Architecture · IT audit · Business continuity

IT consulting: IT audit, architecture and business continuity

Advice from senior people who look inside your systems before telling you what to change. We advise on data, architecture, security, AI and compliance, run IT audits and prepare business continuity plans backed by a real restore test.

// In short

Senior IT consulting, not another slide deck

We work in five areas: architecture review, IT audit, business continuity and disaster recovery, technical due diligence, and fractional roles (CISO, architect, data lead). We advise on data, security, AI, governance and compliance. For boards, CIOs and investors who need an independent assessment and a plan with owners.

// Areas

Five areas we advise on

Each area can be ordered on its own. We usually start with an architecture and risk review, because it shows which area is urgent.

  1. 01Architecture

    Architecture review and target architecture

    Data, security and AI in one picture: what scales, what is a single point of failure, and where controls are missing.

    • Map of systems, integrations and data flows
    • Single points of failure and technical debt
    • Target architecture with transition stages

    First step, 4-5 weeks

    Architecture and risk review

    • Current-state map
    • Top risks with owners
    • 90-day plan

    Key deliverable: a risk list with owners and a 90-day plan

    Request the first step
  2. 02IT audit

    IT audit based on ITAF

    Led by certified auditors on our team.

    • Cloud audit
    • Architecture audit
    • Software license audit
    • IT project audit
    How we run IT audits
  3. 03Business continuity

    BIA, business continuity plan and DR tests

    The plan is proven in a restore test, not in a document review.

    • Business impact analysis (BIA)
    • Business continuity plan (BCP)
    • Disaster recovery (DR) tests
    Business continuity and DR testing
  4. 04Due diligence

    Technical due diligence

    For investors and acquisitions: an assessment before you sign.

    • Architecture and code quality
    • Security and licenses
    • Team, processes and running costs
  5. 05Fractional roles

    A CISO, architect or data lead for a set period

    A senior in a role it does not yet pay to fill full time, with a scope, goals and an end date.

    • Fractional CISO
    • Solution architect
    • Data lead

// IT audit

IT audit based on ITAF, with evidence for every finding

We follow ITAF, the IT audit framework published by ISACA: a plan, samples, evidence for every finding and a report with priorities. An IT audit is not the formal audit under Article 15 of the Polish KSC Act (NIS2 in Poland).

  1. 01Cloud

    Cloud audit

    Configuration, permissions, costs and compliance, based on data from the console and logs.

    Cloud audit: security, costs and compliance
  2. 02Architecture

    IT architecture audit

    Scalability, stability, single points of failure and technical debt.

    Architecture audits and scalability
  3. 03Licenses

    Software license audit

    License compliance and costs, checked before the vendor does.

    Software license audit
  4. 04Projects

    IT project audit

    Whether the project meets its goals, budget and schedule, and what to do if it does not.

    IT project audit

// Qualifications

Team credentials

Our audits are led by certified auditors. Our team also holds certifications in security, data protection and process management. When we agree the scope, we show you which of them the people on your project have.

Certifications held by our team

  • CISA (Certified Information Systems Auditor)ISACA
  • IODO (Polish data protection officer certificate)
  • CompTIA Security+CompTIA
  • ITILAXELOS / PeopleCert
  • REQBRequirements Engineering Qualifications Board
  • SAFeScaled Agile
  • ISTQBInternational Software Testing Qualifications Board

// Scope

What we do, and what we don't

We agree the scope and date in writing before we start.

We do

  • Architecture review and target architecture
  • IT audit based on ITAF: cloud, architecture, licenses, projects
  • Business impact analysis, a business continuity plan and restore tests
  • Technical due diligence for investors and acquisitions
  • A fractional CISO, architect or data lead, with an end date

We don't

  • A formal KSC audit under Article 15: we don't perform it, and an IT audit does not replace it
  • Reselling licenses or hardware
  • Audit reports without discussing the findings with their owners
  • Fractional roles without a scope and goals

The rules of the formal KSC audit are on our NIS2 compliance in Poland page. Data ownership and quality are covered by data governance, and the rules for using AI by AI governance.

// FAQ

Questions about IT consulting

How is an IT audit different from a KSC audit?

An IT audit assesses whether systems, projects and IT processes work as they should: securely, in line with contracts and at a reasonable cost. The formal KSC audit is the audit under Article 15 of the Polish KSC Act, which only an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT may perform. IT audit results help with KSC but do not replace it.

How do you test a business continuity plan?

We agree a recovery time objective (RTO) and a recovery point objective (RPO) with the process owners, then restore a chosen system from backup or fail it over to a standby and measure the time. The details and the first step are on our business continuity and DR testing page.

What does technical due diligence cover?

Architecture and code quality, security, software licenses, vendor dependencies, team and processes, and running costs. The result is a list of risks rated by their impact on the valuation or deal terms, and a plan for the first 100 days after the transaction.

How does a fractional CISO work?

A senior person acts as your CISO for a set number of days a month: runs the risk register, reports to the board, prepares audits and oversees suppliers. The contract has a scope, goals and an end date, and the knowledge stays in your documentation.

How long does the first step take?

The architecture and risk review takes 4 to 5 weeks. You get a current-state map, the top risks with owners and a 90-day plan. We agree the scope and date in writing before we start.

From the blog: IT audit and risk

Let's start with an architecture and risk review

In 30 minutes we work out which area is urgent and what goes into the first step.

Book a 30-minute call

Prefer to start in writing?

Describe your situation and we will send back the scope and date of the first step. We reply within one business day.

Request the first step