How does a NIS2 audit take place? What is my company’s current level of preparedness? How would our implemented information security system test in a real regulatory audit?
A pre-audit conducted by Grant Thornton is not a substitute for a formal NIS2 audit, but it will help to ensure that the information security system you have put in place will test well in future official audits.
To whom do we recommend our NIS2 internal audit service?
We recommend our NIS2 internal audit service to CEOs and managers who want to ensure that their company’s information security system will pass a subsequent official audit.
Unlike an official audit, NIS2 internal audits are always conducted by a support team within the company.
Want to know more about our NIS2 pre-audit service? Click to make an appointment with one of our experts!How do we conduct an NIS2 internal audit?
- Requesting information: Requesting documents and information, taking data on-site if necessary, sending questionnaires.
- Analysis of contributors: In the case of external support, analysis and discussion of the outsourced tasks.
- Analysis of information: Processing of information received, preparation of task plan and GAP analysis.
- Testing: Testing of protection measures with the involvement of the employees concerned.
- Report preparation: Documentation of NIS2 compliance according to our methodology in Hungarian/English
How do we prepare your company for the NIS2 audit?
The internal audit provides an independent and objective view of the company management’s state of preparedness for NIS2 requirements. It also provides advice, recommendations and actions with respect to areas that may need further improvement.
The pre-audit will review and test the company’s information security processes, documentation and practical implementation of the system’s operation. Based on the results of the pre-audit, the company will be able to prepare a cost-benefit analysis and take corrective actions to address any shortcomings, thus preparing for the official NIS2 audit.
During the NIS2 pre-audit, we use a specific methodology, in which a risk-based maturity score is calculated. Our report thus also results in a well-prioritised action plan, which can be used to easily estimate the necessary expenditure.