CREST-ACCREDITED UK PROVIDER

Cyber Security Audit Services

A cyber security audit reviews the controls protecting your systems and data, then tells you which gaps to close first. EJN Labs runs them UK-wide as a fixed-price engagement, with a named CREST-certified consultant and three reports you can take to your IT team, your board and the people who ask you for evidence.

  • Free retest of every fix
  • Fixed price agreed up front
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori

AUDIT SCOPE

What the audit covers

An audit answers one question: if someone tried to get in today, what would actually stop them?

Accounts and access

Privilege levels, and whether multi-factor authentication is actually enforced rather than merely available.

Patching

Supported software, and how quickly fixes reach the machines that matter.

Backups

Not just that backups run, but whether a restore has ever been tested.

Network

Firewalls, and the segregation between parts of the estate that should not reach each other.

Remote and third party

Remote access routes, and the connections you have given suppliers and MSPs.

Devices

Endpoint configuration and malware protection on the machines people work on.

Mapped to your framework
CIS BenchmarksNCSC 10 StepsISO 27001 Annex AUK GDPR

We map the controls above to whichever framework your assessor, auditor or underwriter uses. The monitoring and incident response parts of those frameworks sit outside an audit.

WHAT YOU GET

Three reports, written for three different readers

The same audit, reported three ways, so nobody has to translate it for the next person.

Management report

Written for a board or an audit committee. What the risk is in business terms, what it would cost you, and what we recommend you fund first.

Technical report

Written for your IT team or MSP. Each finding names the control it fails, the evidence we saw and what “fixed” looks like, ordered by what reduces risk fastest rather than by scanner severity.

Public report

The sanitised version, cleared for sharing with clients, insurers and procurement teams who ask you to prove an independent review happened.

Once you have worked through the fixes we retest them free of charge.

CYBER ESSENTIALS

Cyber Essentials readiness: where you stand before you certify

The audit doubles as a gap check against the five technical controls the scheme is built on.

How the audit shortens the route

We review the five controls an assessor marks your answers against: firewalls, secure configuration, user access control, malware protection and security update management. You get the gaps in writing before anything is submitted. The five controls are set out in the NCSC’s Cyber Essentials overview.

We assess and issue in house

EJN Labs is a licensed IASME certification body for Cyber Essentials and Cyber Essentials Plus, so the same team can assess and issue your certificate rather than handing it to another firm. Certification is quoted separately from the audit, and the IASME scheme fee sits inside that published certification price, never billed on top.

This is the audit finding the gaps, not the certification itself. Cyber Essentials certification

COST AND FIT

What it costs, and when you need a test as well

How it is priced

Our CREST-certified consultants are priced at a fair-market £1,100 to £1,400 per day. We do not bill day rates: an audit is quoted as one scope-based fixed price, agreed before work starts, so the price you agree is the price you pay. See the full price list.

How long it takes

Audits we run are usually a matter of days rather than weeks. The exact number depends on how many sites, systems and user groups are in scope, and we agree it with you before you commit.

Start with an audit

Start here if you have never had an independent review, or if you need evidence on the controls above for a cyber insurance questionnaire, an ISO 27001 or SOC 2 auditor, or a board paper.

Step up to a test

An audit reviews your controls; a penetration test attempts to defeat them the way an attacker would. Step up when you want proof of what an attacker could reach, not confirmation that a control exists.

In our experience most estates need both: an audit across the estate, a penetration test on the systems that would hurt most.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST pen test quote in 24 hours

A fixed-price quote back in one working day, from a named CREST-certified consultant. No sales pipeline, no chasing.

  • CREST-accredited, and licensed by IASME for Cyber Essentials and Cyber Essentials Plus. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £5,000 for a single-role, single-app scope, agreed up front. In our experience most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one working day with a fixed-price quote from a named CREST-certified consultant.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one working day. Your data stays with us. No newsletter signup.

FAQ

Frequently asked questions

What is the difference between a cyber security audit and a penetration test?

An audit reviews whether your controls exist and work as intended, and produces a prioritised list of what to close first. A penetration test attempts to defeat those controls the way an attacker would, and produces proof of what could be reached. An audit answers “are we set up correctly?”; a test answers “would it hold?”

What do we get at the end?

Three reports and a retest. The management report is written for a board or an audit committee, the technical report gives your IT team or MSP the detail and the evidence, and the public report is the sanitised version you can share with clients, insurers and procurement teams. Once you have worked through the fixes we retest them free of charge.

Will the audit get us Cyber Essentials certified?

The audit tells you where you stand against the five controls and what to close. Certification is a separate step, and because EJN Labs is a licensed IASME certification body for Cyber Essentials and Cyber Essentials Plus, the same team can assess and issue the certificate. Cyber Essentials certification is quoted separately from the audit, and the IASME scheme fee sits inside that published certification price.

How much does a cyber security audit cost?

It is priced on scope. Our consultants are priced at a fair-market £1,100 to £1,400 per day, though we do not bill day rates: every audit is quoted as a single fixed price for an agreed scope, so there are no day-rate surprises. See the full price list, or ask for a quote and you will have the number within one working day.

Who carries out the audit?

UK-based, CREST-certified consultants. You get a named consultant at quote stage.

What does the audit not cover?

It reviews controls rather than monitoring them. Logging, alerting and incident response are outside the scope of a cyber security audit. The audit will tell you whether those controls exist and how they are configured, but it does not monitor them for you.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a pen test quote in 24 hours

Tell us what needs testing and a CREST-accredited UK team replies within one working day with a fixed price.