ITInfrastructureAudits&HealthChecks
One-Off Deep Dives | Tiered Monthly Retainers | Executive Roadmap
Two engagement models under one framework. The 2-day deep-dive audit produces a vendor-neutral assessment of your network, physical security, cloud spend, and cybersecurity posture. The tiered Security Shield retainer runs weekly firewall and endpoint reviews, monthly vulnerability scans, and 24/7 monitoring on the premium tier. Both feed a single living roadmap.
Request Consultation
Technologies in use
When this service becomes urgent
912 IT audits convert infrastructure uncertainty into a prioritized remediation plan. The review covers assets, credentials, firewall, endpoints, backups, licensing, users, vendor ownership, compliance, and quick wins.
Discovery call agenda
Discovery workshop, technical evidence collection, risk scoring, quick-win register, remediation roadmap, and leadership summary.
- 1Confirm audit drivers and decision deadline.
- 2Review systems, vendors, and missing records.
- 3Define evidence pack and remediation output.
What the numbers say about leaving this alone
An audit is cheap. Finding out what an audit would have told you, during an incident or an inspection, is not.
The ODPC draft Strategic Plan reports 82 audits or inspections, 62 reported data breaches, and 10 penalty notices.
Office of the Data Protection Commissioner Kenya(opens in a new tab) — regulator activity reported in its draft Strategic Plan 2023–2027
The document is marked "Draft for Public Participation" — these are administrative figures from it, not an audited annual report.
Serianu reported that more than 75% of surveyed organisations aligned with recognised cybersecurity frameworks and 71% had formal cybersecurity policies.
Serianu(opens in a new tab) — which is what an audit exists to test: whether the documented policy is the operating reality
What the Audit Covers
Cybersecurity & Network
- Weekly firewall rule and endpoint-alert review
- Brute-force and port-scan log analysis
- Active Directory permission hygiene
- VPN access review and zero-trust alignment
Physical & Infrastructure
- Server room power, cooling, and environmentals
- CCTV and Access Control integration safety
- Structured cabling standards check
- UPS and backup-power resilience
Cloud, Backups & Licensing
- Backup recovery tests (RTO/RPO verified, not assumed)
- Cloud spend analysis with unattached-resource surfacing
- SaaS licensing right-sizing
- Microsoft 365 and Google Workspace admin posture
What We Typically Find
Paying for 'Managed IT' but never receiving a network map or configuration backup.
Believing you have backups, only to discover they haven't run successfully in 6 months.
CCTV cameras installed by third parties that created backdoor vulnerabilities in your corporate network.
20-30% of cloud spend on unattached resources, orphaned instances, and over-provisioned licences.
Honest Risk Framing
What this protects against — and what it doesn't.
Audit findings, not implementation
The audit produces findings, recommendations, and a prioritised roadmap — not the implementation itself. Acting on the recommendations is a separate engagement (project work or a Managed IT retainer). The audit fee is deductible from any project signed within 6 months.
Read-only by design
We use read-only scanning tools so the audit never disrupts production. The trade-off is we observe what's running, not what could be — deep penetration testing or red-team exercises require explicit consent and a separate scoping conversation.
Security Shield retainer is monitoring, not Managed IT
Even the Premium tier covers security monitoring, alerts, and incident response. It does not include day-to-day helpdesk, patching for non-security updates, or vendor management — those are full Managed IT scope. Many clients pair both.
Engagement Models
Choose the one-off deep dive, the ongoing retainer, or both.
Part of the 912 six-phase engagement model — this is how it runs for this service.
Day 1: Discovery & Scans
On-site physical inspection and read-only network scanning tools deployed in your environment.
Day 2: Policy & Cloud
Backup logs, firewall rules, AD permissions, cloud architecture, and licensing position reviewed.
Analysis & Briefing
Findings synthesised against ISO/NIST and the field-tested 912 audit framework. Executive briefing with prioritised, budgeted roadmap.
Optional: Security Shield Retainer
Continue with monthly Basic, Standard, or Premium tiers — recurring audit cadence with optional Backup, MsSQL, and Brute Force Defender add-ons.
The 912 Difference
Cross-Pillar Insight
We audit physical security, networks, cloud, and identity together — most auditors only see one slice.
Field-Tested Framework
Our audit checklist is grounded in real engagements across SAP HANA DR, CCTV deployments, virtualization migrations, and firewall implementations — not a generic ISO template.
Fortinet
Technology in scope
Bitdefender GravityZone
Technology in scope
Microsoft
Technology in scope
Common Questions
Everything you need to know about IT Infrastructure Audits & Health Checks.
What does a 912 IT audit cover?
A 912 IT audit is a 5-day stack review covering five domains: security posture (firewall, identity, endpoint, email), infrastructure (cloud, server, network, backup), licensing and vendor contracts, process and documentation maturity, and ODPC DPA 2019 compliance gaps. Output: a written report with prioritised remediation roadmap and an itemised cost-savings estimate.
How much does an IT audit cost?
Free for prospective clients — we offer a free 5-day IT audit as the entry point to our One Contract model. For existing audit-only engagements (no follow-on managed services), we charge KES 350,000 to KES 1.2M depending on scope. Most audits identify 30–40% duplicate spend or compliance gaps that pay for themselves within 90 days.
How long does an audit take?
Standard engagement: 5 working days of fieldwork plus 3 days of report writing. The fieldwork is non-disruptive — interviews, configuration reviews, and read-only tool deployments. We never make changes during an audit.
What deliverables do we get?
A written executive summary, a detailed findings register (typically 30–80 items prioritised by risk), a 90-day remediation roadmap, an itemised cost-savings projection, and an ODPC DPA compliance gap analysis. All deliverables are presented in a debrief workshop with your leadership team.
Does the audit cover physical security?
Yes — 912's scope is unique in Kenya because we cover physical and digital security under one engagement. CCTV blind spots, electric fence calibration, access control credential hygiene, and server-room environmental controls are all part of the audit.
Who conducts the audit?
A team of 3 senior engineers — one security lead (CISSP or equivalent), one infrastructure lead, and one applications/data lead. All audits are signed off by 912's Head of Engineering. References available on request.
Related Technical Protocol

Try Bitdefender GravityZone Free for 30 Days: What Your Business Should Test.
A free product trial should answer whether GravityZone fits your devices, applications, policies, reporting needs, and operating team. Here is what organisations with at least 15 endpoints should test during the 30-day evaluation.

What Happens When Ransomware Starts Encrypting Files? GravityZone Prevention and Recovery Explained.
When ransomware begins abnormal encryption, GravityZone can detect the behaviour, block the responsible process, and preserve temporary recovery data where the required protection and prerequisites are active. Here is what that does—and does not—mean for recovery.

SAP ECC to S/4HANA: The 2027 Deadline Explained for Kenyan Businesses
SAP ends mainstream support for ECC at the end of 2027. Here is what the deadline actually means for Kenyan businesses, the migration paths to S/4HANA, and why planning now is cheaper than reacting later.