Accounts, access and email
Review administrator roles, account recovery, joiners and leavers, multi-factor authentication and email/domain controls within the agreed scope.
Understand the systems your business depends on, the weaknesses that matter and what to improve first. Dragon AI delivers evidence-led cyber security reviews with a written scope and a practical route to remediation.
Discuss a security reviewAn administrator account, a booking platform, a payment integration or a supplier holding your data can all be critical to normal operation. A useful review follows those dependencies and the consequences of losing control of them.
Our audit brings together agreed configuration evidence, application behaviour, access arrangements and recovery plans. Findings are separated from evidence gaps and unverified concerns. You receive a clear explanation of the issue, its business impact and what would demonstrate that it has been resolved.
Review administrator roles, account recovery, joiners and leavers, multi-factor authentication and email/domain controls within the agreed scope.
Examine relevant permissions, configurations, source code or dependencies, and how sensitive actions are protected. Confirm the evidence needed for each finding.
Map important information flows and the people or providers who can change them. Review access, operational ownership and the dependency on third parties.
Look beyond the existence of a backup to restore evidence, recovery ownership, emergency access and what happens if a critical supplier becomes unavailable.
A business relies on an externally managed platform. It is unclear who can administer it, whether a usable data export exists or what the team would do during a prolonged outage.
The review identifies the confirmed access arrangements, unanswered supplier questions and available recovery evidence. A prioritised plan gives each next action an owner and a way to verify completion.
Identify critical records, privileged roles and the consequences of disruption.
Review authorised access, configuration and recovery information.
Separate immediate fixes from supplier questions and longer-term changes.
An illustrative engagement. We agree the actual scope, access and success measures with your business.
The engagement has a clear scope and a tangible handover. We agree the deliverables before work starts.
Discuss the scopeThe important findings and decisions explained in terms of business operations and recovery.
Affected systems, observed evidence, impact and the distinction between confirmed findings and unresolved questions.
The people, accounts and suppliers able to affect critical data, configuration or continuity.
Recommended actions, owners and an agreed order based on impact and practical constraints.
A walkthrough for leadership and implementers, plus the evidence needed before findings can be closed.
Name the systems, evidence, access, authorised checks and stop conditions in writing.
Gather the approved evidence and review it in the context of your operation.
Check findings safely, identify gaps and agree the most useful order of action.
Support agreed remediation and distinguish a proposed fix from a verified result.
Questions about your own setup?
Let’s talk it through
No. An audit can cover access, configuration, applications, suppliers and recovery as well as technical weaknesses. Controlled penetration testing requires explicit rules of engagement. If you need an accredited test or a particular certification, we clarify that requirement and the appropriate specialist route.
Any active testing is agreed explicitly in writing before it happens. We begin with scoped evidence gathering and review. Named systems, test accounts, suitable test data, emergency contacts and stop conditions govern any authorised validation.
It depends on the questions the audit must answer. The review may use public information, selected configuration evidence, representative roles and source-code access where appropriate. We request the least access needed for the agreed work and keep secrets out of the final report.
Yes. Configuration, development or process improvements can be scoped alongside the remediation plan. We keep identified, implemented, deployed and retested as separate states, so the report does not imply a risk has been resolved before the evidence supports that conclusion.
No audit can guarantee that a business will never be compromised, and this service is not presented as certification. It provides a scoped view of evidence, risks and improvements at a point in time. Changes to systems and suppliers may create a need for further review.
We agree the critical services, systems, user roles, evidence and testing boundaries first. The depth of review and access available determine the effort. The proposal makes the audit, remediation support and any retesting distinct so you can decide what to commission.
Tell us what you’re working on. We’ll help you find a practical next step.
Discuss a security review