Skip to main content

Cyentrix · FAQ

Questions, answered.

How working with Cyentrix works, what you receive, and how engagements are scoped. Still stuck? hello@cyentrix.com.

Working with us
What exactly do you do?
Cyentrix helps organisations strengthen cyber security — and audit IT General Controls where assurance is needed. Five cyber reviews (cybersecurity & data protection, cloud security & infrastructure, cyber risk & control assurance, business continuity & DR, system & application security) and one IT-audit offer, IT General Controls (ITGC). We also build: Secure Build delivers websites, internal tools, automations and AI workflows with security built in. Every one is scoped and quoted in writing, tested by hand, and re-tested once the fixes land. See Services.
Do you build things, or only review them?
Both. Secure Build is our build service: websites, internal tools, automations, integrations and AI workflows, designed against a threat model first and handed over with documentation and a written risk summary.
Do you certify us for SOC 2 or ISO 27001?
No — and be wary of anyone who says they can from the outside. We get you audit-ready, own the evidence, and sit beside you when the auditor or the buyer’s security team comes. Certificates and attestations come from the accredited body, not from us.
Do I need to buy or install any software?
No. The tooling we use is ours and we run it as part of the engagement. There is nothing for you to license, install or learn.
Who actually does the work?
Our own team. The testing, the verification and the report are done by the people you speak to — you are not handed to a junior after the sales call.
How do we get started?
Tell us what is driving this via the contact form — a blocked deal, an insurer, a board question, or nobody owning security. We will arrange a short call, then come back with a written scope, a timeline and a fixed quote before any work begins. Not ready to talk? Start with the free exposure review.
Scope & engagement
What do you need from us to start?
For an external review, the domains or IP ranges you own and written authorisation to test them. For internal or credentialed work we also need network access and a read-only account. We tell you exactly what is required — and why — during scoping.
Will the testing disrupt anything?
Our default is safe, read-only testing. We do not run destructive tests, and nothing intrusive happens without your explicit written approval and an agreed window. If you have fragile systems, flag them at scoping and we will work around them.
How long does a review take?
Most cyber reviews run 1–3 weeks end to end, depending on scope, plus the re-test once your fixes land. An ITGC audit is scoped to the domains and period in question. We agree the timeline with you up front.
Can you work around our change freeze or business hours?
Yes. Testing windows are agreed during scoping, including out-of-hours or weekend testing where that suits you better.
Findings & reporting
What do we actually receive?
A report in two halves: an executive summary stating the material risks and what they mean for the business, and a technical section with the evidence, affected systems and the specific fix for each finding. Then a call to walk your team through it.
What do “Confirmed”, “Highly likely” and “Potential” mean?
They describe how strong the evidence is. Confirmed means we directly observed or reproduced it. Highly likely means the indicator is strong but the final call needs judgement. Potential means it is an unverified candidate — we tell you that rather than dressing it up. Anything we prove is not exploitable is set aside instead of padding the count.
Why might you report fewer findings than a scanner would?
Because we remove what is not real. A raw scanner reports every version match as a vulnerability; we verify them, discard false positives, and rank what is left by what attackers are genuinely exploiting. A shorter list that you can act on is the point.
Do you help fix things, or just report them?
We stay involved. We walk your team through the findings, answer questions while the fixes are being made, and re-test afterwards to confirm the issue is actually closed rather than just marked done.
Quotes & commitment
How do I get a quote?
Every review, ITGC audit and build is scoped first — the systems, the controls and the depth you need — and then quoted in writing. Tell us what you need and we will come back with a written scope and a quote before any work starts.
Am I committing to anything ongoing?
No. Every engagement is scoped and quoted in writing and ends when the work ends. Repeating a review annually or quarterly is optional and agreed in advance. No automatic renewals.
How often should we be assessed?
It depends on how fast your environment changes. A stable estate may only need a thorough review once or twice a year; anything with frequent deployments or internet-facing change benefits from a quarterly or annual cycle. We will give you an honest recommendation at scoping.
Is the free exposure review really free?
Yes. The free exposure review looks at what is visible from the internet and needs no access to your systems. It is a genuine sample of how we work, with no obligation to continue.
Data & confidentiality
What happens to our data?
Findings and evidence from your engagement are treated as confidential and are only used to deliver your engagement and report. We are happy to sign an NDA before scoping.
Will you name us as a client?
Only if you explicitly agree. We do not publish client names, logos or details without written permission.

Ready when you are

Let’s find what actually matters.

Tell us what is blocking you and we will come back with a scope, a timeline and a fixed quote.

Talk to Cyentrix →