Cyber Security Audit Services

Security audit services that help identify risks, ensure compliance, and support your organisation's business continuity.

Gabrielius Vinciūnas

Head of Information Security

Vitalis Kavaliauskas

Chief Technology Officer

Cyber Security Audit Offers

Information and cyber security audit

We conduct cyber security audits in accordance with ISO/IEC 27001, the Law on Cyber Security, and Cyber Security Requirements Description requirements. The audit is carried out by certified (CISM, CISSP) auditors recognised by the NCSC.
Assessment of compliance with ISO 27001, the Lithuanian Law on Cyber security and related legal acts, including the Cyber Security Requirements Description, as well as other information security standards or directives.
Assessment of the Information Security Management System (ISMS).
Assessment of the adequacy of organisational and technical security measures.
Audit report identifying non-compliances and security gaps.
Corrective action plan.
Handover of documents and presentation of results to the organization's management.
Deliverables:
A comprehensive audit report with clear recommendations, ready for use in internal processes and, if needed, for submission to the NCSC.

Information security risk assessment

We conduct information security risk assessments in accordance with ISO/IEC 27005, the NCSC methodology, and ISO/IEC 27001. Managers of state information resources and critical infrastructure entities are required to submit this assessment to the NCSC on a periodic basis.
Overview of information assets.
Assessment of confidentiality, integrity, and availability (CIA) impact.
Review of information security controls.
A practical risk register with prioritisation.
Identification of security gaps and vulnerabilities.
Risk management plan with priorities and an implementation timeline.
Deliverables:
A risk assessment report and a risk management action plan with implementation priorities, ready for submission to Cybersecurity Information System.

Cloud security assessment

Configuration and control review of Azure, AWS, GCP and Microsoft 365 environments, benchmarked against cloud-specific standards and mapped to your regulatory obligations.
Identity and access review – privilege escalation paths, workload identities, analysis of JML and app consent grants.
Logging, monitoring and alerting readiness.
Control-plane and tenant configuration against CIS Benchmarks and provider baselines.
Data sovereignty and encryption standards.
Resilience, backup and exit strategy.
Deliverables:
Technical findings report with prioritised remediation actions, mapped to ISO 27001, CSA CCM and NIS2 or DORA obligations.
Process-automation

Cyber security audit for power plants (>100 kW)

An independent cyber security audit of control systems for electricity generation and energy storage facilities, ensuring compliance with Article 73³ of the Lithuanian Law on Electricity.
OT/ICS control system and network architecture assessment.
Vendor, installer and manufacturer cloud connectivity, including remote control exposure from high-risk jurisdictions.
Logging, retention and monitoring of the control system.
Identification of risks and non-conformities in accordance with the methodology of the NCSC.
The ability to meet compliance requirements using CISO services.
Deliverables:
Independent audit report and remediation plan supporting your security compliance declaration to ESO (distribution-connected) or LITGRID (transmission-connected).

Our Cyber Security Assessment Process

01

Scoping & context definition

We define the assessment scope by aligning business objectives with your operational and regulatory context.
02

Information assets' identification

We identify and map key information assets through system reviews, stakeholder interviews, and existing documentation.
03

Threat & vulnerability analysis

We analyse threats and vulnerabilities through structured assessment, threat modelling, and exposure validation.
04

Score & risk prioritisation

We assess CIA impact, create a risk register, and prioritise risks based on their effect on business continuity.
05

Compliance & control review

We review controls and policies, map them to regulatory frameworks, and assess audit readiness.
06

Remediation plan preparation

We prepare a clear remediation roadmap and treatment plan, prioritising risk mitigation and summarising outcomes in an executive report.

Why Baltic Amadeus

Security & compliance.

Real-world attack simulation.

Support for NIS2, DORA & MiCA ICT requirements.

Certifications

CISM Certified Information Security Manager logo with green circular design and blue text.
CISM
Certification mark for TÜV Thüringen with a red checkmark and a red mask symbol.
ISO 27001
CREST logo with intertwined loops in shades of blue and teal above the word CREST.
CREST
CISSP certification badge with white text on a green rounded square background.
CISSP

Case Studies

FAQ

What is a security assessment, and why does my organisation need one?

A security assessment evaluates risks to your information and systems, helping you identify gaps, reduce exposure, and make informed decisions to protect the business.

How often should a security assessment be conducted?

Most organisations should conduct a security assessment annually or when major changes occur, such as new regulations, systems, or business models.

What is the difference between information security, compliance risk, and cloud security assessments?

Information security assessments look at how information is protected across people, processes, and systems. Compliance risk assessments focus on how well your organisation meets regulatory and standards requirements. Cloud security assessments assess risks specific to cloud environments, such as configuration, access controls, and shared responsibility models.

Related Cyber Security Services

Let’s talk about your project

Starting something new or need support for an existing project? Reach out, and our experts will get back to you within one business day.

Start the conversation

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.