The standard "cybersecurity audit"

Automated vulnerability scanner run against your IP range
Five generic findings in a templated PDF
Junior analyst who has never seen a real breach
Recommendations with no context for your business
The same report re-used for dozens of clients
Auditor disappears after delivering the PDF

A ThreeShield cybersecurity audit

200+ findings using manual expert analysis beyond what scanners catch
CISA-led team with government and Fortune 50 audit experience
Full compliance-framework coverage, customized to your organization: every applicable requirement, not a generic subset
Finds what remote scans cannot: physical security, business processes, and insider threats
Lavawall® platform data correlated with manual testing, from penetration tests to policy reviews to cloud configuration
Actionable, business-contextualized recommendations that reduce risk and can lower insurance premiums
Independent, arm's-length reporting, separate from your MSP and internal IT, so the findings carry weight
Optional remediation support: we can help you fix findings, or hand you a clean, independent report to act on yourself

Independent Review

A second opinion on IT security someone else runs

If your IT is managed by an MSP or in-house IT, they cannot objectively grade their own work. A board, an insurer, an auditor, or a large client will trust a review far more when it comes from an outside party with nothing to defend. That is what ThreeShield provides: an arm's-length review of the security someone else is responsible for.

We look at what your provider is actually delivering against what your contract and your risk require, and we report to you in plain language. We are glad to work alongside your MSP to close the gaps we find, but the findings are yours, and they are honest.

MSP oversight

Confirm your managed-services provider is delivering the security your contract promises, and see what is falling through the cracks.

Board and insurer assurance

An independent report your directors and your cyber-insurer will accept, because it does not come from the party being reviewed.

Vendor and supply-chain review

Assess the security of a third party you rely on, or answer a client who is assessing you.

Pre-acquisition due diligence

Understand the real security posture of a company before you buy or merge with it.


Audit Services

Every compliance requirement.
One audit team.

SOC 2

SOC 2 Readiness & Audit

Type I and Type II readiness assessments plus audit delivery. Especially relevant for technology vendors selling to enterprise and healthcare clients.

HIPAA

HIPAA Risk Assessment

Required HIPAA Security Rule risk analyses for covered entities and business associates. Includes administrative, physical, and technical safeguard reviews.

HIA

Alberta & BC Health Information Act

Compliance assessments for custodians of health information under Alberta HIA and BC PIPA. Required for clinics, pharmacy groups, and health-adjacent companies.

PCI DSS

PCI DSS Assessment

SAQ A, A-EP, B-IP, C, C-VT, and D assessments. We can reduce your compliance scope and quickly implement the controls your processor requires.

NERC CIP

NERC CIP Compliance

Critical Infrastructure Protection compliance reviews for utilities and energy companies. One of the most rigorous regulatory frameworks in North America.

Comprehensive

Comprehensive IT Security Assessment

Our flagship audit. No checklist limitations. Full control assessment, penetration testing, cloud configuration review, policy analysis, and prioritized remediation roadmap.

CIS/NIST

CIS Controls & NIST CSF

Maturity assessments against CIS Controls v8 (IG1-IG3) and NIST Cybersecurity Framework. Often required for cyber insurance and enterprise client questionnaires.

CMMC

CMMC Readiness

Cybersecurity Maturity Model Certification readiness for defense contractors and US government supply chain participants.


Our Methodology

From kickoff to
certified compliance outcome.

1

Scoping & Context

We understand your business, your data flows, your regulatory environment, and your risk tolerance before touching anything technical. Compliance and security are not the same - we start with your actual risks.

2

Lavawall® Baseline (where applicable)

We deploy Lavawall® monitoring to capture a real-time baseline of your endpoint, cloud, and domain posture. This gives the audit team live data to correlate with manual testing.

3

Technical Assessment

Penetration testing, vulnerability scanning with commercial and proprietary tools, network architecture review, cloud configuration analysis, and manual expert analysis of what automated tools miss.

4

Control & Policy Review

Administrative controls, policies, procedures, training records, incident response plans, vendor agreements, and physical security - all reviewed against applicable frameworks.

5

Report & Debrief

200+ prioritized findings with business-context explanations - not just CVE numbers. Executive summary for leadership. Technical details for your IT. Remediation roadmap with cost estimates.

6

Remediation Support

We don't disappear after delivering the report. ThreeShield provides hands-on remediation support, compliance operationalization, and certification delivery. Same team, start to finish.


FAQ

Audit questions answered

Timeline depends on scope and organization size. A focused compliance audit (for example, a PCI SAQ or a HIPAA risk assessment) typically takes 2 to 4 weeks. A comprehensive IT security assessment for a mid-sized organization is typically 4 to 8 weeks. SOC 2 Type II audits require an observation period of at least 6 months. We provide a detailed timeline at scoping.
Yes. That is one of the most common reasons organizations hire us. We review the security of IT that someone else runs, at arm's length, so you get an honest second opinion rather than a team grading its own work. We report to you, and we can share the findings with your MSP to fix, or simply hand you a clean independent report to act on.
Yes. ThreeShield's founder has been certified as an expert witness by the Court of King's Bench of Alberta, and is available for legal proceedings involving cybersecurity matters.
A vulnerability assessment identifies and prioritizes known weaknesses. A penetration test actively attempts to exploit those weaknesses to demonstrate real-world impact. ThreeShield's comprehensive assessments go beyond both - following vulnerabilities through manual expert analysis to discover issues automated tools miss entirely. We frequently find issues that automated tools would score as low-risk but that represent significant real-world exposure.
Yes. ThreeShield provides pre-audit readiness assessments and remediation support to ensure you're prepared for third-party audits. With experience on both sides of the audit table, we know exactly what auditors look for - and where organizations typically stumble.

Not sure what you need?

Audit, penetration test, or vulnerability assessment?

A full audit is the widest lens. A penetration test proves what an attacker could do. A vulnerability assessment gives you broad, regular coverage. Many organizations combine them, and we can help you decide.

Cybersecurity audit

The complete picture: controls, policies, physical security, and technical testing against every applicable framework. You are here.

Penetration testing →

A hands-on, authorized attack that shows exactly what an intruder could reach. Satisfies PCI DSS 11.4, SOC 2, and insurers.

Vulnerability assessment →

Broad, regular scanning with findings validated by hand and continuous Lavawall® monitoring between assessments.

Ready for an audit that
actually finds your risks?

Request an audit proposal. We'll scope the right engagement for your regulatory requirements, risk profile, and budget - with full transparency on what you'll receive.