The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
A representative extract from a comprehensive software audit: the executive dashboard, severity matrix, risk register and remediation roadmap. It shows the structure and quality of the deliverable without exposing any client information.
Subject: Example Ltd order management platform (ASP.NET Core API, Blazor admin portal, Azure SQL, Azure App Service). Purpose: supplier transition. Scope: comprehensive audit, read-only access, interviews with the outgoing supplier.
The platform is broadly well structured and can be taken over by another team without a rebuild. The most significant risks are about control and recovery rather than code: the production subscription is held in the supplier's tenant, restores have never been tested, and deployment depends on one person. These should be addressed before the supplier relationship ends. The runtime reaches end of support in November 2026 and should be upgraded in the next quarter.
Overall recommendation: retain and remediate. Replacement is not justified by the evidence.
Each finding is placed by how likely it is to cause harm and how serious that harm would be for the business. Severity follows the position, then urgency and remediation complexity decide the order of work in the roadmap.
Finding IDs refer to the risk register below.
In a full report each row expands into a detailed write-up. Effort is indicative: S = days, M = weeks, L = months.
| ID | Area | Finding | Evidence | Business impact | Severity | Recommendation | Effort |
|---|---|---|---|---|---|---|---|
| F-01 | Ownership & control | Production Azure subscription sits in the outgoing supplier's tenant; client has no Owner role. | Azure RBAC export; supplier confirmation | A supplier exit could leave the client unable to deploy or recover the service. | Critical | Transfer the subscription to a client-owned tenant before notice is served. | S |
| F-02 | Operational resilience | Database backups exist but no restore has ever been tested. | Backup policy; absence of restore records | Recovery time and data loss in an incident are unknown. | High | Run a controlled restore into an isolated environment; record actual RTO/RPO. | S |
| F-03 | Dependencies & lifecycle | API runs on .NET 8, which leaves support on 10 November 2026. | Project files; Microsoft lifecycle policy | No security patches after that date. | High | Upgrade to .NET 10 (LTS); low code change expected after dependency review. | M |
| F-04 | Security | Connection strings and an SMTP password committed to source control. | Repository history scan | Anyone with repository access, past or present, holds live credentials. | High | Rotate credentials; move secrets to Azure Key Vault; purge from history. | S |
| F-05 | Knowledge risk | Deployment depends on one engineer's local scripts; no pipeline. | Interview; absence of CI/CD definitions | Releases stop if that person is unavailable. | High | Introduce a build and release pipeline with test gates. | M |
| F-06 | Code quality | Order pricing logic duplicated in four places with small differences. | Static analysis; code review | Pricing changes are slow and error-prone. | Medium | Consolidate into one tested pricing service during the next feature change. | M |
| F-07 | Tests | Automated test coverage limited to a small set of unit tests; none on checkout. | Test project review; coverage report | Regressions reach customers before they are noticed. | Medium | Add integration tests around checkout and invoicing first. | M |
| F-08 | Azure cost | Premium App Service plan and SQL tier sized for a peak that no longer occurs. | Cost Management export; utilisation metrics | Avoidable monthly spend; no performance benefit observed. | Medium | Rightsize after a monitored trial; consider a savings plan. | S |
| F-09 | Monitoring | Application Insights enabled but no alerts configured. | Azure Monitor configuration | Failures are reported by customers, not detected. | Medium | Define alerts for failed requests, dependency failures and job errors. | S |
| F-10 | Documentation | No architecture overview; integration with the accounting package undocumented. | Document review; interviews | Slower onboarding for any new team. | Low | Capture an architecture overview and integration runbook during handover. | S |
One evidence-based method, applied to the decision in front of you. Each specialist assessment can run on its own or as part of a comprehensive audit.
An anonymised example built from synthetic findings: executive dashboard, severity matrix, risk register and roadmap.
Tell us about the application and the decision in front of you. We will scope an audit that answers that question, and confirm timescales and access before any work begins.
Discuss Your Software Audit Requirements All Software Audit ServicesCyber Essentials Plus certified · NDA as standard · UK-based team · Microsoft Partner · No obligation to appoint us for remediation