Questions to ask before commissioning a security audit
Ask the right questions before commissioning a security audit. Learn what good answers sound like and what evasive responses reveal about an auditor's approach.
When you're ready to commission a security audit, you face a critical choice: finding an auditor who understands your actual risks, works independently, and will give you answers you can trust. The best way to know whether someone can deliver is to ask them the right questions before you sign anything. This isn't about vetting credentials alone—it's about gauging how they think, what they'll actually examine, and whether they'll be straight with you about what they find.
What they'll test and why it matters to you
Start by asking: "What areas of our business will you examine, and how will you decide which ones to prioritise?" A strong auditor won't give you a boilerplate checklist. Instead, they'll ask you questions first—about your operations, data flows, remote workers, payment systems, third-party integrations, and where you'd be most exposed if something went wrong. They should then explain how they've mapped those conversations to a testing scope. If they've already planned the audit before speaking to you, that's a red flag; they're not tailoring work to your actual environment.
Also ask: "Who will do the testing, and what are their hands-on qualifications?" You want to know whether the auditor will personally conduct the work or whether junior staff will do the legwork under minimal oversight. Ask how many similar audits they've completed for businesses like yours. A vague answer—or one that focuses on credentials rather than practical experience—suggests they may be covering gaps with theory.
Push on methodology too: "How will you test our defences? Will you use automated tools, manual testing, or both?" Automated scanners are fast but can miss logic flaws and complex attack chains. Manual testing is slower but catches nuance. Good auditors combine both and explain why, based on your risk profile. If they only mention one approach, ask why the other isn't needed.
How they'll report and what they'll recommend
Ask: "What will the report include, and how will you prioritise findings?" A useful audit report ranks risks by severity and exploitability, not just by how easy they are to fix. It explains the business impact of each issue, not just the technical flaw. It includes both what's wrong and practical steps to fix it. A weak report lists problems without context—you get a to-do list but no guidance on what actually matters most.
Also clarify: "If we discover something serious during the audit, what happens next? Who do we tell, and what's your role?" A good auditor will explain their process for handling unexpected findings and whether they'll help you contain or investigate. Some issues—evidence of active breach, illegal activity—may require immediate disclosure; ask how they handle that, and whether they'll guide you through it. If they're vague or say "that's your problem," walk away.
Ask whether they'll do a follow-up: "After we've fixed issues, will you retest to confirm the fixes work?" Not all audits include retesting, but it's worth understanding the boundary. Some auditors build it in; others charge extra. Knowing upfront avoids surprise invoices and broken expectations.
Independence and what they won't do
Demand clarity: "Will you sell us remediation work, tools, or managed services after this audit?" This is the crux. An auditor who profits from selling you solutions has a motive to overstate findings or recommend expensive fixes you don't need. Independence doesn't mean they can't suggest vendors—it means they don't take a cut if you hire one. Ask directly whether they have commercial relationships with security vendors they'd recommend. Their honesty here—even if the answer is yes—matters more than the answer itself.
Lastly: "Can you provide references from customers in our sector or of similar size?" Call at least two and ask whether the auditor was thorough, honest about what they found, and reachable if they had questions during fixes.
These questions won't guarantee a perfect audit, but they will reveal whether the auditor is thinking like a partner or like a box-ticker. Once you're confident in your choice, Strove's verified cybersecurity consultants can connect you with auditors who've been vetted for exactly this kind of clarity and rigour.
Common questions
- Should I ask an auditor about their conflicts of interest?
- Yes, absolutely. Ask directly whether they sell remediation services, tools, or managed security services, and whether they have commercial arrangements with vendors they recommend. An auditor who profits from your fixes has a motive to exaggerate findings. Transparency about these relationships is a sign of integrity.
- What's the difference between asking an auditor about 'scope' and 'methodology'?
- Scope is what they'll examine (your networks, applications, employee practices, third-party integrations). Methodology is how they'll test it (automated tools, manual penetration testing, interviews, code review). Both matter because a broad scope with only automated scanning may miss complex risks, while a narrow scope tested thoroughly won't serve your full business.
- How many questions is too many to ask before hiring an auditor?
- There's no upper limit. A good auditor expects detailed questions and welcomes them—it shows you're thoughtful about the work. If an auditor seems impatient or dismissive of your questions during the sales conversation, that's how they'll likely behave during and after the audit.
- What if an auditor won't answer one of these questions directly?
- Treat evasion as a warning sign. If they won't explain their methodology, independence, or reporting process upfront, they won't be transparent during the audit either. Move on to someone who will.
Find a verified provider on Strove
Compare vetted security audits providers, check their credentials, and book or request a quote — all in one place.
Find a Business