Somebody is going to find your gaps. It should be us, on a schedule, with a written plan attached.
A cybersecurity audit is a structured assessment of your technical controls, written policies, and incident-readiness against a recognized framework, typically HIPAA, SOC 2, NYDFS Part 500, NIST CSF, CMMC, ISO 27001, or PCI DSS. GR IT Services runs independent audits with evidence-pack deliverables your auditor or regulator will accept.

- 100+Audits delivered
- 5Frameworks covered
- 30 daysAudit-to-report
- IndependentNo conflict of interest
Six disciplines, scoped to your environment.
Security audit
A configuration review across identity, network, endpoints, cloud, and data, mapped against whichever framework you answer to. What you get back is a gap register with a severity and an effort estimate on every line.
Penetration testing
Perimeter, internal network, web applications, wireless, and social engineering. You choose how much we start with: nothing, partial knowledge, or full documentation. Methodology follows NIST SP 800-115 and the Penetration Testing Execution Standard.
Compliance gap analysis
Mapped against SOC 2, HIPAA, PCI DSS, NIST CSF, CMMC or ISO 27001, whichever applies to you. You receive an assessment of where you stand, a gap register, and a roadmap to the target state with effort and budget attached.
Vulnerability management
Scanning that runs continuously, findings ranked by real risk, patching coordinated with whoever owns the systems, and a remediation report each month. Available as an ongoing service once the initial audit is done.
Threat hunting & incident review
Looking back through historical telemetry for something that has been sitting in the environment quietly. Live incident response is available as a separate engagement when the hunt finds one.
Policy & procedure
Information security policy, acceptable use, incident response, and business continuity, written around how your company actually operates rather than pulled from a template. Ready for an auditor to read and a board to approve.
Six frameworks we have shipped end-to-end.
Six frameworks, in detail.
ISO 27001
A full management system assessed against the Annex A control set. We have carried clients all the way to a certificate rather than stopping at a gap analysis and calling it a program.
- ISMS scope and risk assessment review
- Annex A control implementation and operating effectiveness
- Statement of Applicability (SoA) review and rationale
- Internal audit program and management review evidence
- Corrective action and continual improvement records
- Coordination with your chosen certification body from start to finish
NIST CSF
The NIST Cybersecurity Framework 2.0, organized around Govern, Identify, Protect, Detect, Respond and Recover. Widely referenced by federal agencies, cyber insurers and enterprise customers as the common language for describing a security program.
- Function and category mapping across all six CSF 2.0 functions
- Compliance level assessment and gap report
- Implementation tier assessment, from Partial through to Adaptive
- Evidence pack built for insurers, customers and regulators
- Continuous monitoring controls review
- Annual surveillance and re-attestation support
State Privacy Laws
State privacy laws, starting with the CCPA and CPRA in California and extending to Colorado, Virginia, Connecticut, Utah and a growing list. Different statutes, largely overlapping operational obligations.
- Personal information inventory and data mapping
- Consumer rights workflow: access, deletion, correction, opt-out
- Sale and sharing disclosures, plus universal opt-out signal handling
- Sensitive personal information handling and limits
- Service provider and contractor contract terms review
- State breach notification readiness against each applicable clock
PCI DSS
The card industry standard, applying to anyone who processes, stores, or transmits cardholder data. All four merchant levels, scoped against how many transactions you actually run in a year.
- Cardholder data environment (CDE) scoping and segmentation
- Twelve PCI DSS requirement areas and 300+ controls
- Network segmentation review and ASV scanning
- Tokenization and encryption-at-rest review
- Internal vulnerability scanning and quarterly external scans
- SAQ or RoC preparation with QSA coordination
HIPAA
HIPAA mapping for covered entities and business associates, covering the Security Rule safeguards, the Privacy Rule, and the Breach Notification Rule with its sixty-day clock.
- Protected Health Information (PHI) data-flow mapping
- Privacy Rule control assessment
- Security Rule administrative, physical, and technical safeguards
- Business Associate Agreement (BAA) inventory and review
- Breach notification readiness and response
- Workforce training and policy attestation evidence
SOC 2
SOC 2 Type 1 and Type 2 readiness for software and technology companies selling into large enterprises. Trust Services Criteria across security, availability, and confidentiality, with the evidence to demonstrate each one operated over the observation period.
- Trust Services Criteria scoping (security, availability, confidentiality)
- Control design effectiveness (Type 1) review
- Control operating effectiveness (Type 2) over the audit period
- Subservice organization and complementary user controls
- Evidence-collection automation and continuous monitoring
- CPA firm coordination through to attestation
Four reasons clients pick us for the audit.
Frameworks we have shipped
SOC 2, HIPAA, PCI DSS, NIST CSF, ISO 27001 and CMMC. We have taken clients all the way through certification rather than stopping at a gap report.
Independent of vendors
There is no security stack we are quietly trying to sell you. A finding names the gap, never the product that happens to fix it. You buy what the environment needs rather than what sits in our catalog.
Reports your board reads
An executive summary, the technical detail behind it, a remediation roadmap, and budget guidance. It arrives in two layers: five pages a board can read and a full evidence appendix your engineers can work from.
Certified team
Our engineers hold CISSP, CEH, CISM, and ISO 27001 Lead Auditor. The people who will actually run your engagement are named in the statement of work, so nobody substitutes a junior subcontractor after signature.
Five phases, one written deliverable trail.
- 01Phase 1· 1 week
Scoping & Planning
Scope, objectives, and methodology all agreed, with the rules of engagement signed before anybody touches anything.
- Initial consultation and stakeholder map
- A scope statement naming what is included and, just as importantly, what is not
- Compliance requirements review
- Audit plan with resource allocation
- Timeline and milestone calendar
- 02Phase 2· 1-2 weeks
Information Gathering
Gathering documentation, interviewing the people who run things, and building an accurate picture of the controls as they exist today.
- Document collection (policies, procedures, runbooks)
- Architecture analysis and data-flow diagrams
- Stakeholder interviews and control owners identified
- Asset inventory aligned to audit scope
- Control identification mapped to framework
- 03Phase 3· 2-3 weeks
Assessment & Testing
Running the security testing, the vulnerability scanning, and the control-by-control evaluation against your chosen framework.
- Vulnerability scanning across in-scope assets
- Penetration testing aligned to NIST SP 800-115 and PTES
- Control effectiveness testing with evidence capture
- Configuration review and policy compliance check
- Access control and security monitoring review
- 04Phase 4· 1 week
Analysis & Reporting
Analyze findings, prioritize risk, and prepare the executive and technical reports.
- Finding analysis with CVSS scoring
- Risk assessment and gap register
- Executive summary (board-ready)
- Technical appendix with full evidence chain
- Remediation recommendations on a 90/180/365 day plan
- 05Phase 5· Ongoing
Remediation Support
Supporting your team while they implement, re-testing what they closed, and handing the whole thing into continuous monitoring.
- Remediation planning and effort estimation
- Implementation guidance for control owners
- Progress tracking against the roadmap
- Re-testing of fixed findings
- Continuous monitoring handover
Audit profiles by sector.
Financial services
SEC-reporting firms, NYDFS Part 500 covered entities, regulated lenders under GLBA and the FTC Safeguards Rule, and insurance brokers. SOC 2 and PCI DSS where cardholder data is in scope, plus whatever your specific examiner expects.
Healthcare & clinics
HIPAA-regulated healthcare facilities (hospitals, clinics, dental practices). PHI handling, patient-data DLP, HIPAA controls evidenced end to end, NIST CSF where applicable.
Retail & e-commerce
Card-present, card-not-present, and everything in between. PCI DSS scoping across all four merchant levels, advice on tokenization, a segmentation review to keep the scope small, and approved scanning.
Professional services
Law firms, accounting practices, and consultancies. Confidentiality controls, document management security, diligence support during a transaction, and state privacy obligations wherever your clients live.
Education
Schools, universities, and training providers. FERPA obligations around student records, integrity of testing systems, parental consent handling, and the vendor management that educational technology demands.
Critical infrastructure
Logistics, utilities, large hospitality. NIST CSF framework alignment, OT/IT segmentation, business continuity, incident response readiness.
Eight assessment areas, grouped by domain.
Technical Controls
- Network SecurityFirewall rules, segmentation, intrusion detection
- Application SecurityWeb app vulnerabilities, code security, API security
- Data ProtectionEncryption, classification, backup and recovery
- Access ControlsUser permissions, authentication, authorization
Operational Controls
- Incident ResponseProcedures, response plans, communication paths
- Security PoliciesDocumentation, awareness training, enforcement
- Third-Party RiskVendor assessments, supply-chain risks
- Physical SecurityData-center access, environmental controls
Why the audit needs to be independent.
| Feature | In-house attestation Your IT team | Independent audit External, evidenced |
|---|---|---|
Conflict of interest Reviewing your own team work creates a quiet pressure to phrase things gently. | Yes (structural) | No |
Acceptable for ISO 27001 audit | ||
Acceptable for board sign-off | Limited | Yes |
Penetration testing depth You cannot pen-test what you built. | Self-blind spots | Independent perspective |
Framework certification readiness | ||
Regulatory submissions | Often rejected | Accepted |
Cost | Internal time only | Custom quote per engagement |
Ten engagement shapes by audit type and sector.
Internal Security Audit
Reviewing access control, checking practice against policy, assessing the internal network, and examining how user activity is monitored.
External Security Audit
Scanning the perimeter, testing web applications, reviewing DNS security, and assessing how well your mail is defended.
Application Security Audit
Reading the source, testing against the OWASP Top 10, assessing the APIs, and probing how authentication actually behaves.
Cloud Security Audit
Reviewing cloud configuration, assessing identity and access policy, checking how storage is secured, and examining the services running on top.
Banking & Finance
PCI DSS, SOC 2, GLBA and the FTC Safeguards Rule, with NYDFS Part 500 where it applies. Protect financial data and satisfy an examiner who reads carefully.
Healthcare & Medical
HIPAA safeguards, protection of patient records, and security for connected medical devices. Keep protected health information out of the breach portal.
Government & Public Sector
NIST CSF, NIST 800-171, CMMC and FedRAMP where relevant. Meet the expectations that come with federal contracts and the data they carry.
Retail & E-commerce
PCI DSS alongside the state privacy statutes covering your customers. Secure the payment path and everything you hold about the people using it.
Education
Student-data protection with FERPA obligations evidenced properly. Protect student records and exam systems.
Technology Companies
SOC 2, ISO 27001, and product security. Answer the enterprise security questionnaire before it stalls the deal.
What an audit program delivers, in numbers.
Critical and high findings closed inside the ninety-day remediation window.
ISO 27001, GDPR, NIST CSF, PCI DSS, HIPAA, SOC 2 covered end-to-end.
An active compromise or exposed data reaches you within hours, never at report delivery.
CISSP, CEH, CISM and ISO 27001 Lead Auditor across every named engagement team.
A roadmap at ninety, one hundred and eighty, and three hundred and sixty five days, with effort and budget attached.
Post-certification surveillance and continuous control attestation.
From scoping call to remediation roadmap.
- 1
Scoping
1 week
A discovery call, a scope document, a confidentiality agreement, a statement of work, and a signed engagement letter. Rules of engagement are written out for any testing. Nothing begins until both sides have signed.
- 2
Fieldwork
2-4 weeks
Testing runs remotely, and on site where the scope genuinely requires it. Evidence gets captured, configurations reviewed, controls tested individually. During a penetration test you hear from us daily. During an audit, weekly.
- 3
Reporting
1-2 weeks
An executive summary, the technical findings, an evidence appendix, and the remediation roadmap. Everything goes through internal review before it reaches you, and we walk your stakeholders through it live rather than emailing a document.
- 4
Re-test
Within 60 days
Your team fixes things. We re-test what they fixed and close each finding in writing. Anything still open moves to the next quarterly review or sits in your risk register with an owner and a target date against it.
Cybersecurity audit & compliance, frequently asked.
Resources for security and compliance leads.
IT AMC
Ongoing baseline security folded into a fixed annual contract: endpoint protection, patching, enforced multi-factor, and threat detection.
Managed IT Services
Complete operational ownership with security operations included: monitoring at any hour, endpoint detection, penetration testing each quarter, and security advisory at leadership level.
Book a security audit
Tell us your industry, which framework you are aiming at, and where you stand today. We scope it and come back with a program at a fixed fee against a fixed timeline.
Book a scoping call.
Three minutes of typing. The security team replies the same working day to book half an hour of scoping. No obligation and no retainer that starts billing itself.
Related Services
Explore more solutions that work great with this service