Cyber security audits.
Know where you stand.

Understand the systems your business depends on, the weaknesses that matter and what to improve first. Dragon AI delivers evidence-led cyber security reviews with a written scope and a practical route to remediation.

Discuss a security review
  • Evidence-backed findings
  • Prioritised improvements
  • Recovery and continuity

Security includes the things you rely on every day.

An administrator account, a booking platform, a payment integration or a supplier holding your data can all be critical to normal operation. A useful review follows those dependencies and the consequences of losing control of them.

Our audit brings together agreed configuration evidence, application behaviour, access arrangements and recovery plans. Findings are separated from evidence gaps and unverified concerns. You receive a clear explanation of the issue, its business impact and what would demonstrate that it has been resolved.

Review the connections that matter to your business.

Accounts, access and email

Review administrator roles, account recovery, joiners and leavers, multi-factor authentication and email/domain controls within the agreed scope.

Applications and cloud systems

Examine relevant permissions, configurations, source code or dependencies, and how sensitive actions are protected. Confirm the evidence needed for each finding.

Data, payments and suppliers

Map important information flows and the people or providers who can change them. Review access, operational ownership and the dependency on third parties.

Backups and continuity

Look beyond the existence of a backup to restore evidence, recovery ownership, emergency access and what happens if a critical supplier becomes unavailable.

Turn an unclear dependency into an actionable plan.

The starting point

A business relies on an externally managed platform. It is unclear who can administer it, whether a usable data export exists or what the team would do during a prolonged outage.

A better way forward

The review identifies the confirmed access arrangements, unanswered supplier questions and available recovery evidence. A prioritised plan gives each next action an owner and a way to verify completion.

  1. 1

    Map the dependency

    Identify critical records, privileged roles and the consequences of disruption.

  2. 2

    Inspect the evidence

    Review authorised access, configuration and recovery information.

  3. 3

    Agree the improvements

    Separate immediate fixes from supplier questions and longer-term changes.

An illustrative engagement. We agree the actual scope, access and success measures with your business.

Something useful.
Yours to put to work.

The engagement has a clear scope and a tangible handover. We agree the deliverables before work starts.

Discuss the scope

How we work with you.

  1. Agree the boundary

    Name the systems, evidence, access, authorised checks and stop conditions in writing.

  2. Inspect

    Gather the approved evidence and review it in the context of your operation.

  3. Validate and prioritise

    Check findings safely, identify gaps and agree the most useful order of action.

  4. Improve and retest

    Support agreed remediation and distinguish a proposed fix from a verified result.

A few things
you might be wondering.

Questions about your own setup?
Let’s talk it through

Is a cyber security audit the same as a penetration test?

No. An audit can cover access, configuration, applications, suppliers and recovery as well as technical weaknesses. Controlled penetration testing requires explicit rules of engagement. If you need an accredited test or a particular certification, we clarify that requirement and the appropriate specialist route.

Will you test our live systems?

Any active testing is agreed explicitly in writing before it happens. We begin with scoped evidence gathering and review. Named systems, test accounts, suitable test data, emergency contacts and stop conditions govern any authorised validation.

What access will you need?

It depends on the questions the audit must answer. The review may use public information, selected configuration evidence, representative roles and source-code access where appropriate. We request the least access needed for the agreed work and keep secrets out of the final report.

Can you help fix the findings?

Yes. Configuration, development or process improvements can be scoped alongside the remediation plan. We keep identified, implemented, deployed and retested as separate states, so the report does not imply a risk has been resolved before the evidence supports that conclusion.

Does the audit certify that we are secure?

No audit can guarantee that a business will never be compromised, and this service is not presented as certification. It provides a scoped view of evidence, risks and improvements at a point in time. Changes to systems and suppliers may create a need for further review.

How is the audit priced?

We agree the critical services, systems, user roles, evidence and testing boundaries first. The depth of review and access available determine the effort. The proposal makes the audit, remediation support and any retesting distinct so you can decide what to commission.

A little clarity before the next step.

Start with the systems you can’t work without.

Tell us what you’re working on. We’ll help you find a practical next step.

Discuss a security review