- Job title
- Accounting clerk
- Sector
- Plastic
- Organization type
- 20-person company
- Joined
- Nov 2023
- Message
- 42
Doki · Mobile app · 2023
We are a 10-person tech company based in Moscow providing warehouse management software to corporate clients. For about two months we've been negotiating an annual contract worth 14 million RUB with a major retail group. Just when we thought we had an agreement on everything, their compliance department made an independent "information security audit" report a mandatory condition of the contract.
Our team is small; we've always practiced basic security internally, but we've never gone through a formal audit. Looking into consulting firms, I found prices ranging anywhere from 350,000 RUB to 2,000,000 RUB, with timelines spanning from two weeks to three months.
What does an information security audit actually evaluate in practice and how is this handled for a small business? How do we establish a reasonable audit scope that satisfies the client, and is it truly impossible to close enterprise deals without this report?