Audit & Assurance

Strong security starts with visibility. Our audit and assurance services review your controls, highlight gaps, and help you build more resilient systems.
Talk to an expert
Uncover security risks

Simplify compliance. Strengthen assurance.

Our audit and assurance services help you meet compliance requirements with confidence from ISO 27001 and PCI DSS to SWIFT CSCF.
Discover our services

Smarter risk decisions start with our audit

From internal risk reviews to certification prep, we offer leading information assurance and security across multiple frameworks so you’re ready for scrutiny at any level.
All of Government Marketplace
We help suppliers meet security and privacy requirements for All-of-Government Marketplace onboarding, including annual assurance deliverables.
All of Government Marketplace
We help suppliers navigate onboarding and annual audit
Digital Identity Services Trust Framework Act
We help digital identity service providers understand and meet obligations under New Zealand’s Digital Identity Services Trust Framework Act.
Digital Identity Services Trust Framework Act
Support for compliance with the Digital Identity Act
ISO 27001
We help you design, implement, and align your security systems to meet ISO 27001 standards so you can achieve certification with confidence.
ISO 27001
ISO 27001 certification made simple
Payment Card Industry (PCI)
We help you assess your PCI DSS readiness, identify gaps in cardholder data protection, and prepare for validation against the applicable compliance level.
Payment Card Industry (PCI)
Get ready for PCI compliance with confidence
SWIFT CSCF
We support SWIFT connected organisations in meeting mandatory and advisory CSCF controls, with independent assessment and practical security recommendations.
SWIFT CSCF
Assess alignment with SWIFT CSCF requirements
Business Manager
Charity
"As a small charity that was the beneficiary of the Hacking for Heroes programme it has been fantastic working with the team at Bastion. The engagement definitely exceeded my expectations and I cannot recommend the Bastion team highly enough."
Service detail

Cyber security audit services delivered by experts.

From real-world control testing to stakeholder-ready reporting, we help you turn audits into meaningful, strategic insight.

Practical insight. Strategic clarity.

Audit & Assurance

Our approach to audit and assurance blends compliance checks with an understanding of your tech stack and threat exposure.

  • Coverage across infrastructure, controls and governance
  • Aligned to ISO, PCI, SWIFT and your own standards
  • Findings prioritised by risk, with clear remediation steps
Our delivery process

Benefits

IT audit and assurance that delivers

We bring clarity, confidence and practical expertise to every information assurance and security engagement, no more jargon.
We build around you
The auditing, assurance and risk processes are directly relevant to you
Certification ready insights
Whether it’s ISO 27001, PCI DSS or SWIFT, we guide you through requirements, remediation and validation.
Want more than just a report?
Expect more than just findings. We translate your audit into insights that you can use.
What comes next

Want to build strong security foundations?

Audits aren't the finish line, they're a chance to improve. Your next steps will be clear, whether it’s remediation, security uplift or an ongoing cyber security audit strategy.

  • Clear roadmap with remediation guidance
  • Recommendations tailored to your risk appetite
  • Access to advisory, technical, and compliance services
Red Teaming
Red teaming simulates real attacks to test your systems, people, and physical security. Our red team penetration testing reveals how well your defences hold up.
Secure Development Training
We train developers and engineers to identify, avoid, and mitigate common security issues — making secure coding part of everyday practice.
Testimonials

Our customers

Look what our customers have to say
Business Manager
Charity
"As a small charity that was the beneficiary of the Hacking for Heroes programme it has been fantastic working with the team at Bastion. The engagement definitely exceeded my expectations and I cannot recommend the Bastion team highly enough."
Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Silverstripe - Cross-Site Scripting (XSS) Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in the administrator panel of Silverstripe CMS, specifically in the handling of the user input within the form messages module.
Silverstripe - Host Header Injection
A Host header injection vulnerability in Silverstripe has been identified that allows an attacker to poison the password rese
Statamic CMS
Sam Schroder found a local file inclusion (write only) vulnerability inside of the upload functionality of Statamic CMS. This affects front end components like forms with `assets` fields.
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

What types of audits does Bastion Security provide?

We offer a range of audit services including ISO 27001 internal audits, PCI DSS readiness assessments, SWIFT CSCF compliance, and tailored risk and control reviews designed to meet both regulatory and internal governance needs.

Can you help us prepare for ISO 27001 certification?

Yes. Our consultants guide you through each stage of the ISO 27001 process, from gap analysis and control implementation to pre-certification readiness, helping you streamline compliance and avoid surprises.

How do PCI DSS assessments work?

Our certified PCI assessors work with your team to review cardholder data environments, identify gaps against PCI DSS controls, and provide a clear remediation roadmap to support full compliance and reduce audit risk.

Do you provide audit support for SWIFT CSCF compliance?

Absolutely. We offer SWIFT CSCF assessments that map your controls against the latest mandatory and advisory controls, provide risk-prioritised recommendations, and support you through remediation and validation.

Is the audit disruptive to daily operations?

No. We aim to conduct our audits with minimal disruption. We’ll coordinate closely to ensure business continuity is maintained.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.