and we will not estimate those before a discovery meeting. You receive the scope and the quote together, in writing, after that meeting.

The fixed fee covers the audit and the non-blocking findings. The 30-minute consult that comes first is free.

The limit

What an audit will not do

An audit will not stop a determined attacker. It tells you what they would find.

The audit is one pass. What it leaves you with is a dated record of where the firm stood and a register of what has to change, each item with a name against it.

After the audit

We do not hand over a list and leave

Findings go into the register, and your people are engaged to implement them with the resources you allocate. Blocking findings become remediation projects, with Rhentech as the responsible party.

Managed IT follows for firms that want the environment kept in that state.

Scope of work

What the scope can cover

An audit can examine any of the areas below. The written scope states which of them apply to your environment.

Network security assessment

Firewall rules, network segmentation, VPN configuration, and external exposure analysis.

Vulnerability scanning

Automated and manual scanning of internal and external systems for known vulnerabilities.

Penetration testing

Ethical hacking to validate the real-world exploitability of discovered vulnerabilities.

Identity & access review

Privilege analysis, MFA coverage, and Active Directory / Entra ID configuration.

Compliance gap analysis

ISO 27001, CIS Controls, and sector-specific regulatory requirements.

Security policies review

Documentation, acceptable use, incident response, and business continuity plans.

Endpoint security audit

EDR coverage, patch levels, encryption status, and device management posture.

Cloud configuration review

Azure, AWS, and Microsoft 365 security settings, data residency, and access controls.

Phishing resilience test

Simulated phishing campaigns and staff awareness benchmarking.

AI-attack readiness

Where your existing controls handle AI-augmented threats (deepfake BEC, prompt injection of agent integrations, autonomous vuln-scanning) - and where they don't.

Sibling engagement

The AI Usage Audit is a separate engagement

The Cybersecurity Audit covers AI-attack readiness in your existing controls. The AI Usage Audit goes deeper on what AI tools your employees are using and the data flowing through them.

Who it's for

Written for the person who signs the answer

The reader we have in mind is the MD, CFO or partner of a regulated firm who has been sent a renewal form, a client's security schedule or a due-diligence list, and has to sign what goes back.

Regulators and standards in view
FSCAInformation RegulatorPOPIAJoint Standard 2 of 2024
Financial services & fintech
Legal & professional services
Healthcare & life sciences
Accountancy & audit firms
Insurance
Regulated manufacturing
Who runs the audit
Senior consultants

The consultant who scopes the audit is the consultant who does it and delivers the debrief. There is no junior hand-off.

The form on the contact page goes to the consultant, not to a sales team.

Process

How an audit works

Seven steps, in this order. There is no scope and no figure before the discovery meeting.

01

The 30-minute consult

Free, with no obligation, with the consultant who would do the work. The call covers what you have been asked to evidence, and what an audit would and would not evidence against it.

02

Discovery meeting

We establish which systems are in scope.

03

Written scope and quote

A high-level written scope and a fixed-fee quote, based on your environment. You approve before we begin.

04

Technical assessment

Remote and on-site testing across the agreed scope. Typical duration: five to ten business days.

05

Analysis and validation

Findings are validated, de-duplicated, and risk-scored against your business context.

06

Report, register and debrief

The written report, the findings register with owners and dates, and a live debrief with the consultant who ran the assessment.

07

Remediation

Your people implement the findings in the register with the resources you allocate. Blocking findings become remediation projects with Rhentech as the responsible party.

Common questions

What clients ask before an audit.

What does a cybersecurity audit cost?

The audit is a fixed fee against a written scope. We do not publish a figure, because the fee depends on the size of the firm, the resources involved and the technology in scope. The written scope and the quote follow a discovery meeting in which we establish which systems are in scope. The 30-minute consult before that is free.

What do we receive at the end?

A written report with an executive summary and the technical detail, a findings register with owners and dates, a live debrief with the consultant who ran the assessment, and a prioritised remediation roadmap.

What can the audit cover?

The written scope is drawn from ten areas: network security assessment, vulnerability scanning, penetration testing, identity and access review, compliance gap analysis, security policies review, endpoint security, cloud configuration review, phishing resilience testing, and AI-attack readiness. Which of them apply depends on your environment and is settled at the discovery meeting.

How long does a cybersecurity audit take?

The technical assessment typically runs five to ten business days, carried out remotely and on site across the agreed scope. It follows the discovery meeting and your approval of the written scope.

Who performs the audit?

A senior consultant. The consultant who scopes the audit is the consultant who does it and delivers the debrief, so there is no junior hand-off. There is no sales team, and the contact form goes to the consultant.

Which regulatory frameworks does the audit take into account?

The compliance gap analysis is written with FSCA, Information Regulator, POPIA, Joint Standard 2 of 2024 in view, alongside ISO 27001 and sector-specific regulatory requirements. Audits are built for regulated sectors including financial services, legal, healthcare, accountancy, insurance, and regulated manufacturing.

What happens after the report is delivered?

Findings go into the register, and your people are engaged to implement them with the resources you allocate. The fixed fee covers the audit and the non-blocking findings. Blocking findings become remediation projects with Rhentech as the responsible party, and managed IT follows for firms that want it. We do not hand over a list and leave.

Free 30-minute consult

Start with thirty minutes and
whatever has arrived on your desk.

The consult is free and carries no obligation. A senior consultant replies within one business day.

Speak to the consultant