Information security audit
We review your network, Wi-Fi, access rights, and workstations using open-source tools, and show where data can leak — to employees, former contractors, or competitors.
What we check
External perimeter
Open ports and services reachable from the internet, outdated software, unnecessary entry points.
Wi-Fi
Encryption strength, guest networks, separation from the working network.
Local network
Segmentation, access to shared resources, unknown devices.
Access rights
Accounts, passwords, access left with former employees and contractors.
Workstations
Updates, antivirus protection, removable media.
Leak channels
Email, cloud storage, messengers, printing, and removable drives.
How an audit works
- 01
Agreement
We record the scope, timeline, and rules of the review in writing.
- 02
Testing
We run tests with open-source tools without disrupting your services.
- 03
Report
A prioritized list of findings with evidence and steps to fix each one.
- 04
Review
We go through the results with your team and plan the fixes.
What you get
- A report in plain language, without unnecessary jargon
- Priorities: what to close first
- Step-by-step recommendations to fix each issue
- A walkthrough of the results with your team
Tools
We use Kali Linux and other widely available open-source tools. The results can be reproduced and verified independently of us.
Who the audit is for
This is probably you if
- Your company has up to 150 people and you do not need a certification audit under the legislation of the Republic of Kazakhstan or PCI DSS.
- You want to know whether an employee or a competitor could reach data they should not see.
- Your Wi-Fi, VPN, or network equipment was set up once, years ago, and nobody has checked it since.
- You need a clear report and a working fix, not a 40-page document written for security specialists.
We are probably not the fit if
- You need a certified audit for a regulator, a bank, or PCI DSS.
- You need a simulated targeted attack (Red Team) or round-the-clock monitoring (SOC).
- You already have an in-house security team with its own response process.
Frequently asked questions
Will the audit interrupt our work?
We agree on the scope and timing in advance, and we do not run tests that could disrupt services without separate consent.
Do we need to give you access to our systems?
The level of access is set during the agreement. Some checks are done from outside, the way an outsider would do them; others from inside the network with your permission.
Do you issue a compliance certificate?
No. We do not perform certification audits under the legislation of the Republic of Kazakhstan, PCI DSS, and similar standards. If you need one, contact an accredited organization.
What happens after the report?
You can fix the findings yourself, ask us to configure hardware, or train your staff at GoldenEye Academy.
How long does an audit take and what does it cost?
It depends on the size of your infrastructure. After a short conversation, we will give you the timeline and price before any work begins.
Let's test your perimeter before someone else does
Describe your infrastructure in a few words and we will propose a scope.