Security & Compliance Auditing
An audit is only worth having if it produces proof. We assess applications, infrastructure, access and processes against an agreed standard — data protection law, ISO/IEC 27001, OWASP ASVS or your own internal policy — and deliver findings with collected evidence, justified severity and a named remediation owner. Once fixes land we retest and issue a closure report you can put in front of your board, your regulator or a client auditing you.
What you receive
Concrete deliverables, defined before work starts and reviewed at handover.
- Technical audit of applications, infrastructure and cloud configuration
- Review of access, privileges, segregation of duties and audit logging
- Compliance assessment against data protection law, GDPR, ISO/IEC 27001 and OWASP ASVS
- Data processing audit: inventory, lawful basis, retention and transfers
- Report with evidence, severity, business risk and a prioritised remediation plan
- Post-fix retest and closure report
- Support for certification readiness and third-party audits
Typical stack
- ISO/IEC 27001
- OWASP ASVS
- OWASP Top 10
- CIS Benchmarks
- NIST CSF
- GDPR
Engagement models
- One-off audit
- Annual audit
- Compliance retainer
Services often combined with this
Custom Software Development
Bespoke platforms built around how your organisation actually works, not around a vendor's roadmap.
Web Development
Fast, accessible, SEO-ready web applications and corporate platforms built on modern React.
Mobile Apps
Native-quality Android and iOS applications, including offline-first field tools for low-connectivity environments.
Cloud & DevOps
Cloud architecture, containerisation, CI/CD and observability — with the cost model designed in.
Start with security & compliance auditing
Send us the context and constraints. We will come back with scope, an estimate and the risks we can see from here.
Or email walter.mussagy@gmail.com — we reply within one business day.
