Skip to content

Advisory · NIS2 · Hungary

After the audit: from findings to controls that work

We rank the fixes, name the owners, define what done means and assemble the evidence that proves the controls run. Your team or your provider makes the changes.

Who this is for

Two situations, the same work

Both end in the same place: controls that operate, and evidence that shows it.

  • Findings with a deadline

    The audit closed, the report lists deviations, and the date was not yours to set. The question is what fits, in what order, and what you can actually evidence by then.

  • Documented, not operating

    The policy exists and the process is written down, but it does not always run and leaves nothing behind. That is a finding at the next audit however good the document is.

What you receive

Four things, each of them named

Not "support" and not "advice". These are the documents an auditor will ask for.

  • Remediation register

    Every finding on one line: the gap, the action, the owner, the date, what evidences it, and where it stands.

  • A ranked plan

    What comes first, what comes later, and what that follows from — risk, deadline, and the capacity you actually have.

  • Evidence that it operates

    Not that a policy exists, but that the thing ran: records, logs, test results, approvals.

  • Closure and readiness review

    What is closed, what is open, and what you can show at the next audit.

Example

What a line of a remediation register looks like

An illustration, not client data. The structure is the point: without an owner and a date, a finding is not a task, only a sentence.

FindingActionOwnerDueEvidenceStatus
Annual review of privileged access not documentedIntroduce a review procedure, run the first cycleHead of IT operationsDay 30Signed review recordClosed
Backup restores never testedRestore test on two critical systemsSystem administratorDay 60Test record, screenshotsIn progress
Supplier security requirements not in contractsExtend the contract template, renegotiate critical suppliersProcurementDay 90Signed contract addendaOpen

The rows above are invented examples based on a typical report. They are not a client result and not anonymised real data.

How we work

Four steps, from findings to evidence

The order is the method: first know where you stand, then what fits, and only then introduce anything.

  1. 01

    Findings and current state

    We read the report and establish what is already there, what is half-done, and what rests on a misunderstanding. Not every deviation is the same amount of work.

  2. 02

    Ranked work

    Ordered by risk, deadline and feasibility, with an owner and a date each. What will not fit before the deadline, we say so rather than leave it unsaid.

  3. 03

    Implementation

    Your team or your provider carries out the fixes; we define what "done" means and check that it got there.

  4. 04

    Evidence and readiness review

    We assemble what proves the control operates, and tell you where you stand for the next audit.

What we ask of you

Three things

  • The audit report

    The exact wording of the findings. Without it there is only guessing at what the auditor expected.

  • Decisions on the days they are needed

    Approving the ranking is a dated milestone. If it slips, everything after it slips.

  • Capacity to implement

    We can define a control and verify it; somebody has to introduce it. Where that is tight we say in advance what is at risk.

What happens if you get in touch

A 20-minute conversation, not a proposal

The first conversation goes through the report, the deadlines and your internal capacity, and ends with us saying whether we can help and in what scope. If we cannot, we say that too. A proposal follows only after that, and only if there is something to propose.

This is a service for the Hungarian market, for the work that follows a Hungarian cybersecurity audit. Other countries have their own deadlines and authorities.

FAQ

Frequently asked questions

The questions we hear most often from security and IT leaders.

Something not covered here? Ask us directly

You do, or whoever runs your systems does. We define what “done” means for each finding, put the findings in an order, name the owner, and verify the result before anything is recorded as closed — and changing a firewall rule, starting a review cycle or rebuilding a backup schedule needs somebody with access, which on advisory work is never us. Budget it as two separate things: the implementation effort is yours and it is the larger number; the specification, the sequencing, the verification and the evidence are ours. If your capacity cannot carry the implementation, that is a fact worth establishing on the first call rather than in month two.

It is not a day rate, and there is no hourly meter or end-of-month reconciliation. The work is quoted as a named scope at a named fee, agreed before anything starts, so the figure you take to your CFO is the figure on the invoice. Where what you actually need persistently and materially exceeds that scope, we re-open scope and fee together rather than sending you a larger invoice for the same agreement. Two things move the level: how many people you are, and how many sites you run. What we will not do is print a number for an audit report we have not read — the quote follows the first conversation and stays valid for thirty days, which is long enough to survive a board cycle.

The register covers every finding in your report, wherever the auditor found it; a deviation on a plant network is ranked, owned and evidenced exactly like one in the server room. We do take work on industrial and plant systems, and how it is priced is worth knowing early: that is one-off implementation work, quoted separately, and it does not sit inside an advisory or vCISO flat fee. Bring the findings that touch production to the first conversation and you will be told which of them are engineering work and which are governance, because the two carry very different numbers.

Three roles, and the weight is not evenly spread. An executive sponsor spends little time but on fixed days: approving the ranking is a dated milestone, and if it moves, everything behind it moves. Somebody internal runs it day to day, usually whoever holds IT. Your IT operations people carry the largest share, because each closed finding is a change that has to be made and then demonstrated — and that is the figure that decides whether this is affordable, not our fee. We work it out against your actual findings before you sign, and where the capacity is not there we say which items are at risk instead of planning as though it were.

Nothing, for the first conversation. It runs on what you can say out loud, and no document has to leave your building for us to tell you whether we can help. We sign a non-disclosure agreement before receiving any document from you, or the confidentiality terms are written into the engagement agreement itself — either way it is in place before the report moves rather than after. The enquiry form is deliberately not a route for an audit report and you should not paste findings into it; we agree how the document reaches us once there is something to read. Our own ISO/IEC 27001 certificate, through a UKAS-accredited body, covers how we handle information while we hold it, and the scope statement behind it is the thing to ask for.

The statutory responsibility stays with your management and no adviser can contract it away — we would rather write that on the page than let you buy this believing it moves. What we carry is that the risk is visible early and in writing: the ranking states what will not fit, your approval of it is on the record, and anything deferred is deferred as a decision with a compensating measure rather than quietly dropped. Dealing with the auditor over the wording or the evidence of a finding is inside the work; contact with an authority is inside it only where we also hold the named security officer role. What a supervisory authority does about a missed date is set by the implementing law your audit was run under, and we go through that with you against your own findings rather than print one country’s consequences on a page read in three. A binding view on your exposure is your counsel’s to give. What we will not do is let you plan as though the date were ours to move.

Yes, and that is the normal way in rather than a concession. A bounded first piece is sold as its own named scope: your findings read against what is already in place, what is half-built, and which deviations rest on a misreading of the report rather than on a missing control. It ends in a document you can take to your board, or to a different firm, with nothing owed to us afterwards. You should not have to commit to a programme in order to find out how large the problem is.

Neither is a timetable for your work. The 180-day programme is a different service, for companies that have a date and no audit yet, and the link at the foot of this page goes to it; your remediation runs to the deadline in your findings letter, which is the only clock here. The day numbers in the example register are relative because the example has no client and no deadline to count from — in a real register those cells hold calendar dates, worked backwards from your date and from what your people can deliver. Bring your date to the first conversation and you will get the example read against it.

Named clients are on this site rather than described in the abstract — the client wall on the homepage and the about page carries them — and the sectors we know from the inside are telecommunications, energy and utilities, and banking, which is where our founders spent their careers. What we will not do is put a name and a phone number against your situation before we have spoken. A proposal carries the references that match what you are actually buying, with enough detail to be worth calling. If a reference from a manufacturer of your size is what decides this, say so on the first call and it goes in the proposal.

Ready to get started?

Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.