Enya Security
Request an audit
FAQ

Answers to
your questions

Wondering how a cybersecurity audit actually works? Here are the answers to the questions we hear most often.

General Process Technical Pricing Confidentiality After the audit NIS2

General

Could the audit disrupt my business?

No. Enya Security audits are carried out read-only. Nothing is modified on your databases or systems during the engagement. The aim is to observe, analyse and identify risks without interrupting your operations.

Do you work remotely?

Yes. Engagements are delivered remotely through secure access — VPN, SSH, a cloud console or screen sharing, depending on your environment.

Who are your services for?

Primarily:

  • Micro-businesses
  • Small and medium-sized businesses
  • Public bodies
  • Associations and non-profits
Do you carry out penetration testing?

No. All our engagements are strictly non-intrusive: we observe, analyse and report. We do not exploit vulnerabilities and we do not carry out remediation work on your systems — which is exactly what keeps our findings independent.

Process

How does an audit run?
  1. 1 Initial call (10 minutes)
  2. 2 Quote approval
  3. 3 NDA signature
  4. 4 Rules of Engagement signature
  5. 5 Technical audit
  6. 6 Report delivery
  7. 7 Debrief call
How long does an audit take?

It depends on scope. On average:

  • Express: a few hours of work, report within 5 business days
  • Standard: 1 to 2 days, report within 7 business days
  • Premium: 2 to 4 days, report within 10 business days
Will I get a report?

Yes. Every engagement ends with a detailed report covering:

  • The vulnerabilities identified
  • Their severity
  • The evidence observed
  • Remediation recommendations
  • An overall risk score

Technical

Which database systems do you audit?
  • MySQL
  • MariaDB
  • PostgreSQL
  • MongoDB
  • SQLite

Along with the main compatible cloud database services.

Do you audit AWS, Azure or Google Cloud?

Yes. Where the database is cloud-hosted, a dedicated module covers network exposure, IAM permissions, backups, encryption, logging and other checks suited to cloud environments.

Do you need administrator access?

No. A read-only account is preferred wherever possible, limited to the scope defined in the Rules of Engagement.

Pricing

How much does an audit cost?

The fee depends on:

  • The number of systems in scope
  • The hosting model
  • Any optional modules needed
  • The tier you choose

See our pricing page or request a free quote.

Are there hidden costs?

No. The quote sets out the scope and any additional modules before the engagement starts.

Confidentiality

Is my data kept confidential?

Yes. A non-disclosure agreement is signed before any work begins. All technical information is handled confidentially, and data collected during the audit is destroyed once the engagement is complete, in line with our commitments.

How personal data is handled is set out in our privacy policy.

Do you keep our access credentials?

No. Credentials are used solely to carry out the engagement and are then destroyed according to our documented procedure.

After the audit

Do you handle the fixes?

No. Enya Security audits and recommends. You remain free to:

  • Apply the fixes in-house
  • Hand them to your IT provider
  • Or use any other supplier you choose

This separation is deliberate: having nothing to sell you afterwards is what keeps the findings independent.

Can you verify the fixes afterwards?

Yes. A post-remediation verification is available to confirm that the recommendations have been correctly applied.

NIS2

Is my organisation in scope for NIS2?

It depends on your sector, size and turnover. Most small and medium-sized businesses are not directly in scope, but may be affected indirectly as a supplier or subcontractor to an organisation that is. The assessment clarifies where you stand.

My organisation isn't in scope. Is the assessment still useful?

Yes. Most of the organisations we work with are not directly in scope. They commission the assessment either because a client or partner subject to the directive is asking for security guarantees, or simply to get ahead of it. It remains useful regardless of your regulatory status.

Is this a technical audit?

No. The assessment is declarative and documentary — interviews and document review. No intrusive testing and no active vulnerability scanning, consistent with our non-intrusive positioning across all services.

Does the assessment count as certification?

No. It is a readiness assessment — a gap analysis against the applicable requirements. It is not an attestation of legal compliance with NIS2 and does not replace a nationally qualified audit provider where one is required.

Does it apply outside France and Italy?

NIS2 is an EU directive, so obligations and deadlines come from each member state's national transposition. Our methodology is built on the French and Italian frameworks. If you are established elsewhere in the EU, tell us at first contact and we will confirm what we can usefully cover before quoting.

DIDN'T FIND YOUR ANSWER?

Get in touch.

We usually reply within 24 hours.

Contact us