Foundations
Know exactly where you stand
A Gorilla audit replaces guesswork with a clear, honest picture of your organisation’s cyber security and resilience: what’s working, what’s exposed, and precisely what to do about it.
Cyber security shouldn’t be an afterthought — and “we think we’re probably fine” isn’t a strategy. You can’t protect what you can’t see, so a Gorilla audit starts by helping you see clearly. We’ve refined this process over more than a decade specifically for midsize and smaller organisations, and it’s overseen by our Chief Information Security Officer, Stephen Phillips.
It’s mapped to recognised frameworks — the NIST Cybersecurity Framework (CSF 2.0) and the New Zealand Information Security Manual (NZISM) — so your findings line up with standards your board, auditor or insurer will recognise. You won’t get a generic checklist or a wall of alarming red text. You’ll get findings that make sense, ranked by what actually matters to your organisation, and the peace of mind that comes from finally knowing where you stand.
Where to start
Two ways in
The One-Day Audit
The ideal starting point for smaller organisations. In a single focused day, we surface your most significant risks and give you clear, practical next steps — fast, affordable and genuinely useful.
The in-depth audit
For organisations ready for a thorough, end-to-end review across every area that shapes their risk. The right choice when you need real assurance — for your board, your insurer, your customers, or your own peace of mind.
Every audit is scoped to your organisation’s size and risk. We’ll always confirm scope and price upfront, before any work begins.
What we review
The areas that shape your risk
We tailor every audit to your organisation, covering the most critical areas first and working down in line with your risk appetite and budget.
- Identity, access and authentication
- Technical configuration of cloud and local systems
- Endpoint detection and response
- Device management
- Network security
- Email and phishing exposure
- Backup, recovery and business continuity
- Data privacy and handling of sensitive information
- Technology selection and supplier risk
- Processes and proactive maintenance
- Cyber incident preparedness
- Reporting and governance
The outcome
A clear path to a stronger posture
You’ll understand your true cyber security posture — and have a prioritised plan to improve it.