Cybersecurity Audit
Who must undergo a cybersecurity audit?
Virtually every critical service operator (CSO) listed in this list by NBÚ.
How often?
Usually every two years or after any significant changes in ICT infrastructure, IT management, or cybersecurity systems.
Why perform a cybersecurity audit?
"Because it is mandatory for all critical service operators under §29 of Act no. 69/2018 on cybersecurity ... 😊"
Because it helps organizations identify deficiencies, inconsistencies, and risks, and propose measures to eliminate or mitigate them to an acceptable level!
Who can perform such an audit?
According to §29, paragraph 3 of the Cybersecurity Act, only a certified cybersecurity auditor can conduct the audit.
Does ITACON have such certified personnel?
Yes. We have multiple certified auditors and technical experts who have carried out dozens of cybersecurity audits.
What does this service involve?
Before the audit, the client needs to prepare and send us:
- A request for the audit (the contents are defined in Annex 1 of NBÚ Decree no. 493/2022).
- An authorization letter for the audit (a pre-filled template will be provided by the auditor).
Subsequently:
- We determine the audit duration (in accordance with Annex 2 of NBÚ Decree no. 493/2022) based on the request details.
- We set the audit price based on its duration.
Once we agree on the price, the audit will be conducted as follows, in compliance with NBÚ Decree no. 493/2022:
- A "Kick-off" meeting to explain the process and finalize the audit schedule.
- Conducting the audit through document reviews, on-site verifications, staff and supplier interviews, and checking the implementation status of security measures.
- Drafting the final report and submitting it for comments.
- Incorporating any feedback.
- Conducting a "Kick-out" meeting, presenting findings to management, and delivering the final report.
After receiving the final report, the client must submit it to NBÚ within 30 days!
The final report should also include the CSO's comments on findings and an "action plan" to address identified inconsistencies and risks. Therefore, the audit marks the beginning of implementing corrective measures.
The audit cost is determined based on its duration, as per Annex 2 of NBÚ Decree no. 493/2022. For the smallest organizations, the price usually starts at 3500 EUR.
If you are interested in our services, contact us...
If interested, feel free to contact us at info@itacon.sk. Just leave your contact, and we will get back to you.