What problem does this audit solve for an SMB?
It identifies gaps that could stop your operation (fraud, ransomware or a data leak) and leaves you a prioritised plan to reduce risk without over-investing.
What exactly do I receive at the end?
A ready-to-use package: an executive summary (for management), prioritised findings, a risk matrix, a staged treatment plan and evidence organised for audits, clients or inspections.
How long does it take and how much work does it require from me?
Usually 4 to 10 weeks. You only need one point of contact and short meetings; we guide the process with a simple checklist so your team is not distracted.
What do I need to start?
A point of contact, a basic inventory (even a partial one) and access to available evidence (backups, configurations, user list, suppliers and tools in use).
How do you prioritise what to fix first?
We prioritise by real risk: impact, likelihood and asset exposure. You get a plan in 3 levels (7–14 days / 30 days / 60–90 days) to see quick improvements without losing rigour.
Does this help with compliance in Chile (Law 21,719)?
Yes. We translate requirements into controls and practical documentation, and leave gaps, owners and baseline evidence to demonstrate progress in an audit or inspection.
Does it work if I have no IT team or my IT is outsourced?
Yes. We coordinate with your IT provider and give you prioritised tasks, clear owners and evidence so you can demand improvements and follow up.
Do you need access to everything or can it be done in a controlled way?
It is done in a controlled way. We define the scope and work with minimum permissions, reviewing only the necessary evidence and keeping a record of what was reviewed.
How do you handle confidentiality and evidence?
Minimum access and only what is needed. If you need it, we sign an NDA. Evidence is organised with an agreed retention period to demonstrate what was reviewed without overexposing anything.
How is the price calculated?
It depends on the scope: critical systems, users, sites, cloud/on-premise and the level of documentation required. We send you a proposal with deliverables, timelines and clear responsibilities.
What happens after the audit?
You can execute the plan with your team or your external IT. If you want, we offer monthly follow-up to validate closures, review new evidence and keep compliance without starting from scratch.
More questions
Why do I need an audit now?
Because the risk is not whether it happens, but when. An audit gives you visibility: what could stop your operation and which actions reduce risk with the best cost/benefit.
Why choose Novas Metrics and not a generic audit?
Because we do not just hand over a report. We leave an executable plan with traceability and defensible evidence for audits and compliance (focused on Law 21,719).
What does the audit include?
A risk assessment + a review of controls and evidence. We deliver prioritised findings, a risk matrix, a staged treatment plan and the baseline documentation to support an audit and compliance.
Is the report understandable for management?
Yes. It includes an executive summary (risk, impact and priorities) and technical annexes with concrete steps for IT or your provider.