Skip to main content

Cybersecurity & ITGC

ITGC audits, hardening, business continuity plans and ISO 27001 / CISA compliance programmes.

ITGC COBIT ISO 27001 CISA
Workstation displaying a cybersecurity screen

Key features

Standards covered

ISO 27001 COBIT 2019 NIST CSF CISA AUDCIF (IS scope)

Security that also protects your accounts

Cybersecurity is no longer decided at the perimeter: with cloud, remote work and distributed architectures, every exposed service is an attack surface. But for a bank, a telecom operator or a ministry, the risk goes beyond intrusion — it reaches the very reliability of financial information. That is where our dual culture makes the difference: the same ITGC controls we test here underpin the IS portion of our statutory audit co-engagements with signing auditors.

We distrust security reports that impress and change nothing. A finding without proof of exploitation is an opinion; a recommendation without a deadline is a wish. Our readouts rank by real severity, cost the remediation and sequence it at 90, 180 and 365 days — then we come back to verify the fixes hold.

We serve organisations for which downtime is not an option: banks and financial institutions, telecom operators, international organisations, ministries and operators of vital importance across the CEMAC region.

Method

How we work

  1. 01

    Confidential framing

    1 week

    Under NDA from the first exchange if you wish: attack surface, regulatory obligations, critical systems. The scope is prioritised by risk, not by catalogue.

  2. 02

    Audit & testing

    2 to 6 weeks depending on scope

    ITGC audit against COBIT 2019 — access, change, operations, continuity — and external, internal and application penetration tests (OWASP Top 10), with proof of exploitation.

  3. 03

    Readout & action plan

    Dated findings

    Risk map, CVSS severity per vulnerability, costed recommendations and an action plan sequenced at 90, 180 and 365 days — not a wish list.

  4. 04

    Hardening & upkeep

    Ongoing

    Remediation support, BCP / DRP with documented failover tests, ISMS design and preparation for ISO 27001 certification, re-validation of fixes.

Deliverables

What you receive

ITGC audit report

COBIT 2019 risk map, prioritised findings, costed recommendations.

Penetration test report

Proof of exploitation, CVSS severity, remediation guidance, post-fix re-validation.

BCP / DRP

Business impact analysis, RTO / RPO per process, standby architectures, documented failover tests.

ISO 27001 ISMS pack

Gap analysis, documented policies, preparation for the mock audit and the certification audit.

Commitment

No report leaves without a dated action plan — 90, 180, 365 days.
Our auditors are CISA-certified (ISACA) and trained on COBIT 2019, NIST CSF and ISO 27001. Sensitive engagements are systematically covered by NDA, with reinforced confidentiality clauses for banks and institutions.

Getting started

How to get started

  1. 1

    Confidential interview

    45 minutes — under NDA if you wish — to qualify your exposure.

  2. 2

    Risk-prioritised scope

    A written audit proposal, sequenced against your obligations.

  3. 3

    Within 48 business hours

    No commitment on your side.

FAQ

Frequently asked questions

What is an ITGC audit?

An audit of IT general controls: access, change, operations and continuity management. It underpins the reliability of your financial information and meets auditor requirements.

Are your auditors certified?

Yes, our consultants are CISA-certified (ISACA) and trained on COBIT 2019, NIST CSF and ISO 27001.

Are sensitive engagements covered by an NDA?

Always. Scoping can start under NDA from the very first exchange, with reinforced confidentiality clauses.

Let's talk about your project

A demo, an audit, an ERP to roll out? One message is enough to start the conversation.