Cyber Security Audit Services
A cyber security audit reviews the controls protecting your systems and data, then tells you which gaps to close first. EJN Labs runs them UK-wide as a fixed-price engagement, with a named CREST-certified consultant and three reports you can take to your IT team, your board and the people who ask you for evidence.
- Free retest of every fix
- Fixed price agreed up front
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
AUDIT SCOPE
What the audit covers
An audit answers one question: if someone tried to get in today, what would actually stop them?
Privilege levels, and whether multi-factor authentication is actually enforced rather than merely available.
Supported software, and how quickly fixes reach the machines that matter.
Not just that backups run, but whether a restore has ever been tested.
Firewalls, and the segregation between parts of the estate that should not reach each other.
Remote access routes, and the connections you have given suppliers and MSPs.
Endpoint configuration and malware protection on the machines people work on.
We map the controls above to whichever framework your assessor, auditor or underwriter uses. The monitoring and incident response parts of those frameworks sit outside an audit.
WHAT YOU GET
Three reports, written for three different readers
The same audit, reported three ways, so nobody has to translate it for the next person.
Written for a board or an audit committee. What the risk is in business terms, what it would cost you, and what we recommend you fund first.
Written for your IT team or MSP. Each finding names the control it fails, the evidence we saw and what “fixed” looks like, ordered by what reduces risk fastest rather than by scanner severity.
The sanitised version, cleared for sharing with clients, insurers and procurement teams who ask you to prove an independent review happened.
Once you have worked through the fixes we retest them free of charge.
CYBER ESSENTIALS
Cyber Essentials readiness: where you stand before you certify
The audit doubles as a gap check against the five technical controls the scheme is built on.
We review the five controls an assessor marks your answers against: firewalls, secure configuration, user access control, malware protection and security update management. You get the gaps in writing before anything is submitted. The five controls are set out in the NCSC’s Cyber Essentials overview.
EJN Labs is a licensed IASME certification body for Cyber Essentials and Cyber Essentials Plus, so the same team can assess and issue your certificate rather than handing it to another firm. Certification is quoted separately from the audit, and the IASME scheme fee sits inside that published certification price, never billed on top.
This is the audit finding the gaps, not the certification itself. Cyber Essentials certification
COST AND FIT
What it costs, and when you need a test as well
Our CREST-certified consultants are priced at a fair-market £1,100 to £1,400 per day. We do not bill day rates: an audit is quoted as one scope-based fixed price, agreed before work starts, so the price you agree is the price you pay. See the full price list.
Audits we run are usually a matter of days rather than weeks. The exact number depends on how many sites, systems and user groups are in scope, and we agree it with you before you commit.
Start here if you have never had an independent review, or if you need evidence on the controls above for a cyber insurance questionnaire, an ISO 27001 or SOC 2 auditor, or a board paper.
An audit reviews your controls; a penetration test attempts to defeat them the way an attacker would. Step up when you want proof of what an attacker could reach, not confirmation that a control exists.
In our experience most estates need both: an audit across the estate, a penetration test on the systems that would hurt most.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST pen test quote in 24 hours
A fixed-price quote back in one working day, from a named CREST-certified consultant. No sales pipeline, no chasing.
- CREST-accredited, and licensed by IASME for Cyber Essentials and Cyber Essentials Plus. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £5,000 for a single-role, single-app scope, agreed up front. In our experience most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one working day with a fixed-price quote from a named CREST-certified consultant.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one working day with your fixed-price quote from a named CREST-certified consultant.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one working day. Your data stays with us. No newsletter signup.
BY SECTOR
Sectors we test
Law firms
Client files and case systems.
Law firms sector pageHealthcare
Patient data and clinical systems.
Healthcare sector pageFintech
Payment flows and FCA-regulated estates.
Fintech sector pageSaaS
Multi-tenant platforms and customer APIs.
SaaS sector pagePublic sector
Testing evidence procurement teams accept.
Public sector pageInsurance
Policyholder data and underwriting platforms.
Insurance sector pageWe deliver on-site or remotely UK-wide; for the capital, see penetration testing London, or browse all sectors.
FAQ
Frequently asked questions
What is the difference between a cyber security audit and a penetration test?
An audit reviews whether your controls exist and work as intended, and produces a prioritised list of what to close first. A penetration test attempts to defeat those controls the way an attacker would, and produces proof of what could be reached. An audit answers “are we set up correctly?”; a test answers “would it hold?”
What do we get at the end?
Three reports and a retest. The management report is written for a board or an audit committee, the technical report gives your IT team or MSP the detail and the evidence, and the public report is the sanitised version you can share with clients, insurers and procurement teams. Once you have worked through the fixes we retest them free of charge.
Will the audit get us Cyber Essentials certified?
The audit tells you where you stand against the five controls and what to close. Certification is a separate step, and because EJN Labs is a licensed IASME certification body for Cyber Essentials and Cyber Essentials Plus, the same team can assess and issue the certificate. Cyber Essentials certification is quoted separately from the audit, and the IASME scheme fee sits inside that published certification price.
How much does a cyber security audit cost?
It is priced on scope. Our consultants are priced at a fair-market £1,100 to £1,400 per day, though we do not bill day rates: every audit is quoted as a single fixed price for an agreed scope, so there are no day-rate surprises. See the full price list, or ask for a quote and you will have the number within one working day.
Who carries out the audit?
UK-based, CREST-certified consultants. You get a named consultant at quote stage.
What does the audit not cover?
It reviews controls rather than monitoring them. Logging, alerting and incident response are outside the scope of a cyber security audit. The audit will tell you whether those controls exist and how they are configured, but it does not monitor them for you.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a pen test quote in 24 hours
Tell us what needs testing and a CREST-accredited UK team replies within one working day with a fixed price.



