Governance and risk
Responsibilities, policies, risks and obligations
GUIDED IT AUDIT · BELGIAN BUSINESSES
Most complete for your businessThe Professional Audit goes beyond checking whether tools exist. It reviews governance, consistency, monitoring and evidence that controls operate effectively.
VERIFICATION SCOPE
The exact number of checks depends on your environment. Irrelevant modules are removed and relevant checks are explored in greater depth.
Responsibilities, policies, risks and obligations
Inventory, lifecycle, software and licences
Accounts, MFA, privileges and leavers
Endpoints, servers, mobile, updates and encryption
Firewall, segmentation, Wi-Fi, remote access and premises
Microsoft 365, SaaS, email and sharing
Classification, retention, GDPR and transfers
Coverage, isolation, recovery and continuity
Logs, alerts, incidents and exercises
Awareness, suppliers and responsibilities
Development, vulnerabilities and changes
Connected equipment, IoT and industrial environments
THE EXPECTED OUTCOME
Understand dependencies between risks
Use verifiable evidence for decisions
Build a realistic roadmap
What you receive
A FOUR-STAGE ENGAGEMENT
We confirm sites, users, equipment, cloud services, exclusions and engagement objectives.
The auditor conducts interviews, reviews authorised configurations and collects useful evidence.
Each finding is qualified by risk, impact, urgency and confidence level.
Management receives a clear summary while teams get a detailed action plan.
THE RIGHT LEVEL OF DEPTH
Vital safeguards
You want an accessible, targeted human review of your most important safeguards.
View this plan →Most complete for your business
You need to decide, budget and track a documented IT or cybersecurity improvement plan.
View this plan →In-depth analysis
Your environment is multi-site, complex, highly IT-dependent or subject to specific obligations.
View this plan →FAQ
No. The audit evaluates practices, configurations and evidence within scope. A penetration test is a separate engagement requiring specific authorisation.
No. The maximum represents the full plan catalogue. We adapt checks to the technology you actually use.
Yes. You choose the report language independently from the language used with the auditor.
No. Access and observations are agreed before the engagement. GVISION never asks for your personal password.