Skip to main content

ITInfrastructureAudits&HealthChecks

One-Off Deep Dives | Tiered Monthly Retainers | Executive Roadmap

Two engagement models under one framework. The 2-day deep-dive audit produces a vendor-neutral assessment of your network, physical security, cloud spend, and cybersecurity posture. The tiered Security Shield retainer runs weekly firewall and endpoint reviews, monthly vulnerability scans, and 24/7 monitoring on the premium tier. Both feed a single living roadmap.

Request Consultation

Use your company email if you have one — it helps us prepare for your call. Gmail works too.

Technologies in use

FortinetBitdefender GravityZoneMicrosoft
Platforms and standards referenced
ISO/IEC 27001
Microsoft ecosystem
AWS platform
Cisco infrastructure
Fortinet security
Buyer fit and next step

When this service becomes urgent

912 IT audits convert infrastructure uncertainty into a prioritized remediation plan. The review covers assets, credentials, firewall, endpoints, backups, licensing, users, vendor ownership, compliance, and quick wins.

No single asset or credential register exists.
Leadership cannot see infrastructure risk or renewal exposure.
A past incident exposed hidden dependencies on one person or vendor.

Discovery call agenda

Discovery workshop, technical evidence collection, risk scoring, quick-win register, remediation roadmap, and leadership summary.

  1. 1Confirm audit drivers and decision deadline.
  2. 2Review systems, vendors, and missing records.
  3. 3Define evidence pack and remediation output.
Book a discovery call
Why now

What the numbers say about leaving this alone

An audit is cheap. Finding out what an audit would have told you, during an incident or an inspection, is not.

  • The ODPC draft Strategic Plan reports 82 audits or inspections, 62 reported data breaches, and 10 penalty notices.

    Office of the Data Protection Commissioner Kenya(opens in a new tab)regulator activity reported in its draft Strategic Plan 2023–2027

    The document is marked "Draft for Public Participation" — these are administrative figures from it, not an audited annual report.

  • Serianu reported that more than 75% of surveyed organisations aligned with recognised cybersecurity frameworks and 71% had formal cybersecurity policies.

    Serianu(opens in a new tab)which is what an audit exists to test: whether the documented policy is the operating reality

What the Audit Covers

Cybersecurity & Network

  • Weekly firewall rule and endpoint-alert review
  • Brute-force and port-scan log analysis
  • Active Directory permission hygiene
  • VPN access review and zero-trust alignment

Physical & Infrastructure

  • Server room power, cooling, and environmentals
  • CCTV and Access Control integration safety
  • Structured cabling standards check
  • UPS and backup-power resilience

Cloud, Backups & Licensing

  • Backup recovery tests (RTO/RPO verified, not assumed)
  • Cloud spend analysis with unattached-resource surfacing
  • SaaS licensing right-sizing
  • Microsoft 365 and Google Workspace admin posture

What We Typically Find

Paying for 'Managed IT' but never receiving a network map or configuration backup.

Believing you have backups, only to discover they haven't run successfully in 6 months.

CCTV cameras installed by third parties that created backdoor vulnerabilities in your corporate network.

20-30% of cloud spend on unattached resources, orphaned instances, and over-provisioned licences.

Honest Risk Framing

What this protects against — and what it doesn't.

Audit findings, not implementation

The audit produces findings, recommendations, and a prioritised roadmap — not the implementation itself. Acting on the recommendations is a separate engagement (project work or a Managed IT retainer). The audit fee is deductible from any project signed within 6 months.

Read-only by design

We use read-only scanning tools so the audit never disrupts production. The trade-off is we observe what's running, not what could be — deep penetration testing or red-team exercises require explicit consent and a separate scoping conversation.

Security Shield retainer is monitoring, not Managed IT

Even the Premium tier covers security monitoring, alerts, and incident response. It does not include day-to-day helpdesk, patching for non-security updates, or vendor management — those are full Managed IT scope. Many clients pair both.

Engagement Models

Choose the one-off deep dive, the ongoing retainer, or both.

Part of the 912 six-phase engagement model — this is how it runs for this service.

01

Day 1: Discovery & Scans

On-site physical inspection and read-only network scanning tools deployed in your environment.

02

Day 2: Policy & Cloud

Backup logs, firewall rules, AD permissions, cloud architecture, and licensing position reviewed.

03

Analysis & Briefing

Findings synthesised against ISO/NIST and the field-tested 912 audit framework. Executive briefing with prioritised, budgeted roadmap.

04

Optional: Security Shield Retainer

Continue with monthly Basic, Standard, or Premium tiers — recurring audit cadence with optional Backup, MsSQL, and Brute Force Defender add-ons.

The 912 Difference

Cross-Pillar Insight

We audit physical security, networks, cloud, and identity together — most auditors only see one slice.

Field-Tested Framework

Our audit checklist is grounded in real engagements across SAP HANA DR, CCTV deployments, virtualization migrations, and firewall implementations — not a generic ISO template.

Audit Deliverables

Clarity and direction in writing

Speak to Our Experts
1
Executive Report
100%
Vendor Neutral
3-Year
IT Roadmap
TECHNOLOGIES IN USE

Fortinet

Technology in scope

Bitdefender GravityZone

Technology in scope

Microsoft

Technology in scope

Common Questions

Everything you need to know about IT Infrastructure Audits & Health Checks.

What does a 912 IT audit cover?

A 912 IT audit is a 5-day stack review covering five domains: security posture (firewall, identity, endpoint, email), infrastructure (cloud, server, network, backup), licensing and vendor contracts, process and documentation maturity, and ODPC DPA 2019 compliance gaps. Output: a written report with prioritised remediation roadmap and an itemised cost-savings estimate.

How much does an IT audit cost?

Free for prospective clients — we offer a free 5-day IT audit as the entry point to our One Contract model. For existing audit-only engagements (no follow-on managed services), we charge KES 350,000 to KES 1.2M depending on scope. Most audits identify 30–40% duplicate spend or compliance gaps that pay for themselves within 90 days.

How long does an audit take?

Standard engagement: 5 working days of fieldwork plus 3 days of report writing. The fieldwork is non-disruptive — interviews, configuration reviews, and read-only tool deployments. We never make changes during an audit.

What deliverables do we get?

A written executive summary, a detailed findings register (typically 30–80 items prioritised by risk), a 90-day remediation roadmap, an itemised cost-savings projection, and an ODPC DPA compliance gap analysis. All deliverables are presented in a debrief workshop with your leadership team.

Does the audit cover physical security?

Yes — 912's scope is unique in Kenya because we cover physical and digital security under one engagement. CCTV blind spots, electric fence calibration, access control credential hygiene, and server-room environmental controls are all part of the audit.

Who conducts the audit?

A team of 3 senior engineers — one security lead (CISSP or equivalent), one infrastructure lead, and one applications/data lead. All audits are signed off by 912's Head of Engineering. References available on request.

Ready when you are

One contract.
Every technology need.

Book a free 30-minute discovery call. We map your stack, identify duplicate spend, and propose a fixed-price One Contract plan within 5 business days.