Skip to content

Your failing tests closed before the audit date

Your compliance tool shows a few red tests and the auditor has questions. We triage, draft the responses and put the controls in place in time.

Free 30-minute call. The assessment from €3,600, fixed and confirmed before any work begins.

Unmesha security assessmentsUM-SA-001 · Revision 4.0

Where Fernleaf’s controls stand before the audit

A status summary for the audit: the controls we checked, what we found, and the work under way with its calendar time.

Who it’s for

Your auditor

What we checked

Access to production, change control for releases, removal of access, cloud logging and alerting, and backups.

What we found

  • Releases could reach production from any branch, under a broader role, and as an image nobody had signed off (CLD-01 to CLD-03).
  • People removed from a customer account kept access until their session ended (APP-03).
  • Cloud logs are kept, but no one is alerted. Backups run nightly but haven’t been restored in a test.

In place now

  • MFA on the cloud console and the code repository for everyone who can deploy.
  • Nightly database backups, kept for 14 days.
  • Staff laptops enrolled in device management, with disk encryption on.

Planned

  • Identity: MFA everywhere, single sign-on, conditional access3 to 4 weeks
  • Cloud monitoring: alerts routed to the team1 to 2 weeks
  • Backups and recovery: immutable copies and a documented restore test1 week
  • Release and access fixes, by Fernleaf’s developers, then our retest4 to 6 weeks

Evidence

Every answer on this page points at an item in the evidence index on page 24: exports, policy files, restore logs.

Questions

Want the detail behind a line? Ask Fernleaf for the finding pages, and we’ll walk you through them.

Fictional sample. The company, systems and data are invented; no real client was assessed.

Prepared by Unmesha Technologies for Fernleaf Billing Ltd
An example of the one-page summary you forward, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • Your compliance tool shows failing tests and the audit is coming up.
  • The auditor has raised exceptions you can’t close alone.
  • You’ve just bought the tool and want the controls in place before you switch it on.
  • You have no security engineer on staff.

What you get, and what it costs

Step 1 is the assessment, at one fixed fee. Step 2 is only the fixes the person asking needs. Every fix, with prices.

Step 1: what the assessment includes

  • Failing tests triaged in order of audit impact.
  • Draft responses for each auditor exception.
  • A remediation plan that fits your audit date.
  • A one-page status summary for your auditor.

Variants

  • Audit prepMonths out instead of weeks. The same assessment before the tool is switched on, so its tests pass from day one.
  • Your tool, or noneVanta, Drata, Secureframe, Sprinto, Scrut, or a spreadsheet.
  • Annual recertificationA rerun before each year’s audit.

How it works

Three steps. You know the price before each one starts.

  1. A free call

    Tell us what you need and who’s asking. We’ll say what we’d check and give you a fixed price.

    30 minutesFree

  2. We check your product

    Your app, your cloud and how code gets to production. You get a report, a plan and a one-page summary to send to whoever’s asking.

    About two weeksfrom €3,600

  3. We fix what’s missing

    We set up what your product lacks, like MFA, alerts and tested backups. Your developers make any code changes, with our help. Then we retest, at no extra cost.

    Fixed price per fixfrom €1,800

Before you enquire

What people ask us most. Anything else, ask on the call.

Do you run the audit?

No. Your auditor does. We get the controls and the evidence ready, and draft your side of each exception.

Which failing tests can you fix?

The infrastructure ones, as fixed-price fixes: MFA, logging, backups, device management. Tests about your application code go to your developers with our pattern, and we check the result.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Tell us your audit date

Which framework, which tool, and how many tests are red. On the call we’ll say what fits before the date.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

Send a short outline of what you want checked and any deadline.

Email Unmesha

Please leave out passwords and customer data. How we handle enquiry information.