Security AuditCompliancePenetration Testing

Information Security Audit: Types, Cost and How to Choose a Provider

May 10, 2025 · 10 min read · System Networks

"We need a security audit" is one of the most common requests — and one of the most ambiguous. A technical audit, penetration test, and compliance check are completely different engagements with different outputs and price ranges. Choosing the wrong type means spending ₽500,000 to get something you didn't need.

Five Types of Security Assessment

Technical Security Audit

1–3 weeks₽150,000 – ₽500,000
Scope: Infrastructure, configurations, policies
Output: Report with vulnerabilities by severity
Best for: Most companies; good starting point

Penetration Testing

1–4 weeks₽300,000 – ₽2,000,000
Scope: Specific systems or full scope
Output: Exploited vulnerabilities, attack chains, recommendations
Best for: Companies with mature IS; regulated industries

152-FZ Compliance Audit

2–4 weeks₽200,000 – ₽800,000
Scope: Personal data processing systems
Output: Compliance gaps, remediation roadmap
Best for: All companies processing personal data

CII / 187-FZ Assessment

3–6 weeks₽500,000 – ₽3,000,000
Scope: Critical infrastructure systems
Output: Categorisation, GOSSOPKA readiness, security requirements
Best for: CII subjects (13 regulated sectors)

Red Team Assessment

4–8 weeks₽1,500,000 – ₽5,000,000+
Scope: Full organisation (technical + physical + social)
Output: Full attack scenario, response gaps
Best for: Mature security programmes; banks, critical infra

How to Choose: Decision Flowchart

Never had an audit before?

Start with Technical Security Audit. Establishes baseline before deeper testing.

Process personal data of customers or employees?

152-FZ Compliance Audit is mandatory — not optional. Fines can exceed ₽15M.

Operate in healthcare, energy, transport, or other regulated sector?

CII / 187-FZ Assessment. Criminal liability for non-compliance.

Want to test your defences against a realistic attacker?

Penetration Testing with black-box scope. Requires mature baseline security first.

Need to demonstrate security to enterprise clients or investors?

ISO 27001 implementation + Technical Audit as supporting evidence.

How to Choose a Provider: 8 Criteria

01
FSTEC TZKI licenseMandatory for legally recognised audits in regulated industries
02
Named senior consultant for your engagementNot just a junior assigned last minute
03
Fixed-price contract with defined scopeAvoid open-ended time-and-materials for audit work
04
Report format previewAsk for a sample report from a past engagement (anonymised)
05
Remediation support includedA good provider helps fix what they find, not just list issues
06
IndependenceThe auditor should not sell you the specific products they recommend
07
Experience in your industryHealthcare audits require different expertise than manufacturing
08
NDA and data handling policyAuditors see your infrastructure — they must be contractually bound

Red Flags That Should Stop You

Audit scope described as "full security audit" without specifics — this means nothing
No FSTEC license for regulated industry work
Price dramatically lower than market (₽50,000 for a "comprehensive audit") — you get a checklist, not an audit
No reference clients willing to be contacted
Results promised within 3 days for any significant scope
Provider also sells specific vendor products with high margins

FSTEC-licensed security audit

Security audit and penetration testing by licensed specialists →

FSTEC TZKI · 152-FZ compliance · CII / 187-FZ · Fixed price · Remediation support

Начнём работу

Защитите инфраструктуру до того, как это потребуется

Бесплатная предварительная консультация. Оценка текущего уровня защиты за 1 день. Первые результаты — в течение недели.