Pillar 01 ยท Audit

Cyber Security Audit

A cyber security audit, sometimes called an IT security audit, answers one question: Where do we stand?

This isn't where the policy document says you stand, or where you stood when the last IT provider signed off. It determines where you stand today, across the systems you run, the controls you rely on, the software you have accumulated and the people who use all of it.

Fourarmed audits are fixed-price, delivered on site from our Bristol office, and written up for two audiences at once. They include a board summary anyone can read in ten minutes, and the technical details your IT team needs to act on.

If you want something lighter to begin with, a cyber risk assessment is a shorter form of the same cyber security assessment work.

Scope
Systems, controls, software and people
Delivery
One day on site for most businesses, from our Bristol office
Price
Fixed, agreed in writing before work starts
Reported to
Board and IT, in two documents
Includes
Business interruption assessment
Afterwards
You own the report. No obligation, no drip-feed.

One figure, agreed up front.

Hourly billing gives a security firm an incentive to keep looking and a client an incentive to stop them, which is exactly the wrong dynamic.

What Our Cyber Security Audit Covers

Four areas

Our cyber security analysis looks at four areas, because these four areas determine what happens to you in an incident.

Systems

Your network, servers, endpoints, cloud services and how they connect. What is exposed to the internet, what is segmented from what, how remote access works, and what happens to your data when a machine is lost or a service goes down. Backups get particular attention, including the question that catches most organisations out: when did anyone last restore from them, rather than simply write to them?

Controls

The rules and processes governing your day-to-day security. Access rights and who reviews them, administrator accounts and how they are separated from ordinary use, patching regimes and how quickly critical fixes are applied, and multi-factor authentication and where it is genuinely enforced as opposed to simply switched on somewhere. Also the joiner, mover and leaver process, which is where live accounts belonging to people who left years ago tend to come to light.

Software

What you are running, which versions, and what has quietly reached the end of support. Most organisations have more software than they think and less visibility of it than they would like. Unsupported line-of-business applications are a common finding and rarely a comfortable one, because they usually cannot simply be switched off.

People

Awareness levels, reporting culture, and how staff actually behave when the policy is not in front of them. Whether someone who clicks a bad link knows to tell you, and whether they would feel safe doing so, matters more than most technical controls. See cyber security training for the follow-on to this.

The government's 2025/26 Cyber Security Breaches Survey put phishing at the top of the attack list, affecting 38% of all UK businesses in the previous year, well ahead of every other vector. This is a finding about people and processes at least as much as technology, and it is why we do not run a purely technical audit.

Beyond Cyber Essentials: The Insurer Standard

Our strongest differentiator

Cyber Essentials is a good scheme and we certify plenty of clients through it. It is a defined baseline of five technical controls, assessed at a point in time. It was never designed to tell you whether your business would survive a serious incident, and it does not.

Insurers ask a broader set of questions, and they ask them for a reason. They pay out when things go wrong, so they have built a working picture of what separates a bad week from an existential one.

Fourarmed came out of Castlemead, an insurance broker, and it is not a line for the website. It is why we ask this second set of questions as a matter of course. Our recommendations are written to hold up to an underwriter as well as an auditor. The practical effect for you is that fixing what we find tends to improve both your security and your insurability at the same time. There is more about this on our cyber insurance page.

The second set of questions

  • Whether your backups are genuinely isolated from your production network, and whether anyone has tested a restore
  • How long you could operate if your primary systems were unavailable, and what that would cost per day
  • Whether administrator access is properly separated, and how many people hold it
  • Whether you could provide evidence of your controls after the fact, which is where a lot of claims run into difficulty
  • What your dependency on key suppliers and platforms looks like

What You Get

Every audit, the same core deliverables

A board-level summary

Short and in plain English. Where you stand, the three or four things that matter most, and what addressing them involves. Written so a non-technical director can read it before a meeting and ask sensible questions based on it.

The full audit report

Findings, evidence and specific remediation steps for whoever runs your systems. A detailed document, structured so your IT team or provider can work straight from it.

A prioritised action plan

Ordered by risk reduced per pound spent instead of by severity label, with quick wins separated from the things that need planning and budget.

A business interruption assessment

What downtime would actually cost you, per day and per week. See the section below.

Insurer-aligned recommendations

Flagged separately, so you know which items to raise at renewal.

A walkthrough

We sit down with you and your board and go through the findings. In our experience, this is what turns a report into a set of decisions.

Business Interruption Assessment

The part most audits leave out

This is the part most audits leave out, and it is often the part that changes the conversation.

Technical findings tell you what could go wrong, while a business interruption assessment tells you what it would cost. We work through your critical processes and ask what happens if each one stops, for a day and for a week, what the revenue impact looks like, what your recovery would involve, and how long it would realistically take.

There is a large difference between telling a board "we should probably improve our backups" and telling them what a week of downtime would cost.

The output is usually uncomfortable and always useful. The second version gets the budget approved. It is also the figure your insurer is already estimating, whether or not you have ever calculated it.

How It Works

Six stages
  1. Scoping call

    A conversation about your business, your systems and what has prompted the audit. It is usually 30 to 45 minutes. We establish what is in scope and what is not.

  2. Fixed quote

    We send a written scope and a single price. Nothing starts until you have agreed to both.

  3. On-site day

    One of our team travels from our Bristol office and spends a day with you. We review systems, look at configurations, and talk to the people who use them, which tells us more than any amount of documentation.

  4. Analysis and write-up

    We assemble the findings, test them against what insurers expect, and produce the report, board summary and action plan.

  5. Walkthrough

    We present the findings to you and, if you want, to your board. You get the chance to challenge anything and to ask what we would do first in your position.

  6. Afterwards

    You own the report and can act on it however you like. If you want help, whether that is remediation support, certification, training or ongoing monitoring, we are here. There is no obligation and no drip-feed.

Who We Audit

Three recurring situations

The defence supply chain

Suppliers in the aerospace, defence and advanced engineering supply chain, where a failed security review from the MOD or a prime can cost a contract. Castlemead's ADS Group membership means we understand how those requirements cascade down a chain.

Small and medium businesses

Businesses with no in-house security team, who want an honest picture and a plan they can afford to act on. A good share of them come to us through brokers, because their client's cover needs to hold up if it is ever tested. See cyber security for SMEs.

Businesses preparing for certification

Finding the gaps here is considerably cheaper than finding them during a formal Cyber Essentials Plus assessment.

Pricing

Fixed, and why

Every Fourarmed audit is quoted as a single fixed price, agreed upon in writing before any work begins.

The figure reflects the scope we set together: number of sites, systems, users and how complex your environment is. It does not change even if we find more than expected. Finding more than expected is the job.

We price this way deliberately. Hourly billing gives a security firm an incentive to keep looking and a client an incentive to stop them, which is exactly the wrong dynamic. A fixed price means we scope honestly at the start and then get on with the job.

Common questions

Five questions
How long does a cyber security audit take?
For most businesses the on-site work is one day, followed by analysis and write-up, then a walkthrough of the findings. Larger or multi-site organisations are scoped and quoted individually.
How much does a cyber security audit cost?
Every audit is quoted as a single fixed price, agreed in writing before any work begins. The figure reflects the scope we set together: number of sites, systems, users and how complex your environment is. It does not change even if we find more than expected.
How often should we audit?
Annually is the usual rhythm, or after a significant change such as a new application, a cloud migration, an office move or a merger. Between audits, monitoring keeps the picture current.
Will an audit help with our cyber insurance?
Yes. We flag insurer-aligned recommendations separately so you know which items to raise at renewal, and the business interruption assessment gives you a defensible figure for how much cover you actually need.
Do we need technical staff to understand the report?
No. Every audit comes with a board-level summary in plain English that a non-technical director can read in ten minutes, alongside the full technical report for whoever runs your systems.
Book your audit

Not confident in the answers you are giving?

If you are being asked security questions by clients or insurers and you are not confident in the answers, an audit is the fastest way to change that. We will scope it on a call and put a fixed price in writing.