The standard "cybersecurity audit"

Automated vulnerability scanner run against your IP range
Five generic findings in a templated PDF
Junior analyst who has never seen a real breach
Recommendations with no context for your business
The same report re-used for dozens of clients
Auditor disappears after delivering the PDF

A ThreeShield cybersecurity audit

200+ findings using manual expert analysis beyond what scanners catch
CISA-led team with government and Fortune 50 audit experience
Full compliance-framework coverage, customized to your organization: every applicable requirement, not a generic subset
Finds what remote scans cannot: physical security, business processes, and insider threats
Lavawall® platform data correlated with manual testing across penetration tests, policy reviews, and cloud configuration
Actionable, business-contextualized recommendations that reduce risk and can lower insurance premiums
Independent, arm's-length reporting, separate from your MSP and internal IT, so the findings carry weight
Optional remediation support: we can help you fix findings, or hand you a clean, independent report to act on yourself

Independent Review

A second opinion on IT security someone else runs

If an MSP or in-house team runs your IT, they cannot objectively grade their own work. A board, an insurer, an auditor, or a large client will trust a review far more when it comes from an outside party with nothing to defend. ThreeShield gives you exactly that: an arm's-length review of the security someone else is responsible for.

We look at what your provider is actually delivering against what your contract and your risk require, and we report to you in plain language. We are glad to work alongside your MSP to close the gaps we find, but the findings are yours, and they are honest.

MSP oversight

Confirm your managed-services provider is delivering the security your contract promises, and see what is falling through the cracks.

Board and insurer assurance

An independent report your directors and your cyber-insurer will accept, because it does not come from the party being reviewed.

Vendor and supply-chain review

Assess the security of a third party you rely on, or answer a client who is assessing you.

Pre-acquisition due diligence

Understand the real security posture of a company before you buy or merge with it.


Audit Services

Every compliance requirement.
One audit team.

SOC 2

SOC 2 Readiness & Audit

Type I and Type II readiness assessments plus audit delivery. Especially relevant for technology vendors selling to enterprise and healthcare clients.

HIPAA

HIPAA Risk Assessment

Required HIPAA Security Rule risk analyses for covered entities and business associates. Includes administrative, physical, and technical safeguard reviews.

HIA

Alberta HIA & BC health privacy

Compliance assessments for custodians of health information under Alberta HIA, BC PIPA, and the BC E-Health Act (often called BC HIA). Required for clinics, pharmacy groups, and health-adjacent companies.

PCI DSS

PCI DSS Assessment

SAQ A, A-EP, B-IP, C, C-VT, and D assessments. We can reduce your compliance scope and quickly implement the controls your processor requires.

NERC CIP

NERC CIP Compliance

Critical Infrastructure Protection compliance reviews for utilities and energy companies. One of the most rigorous regulatory frameworks in North America.

Comprehensive

Comprehensive IT Security Assessment

Our flagship audit, with no checklist limits: full control assessment, penetration testing, cloud configuration review, policy analysis, and a prioritized remediation roadmap.

CIS/NIST

CIS Controls & NIST CSF

Maturity assessments against CIS Controls v8 (IG1-IG3) and the NIST Cybersecurity Framework. Often required for cyber insurance and enterprise client questionnaires.

CMMC

CMMC Readiness

Cybersecurity Maturity Model Certification readiness for defence contractors and US government supply chain participants.


Our Methodology

From kickoff to
certified compliance outcome.

1

Scoping & Context

Before we touch anything technical, we learn your business, your data flows, your regulatory environment, and your risk tolerance. Compliance and security are not the same thing, so we start with your actual risks.

2

Lavawall® Baseline (where applicable)

We deploy Lavawall® monitoring to capture a real-time baseline of your endpoint, cloud, and domain posture. This gives the audit team live data to correlate with manual testing.

3

Technical Assessment

Penetration testing, vulnerability scanning with commercial and proprietary tools, network architecture review, cloud configuration analysis, and manual expert analysis of what automated tools miss.

4

Control & Policy Review

Administrative controls, policies, procedures, training records, incident response plans, vendor agreements, and physical security, all reviewed against the applicable frameworks.

5

Report & Debrief

200+ prioritized findings, each explained in business terms rather than as a bare CVE number. You get an executive summary for leadership, technical detail for your IT team, and a remediation roadmap with cost estimates.

6

Remediation Support

We don't disappear once the report is delivered. ThreeShield provides hands-on remediation support, compliance operationalization, and certification delivery. Same team, start to finish.


FAQ

Audit questions answered

It depends on scope and organization size. A focused compliance audit (for example, a PCI SAQ or a HIPAA risk assessment) typically takes 2 to 4 weeks. A comprehensive IT security assessment for a mid-sized organization is typically 4 to 8 weeks. SOC 2 Type II audits require an observation period of at least 6 months. We provide a detailed timeline at scoping.
Yes. That is one of the most common reasons organizations hire us. We review the security of IT that someone else runs, at arm's length, so you get an honest second opinion rather than a team grading its own work. We report to you, and we can share the findings with your MSP to fix, or simply hand you a clean independent report to act on.
Yes. ThreeShield's founder has been certified as an expert witness by the Court of King's Bench of Alberta, and is available for legal proceedings involving cybersecurity matters.
A vulnerability assessment identifies and prioritizes known weaknesses. A penetration test actively attempts to exploit those weaknesses to demonstrate real-world impact. ThreeShield's full assessments go further than both: we follow vulnerabilities through manual expert analysis to find issues automated tools miss entirely. We often find issues that automated tools would score as low-risk but that are a significant real-world exposure.
Yes. ThreeShield provides pre-audit readiness assessments and remediation support so you're prepared for third-party audits. With experience on both sides of the audit table, we know exactly what auditors look for and where organizations typically stumble.

Not sure what you need?

Audit, penetration test, or vulnerability assessment?

A full audit is the widest lens. A penetration test proves what an attacker could do. A vulnerability assessment gives you broad, regular coverage. Many organizations combine them, and we can help you decide.

Cybersecurity audit

The complete picture: controls, policies, physical security, and technical testing against every applicable framework. You are here.

Penetration testing →

A hands-on, authorized attack that shows exactly what an intruder could reach. Satisfies PCI DSS 11.4, SOC 2, and insurers.

Vulnerability assessment →

Broad, regular scanning with findings validated by hand and continuous Lavawall® monitoring between assessments.

GRC audit (Canada) →

Governance, risk, and compliance audited together against Canadian and international frameworks, evidence collected continuously by Lavawall®.

Ready for an audit that
actually finds your risks?

Request an audit proposal. We'll scope the right engagement for your regulatory requirements, risk profile, and budget, and show you up front exactly what you'll receive.