SECURITY AUDITS & ASSESSMENTS

Your Security Posture.
The Truth, Good or Bad.

Our cyber audit assesses your current security posture and delivers an accurate report on what we find. Good or bad. No fear selling, no sugar coating. Just a clear score, a ranked findings list, and a fix path. Need compliance? We also provide detailed audits for HIPAA, PCI-DSS, and GLBA when required.

0SECURITY POSTURE
SAMPLE ASSESSMENT · BEFORE HFG: 38 → AFTER REMEDIATION: 86
// 01 — THE AUDIT

An Accurate Report. Good or Bad.

We assess your current security posture the way an attacker would test it, then tell you the truth about what we found. If something is working, you'll hear that too. No 200 page PDF that sits in a drawer.

Findings are ranked by real world risk, each with a plain language explanation and a concrete fix, in the order we'd attack them. Two versions, every time: an executive summary your board understands and a technical appendix your IT team can execute line by line.

hfg_audit — findings by severity
CRITICAL3 FINDINGS
HIGH7 FINDINGS
MEDIUM12 FINDINGS
LOW15 FINDINGS
REMEDIATION PATH: 37 FINDINGS · 14 QUICK WINS · PRIORITIZED
// 02 — NEED COMPLIANCE? WE GO DEEPER

Detailed Compliance Audits, When Required

If your industry answers to a regulator, we layer a detailed compliance audit on top of the posture assessment, mapped to the framework you're held to.

HIPAA
HEALTHCARE · PRACTICES · BILLING

Security Rule and Privacy Rule assessment for covered entities and business associates.

  • ePHI storage, access, and transmission review
  • Risk analysis that satisfies OCR expectations
  • Breach notification readiness
PCI-DSS
RETAIL · HOSPITALITY · ECOMMERCE

Cardholder data environment scoping and control assessment against current PCI-DSS requirements.

  • CDE scoping and segmentation review
  • Control gap analysis with ranked fixes
  • Evidence package for your QSA or bank
GLBA
BANKS · CREDIT UNIONS · FINANCIAL

Safeguards Rule assessment for financial institutions, aligned to FTC and examiner expectations.

  • Written information security program review
  • Vendor and third party risk evaluation
  • Examiner ready documentation
// 03 — WHAT WE HUNT FOR

CVEs, Dead Software, and Blind Spots

The audit digs into the things attackers actually use to get in: unpatched vulnerabilities, software past its End of Life, and the systems nobody remembered they had. On prem and in your cloud.

hfg_scan — known exploited vulnerabilities
CVE-2021-44228Log4Shell · app server10.0
CVE-2023-34362MOVEit Transfer · file server9.8
CVE-2017-0144EternalBlue SMBv1 · legacy host8.1
CVE-2023-23397Outlook privilege escalation9.8
CVE-2024-3400Firewall GlobalProtect · edge10.0
hfg_eol — end of life software audit
Windows Server 2012 R2EOL
SUPPORT ENDED OCT 2023 · NO SECURITY PATCHES
Windows 10EOL
SUPPORT ENDED OCT 2025 · NO SECURITY PATCHES
Exchange Server 2016EOL
SUPPORT ENDED OCT 2025 · NO SECURITY PATCHES
Windows Server 2019EOL SOON
EXTENDED SUPPORT ENDS JAN 2029 · PLAN NOW
hfg_scope — software & infrastructure audit coverage

ON PREM

Servers, workstations, and legacy hosts inventoried
Active Directory configuration and privilege review
Patch levels vs known exploited vulnerability catalog
Network segmentation, firewalls, and remote access
Installed software audit, licensed, unlicensed, forgotten

CLOUD

Microsoft 365 and Entra ID configuration review
Azure and AWS exposure, storage, keys, public services
MFA coverage and conditional access gaps
SaaS sprawl and shadow IT discovery
Backup posture, tested, offsite, ransomware resistant
// 04 — THE PROCESS

Five Steps. No Disruption.

STEP 01

Scope

We map your environment, data flows, and the framework you answer to.

STEP 02

Assess

Controls tested by investigators, not checkbox interviews.

STEP 03

Report

Ranked findings, plain language, executive and technical versions.

STEP 04

Remediate

We help you fix what matters first, or hand your team the playbook.

STEP 05

Verify

Reassessment confirms the gaps are closed and your score moved.

TRANSPARENT SCOPE · NO SURPRISE INVOICES

Know Where You Stand.

One conversation to scope it. A clear price before we start. A score, a findings list, and a fix path when we're done.