Skip to content
RO
← All writing

The audit that changes nothing

  • security
  • audit
  • windows
  • cyber-essentials

Every security tool I have ever been handed by a client wanted administrator rights and permission to fix things.

Mine does not fix anything. It reads, it writes a report, and it leaves the machine in exactly the state it found it. That is a deliberate design decision rather than a missing feature, and it is the first thing people ask about, usually in a tone that suggests they think I have undersold myself.

So here is what read-only actually buys you, what it costs me, and where the whole approach runs out of road.

Nobody has to trust me on day one

The sales problem with a security audit is that you are asking a stranger for the keys to the estate, on the strength of a website and a phone call, before they have done anything for you.

Read-only removes most of that conversation. Nothing is changed, nothing is installed as a service, no configuration is written, no account is created. If the audit is wrong about something, the worst case is a wrong sentence in a document rather than a registry key that used to work. I can hand somebody’s IT manager the report and they can check it themselves before deciding whether I am worth listening to.

It also means the audit can run on a Tuesday afternoon on a live machine, which matters more than it sounds. The alternative is a change window, and a change window means it gets scheduled for a quiet weekend that never arrives. I wrote about the same instinct from the other direction when I made every hardening script back up what it touches — the risk was never the script, it was the hesitation before running it.

Every finding carries the thing it was read from

This is the half that took the longest to build and is the half that matters.

A scanner that tells you “SMBv1 is enabled” is asking you to believe it. A finding that tells you SMBv1 is enabled and shows you the registry value it read, with the path, gives you something you can check in thirty seconds without me in the room. Those are different products.

It changes the argument, too. Reports get read by somebody’s existing IT provider, and the natural first response to an outside audit is that it is wrong. Fine. Here is the value, go and look. That has closed several conversations that would otherwise have gone three emails deep, and on one occasion the provider was right and I was wrong, which I would never have found out from a report that said only “SMBv1 is enabled”.

What I map to, and what I cannot do

Findings get mapped to the relevant Cyber Essentials control, because a good half of the people asking for an audit are actually asking whether they would pass. The other half are holding a security questionnaire a customer sent them, which is the same five controls rephrased by somebody in procurement.

I cannot certify anybody, and neither can anybody who is not an IASME-licensed certification body. I say that on the service page and I say it on the phone, because the alternative is somebody paying me and then discovering the certificate they wanted was never on the table. What the mapping does is tell you where you stand before you pay an assessor, which is worth having, since going in unprepared is how people fail it twice.

Four things Windows will not tell me

Here is the part a brochure would leave out.

When your software licences expire. There is no registry of installed software licences and their renewal dates, because no such API exists. Every vendor stores it their own way, in an encrypted blob or a cloud check-in or a dongle. Windows and Office are the exception — SoftwareLicensingProduct exposes real activation status, the channel, a partial key and a genuine grace countdown, and that is authoritative. Everything else comes off the uninstall hives, which give a name, a version, a publisher and an install date, and no expiry, because there is none to read. Any tool claiming to list all your licences and when they run out is guessing or is quietly only reporting Microsoft.

Whether a password is any good. I can read the policy. The minimum length, the lockout threshold, whether complexity is on. I cannot tell you that four people in accounts are using the same one.

What happened before I arrived. An audit is a photograph. If the logs have already rolled, that history is gone, and I would rather say so than infer a story from what is left.

Whether the exposure is being exploited right now. A read-only audit finds an open door. It does not tell you whether anybody has walked through it. Those are separate jobs and the second one is incident response, not an audit.

The honest version of this service is that it tells you what is exposed, with the evidence, and stops there. The list above is the price of the constraint I picked.

The re-audit is the actual product

A one-off audit produces a document. Documents get filed.

So the re-audit costs less than the first one and does one specific job: it shows what actually got fixed. Not what somebody says got fixed. The same checks, run again, against the same evidence format, with the before and the after side by side. That is the only way I know of to tell the difference between remediation and a closed ticket, and I have been on the wrong side of that distinction on my own systems more than once. My own server reported itself fully patched while running a kernel three versions behind, and my own header audit told me a site was missing four headers it had had for months. Reading the config back is not verification.

There is no retainer attached and no obligation to have me do the remediation. If your existing provider fixes everything on the list, that is the outcome I wanted, and I would rather be paid for the re-audit that proves it.

What it costs

Fixed price per audit, based on how many machines are in scope. Re-audits at a lower rate. I quote after I know the machine count rather than publishing a number that would be wrong for almost everybody. Only the care plan carries a price up front on this site. The builds, the server work and this are all quoted after a call, and that bothers me slightly.

The thing I would push back on, if you are shopping around: ask whoever is quoting you whether their tool writes anything to the machines, and ask to see one finding with its evidence attached before you sign. Those two questions sort the field out faster than any comparison of feature lists. And if the quote in front of you is for a penetration test, check whether you need one yet, because it answers a different question.