Wondering how a cybersecurity audit actually works? Here are the answers to the questions we hear most often.
No. Enya Security audits are carried out read-only. Nothing is modified on your databases or systems during the engagement. The aim is to observe, analyse and identify risks without interrupting your operations.
Yes. Engagements are delivered remotely through secure access — VPN, SSH, a cloud console or screen sharing, depending on your environment.
Primarily:
No. All our engagements are strictly non-intrusive: we observe, analyse and report. We do not exploit vulnerabilities and we do not carry out remediation work on your systems — which is exactly what keeps our findings independent.
It depends on scope. On average:
Yes. Every engagement ends with a detailed report covering:
Along with the main compatible cloud database services.
Yes. Where the database is cloud-hosted, a dedicated module covers network exposure, IAM permissions, backups, encryption, logging and other checks suited to cloud environments.
No. A read-only account is preferred wherever possible, limited to the scope defined in the Rules of Engagement.
The fee depends on:
See our pricing page or request a free quote.
No. The quote sets out the scope and any additional modules before the engagement starts.
Yes. A non-disclosure agreement is signed before any work begins. All technical information is handled confidentially, and data collected during the audit is destroyed once the engagement is complete, in line with our commitments.
How personal data is handled is set out in our privacy policy.
No. Credentials are used solely to carry out the engagement and are then destroyed according to our documented procedure.
No. Enya Security audits and recommends. You remain free to:
This separation is deliberate: having nothing to sell you afterwards is what keeps the findings independent.
Yes. A post-remediation verification is available to confirm that the recommendations have been correctly applied.
It depends on your sector, size and turnover. Most small and medium-sized businesses are not directly in scope, but may be affected indirectly as a supplier or subcontractor to an organisation that is. The assessment clarifies where you stand.
Yes. Most of the organisations we work with are not directly in scope. They commission the assessment either because a client or partner subject to the directive is asking for security guarantees, or simply to get ahead of it. It remains useful regardless of your regulatory status.
No. The assessment is declarative and documentary — interviews and document review. No intrusive testing and no active vulnerability scanning, consistent with our non-intrusive positioning across all services.
No. It is a readiness assessment — a gap analysis against the applicable requirements. It is not an attestation of legal compliance with NIS2 and does not replace a nationally qualified audit provider where one is required.
NIS2 is an EU directive, so obligations and deadlines come from each member state's national transposition. Our methodology is built on the French and Italian frameworks. If you are established elsewhere in the EU, tell us at first contact and we will confirm what we can usefully cover before quoting.