- Job title
- Site Manager
- Sector
- IT services
- Organization type
- cooperative
- Joined
- Jul 2023
- Message
- 86
We are a 14-person logistics consultancy based in London. Four months ago, we migrated our file storage, accounting records, and CRM entirely to cloud infrastructure. We paid an external freelance specialist around 6,500 GBP for the migration. Everything is working fine right now, but once the specialist finished and left, we realized that no retrospective security audit or testing was ever carried out.
Last week, an enterprise client sent over a vendor audit questionnaire requesting the results of our cloud security assessment. I don't have a report, nor do I even know what we're supposed to check. What are the concrete steps we can review internally? Which stages can our in-house IT person handle, and at what point does bringing in an external cybersecurity firm become unavoidable?