They give you a structure to follow. The work is split into modules, and after each workshop you get a written list of actions with names against them, so I always knew what the next thing was.
They are sensible about scope and know their stuff. We are fully remote, BYOD, no office, and everything runs on managed PaaS. Rather than asking us to produce evidence for controls we don't have, they helped us take things out of scope with a written reason we can confidently show an auditor.
They manage progress, advise on drafting documents and entering them into Vanta correctly. Risk register, tabletop exercise report, management review pack, non-conformity register with root cause analysis. That is a lot of work we got right the first time, saving untold hours of effort.
The internal audit was a real audit. It picked up things Vanta's automated tests hadn't, and we came out of it with findings and actions, including some non-conformities.
Day to day the engagement runs in a shared Slack channel with a named consultant and a project coordinator. Replies are quick, and when our consultant was on leave they put someone else on it.
The team is genuinely a pleasure to work with. They're highly knowledgeable, well-prepared, and approach the audit as a collaborative exercise rather than a checklist. Communication throughout was consistent and clear, timelines were respected, and the deliverables (interview scheduling, evidence tracking, final report) were all well organised. Special mention to the lead auditor and QA reviewer who were responsive, patient with our clarification questions and always constructive in their feedback.
Cognisys is a global cybersecurity services, consulting partner and CREST-accredited penetration testing provider. We turn security from a business blocker into a business enabler, working with fast-growing companies and established enterprises to reduce risk, unlock revenue, and build customer confidence with security programmes that are practical, measurable, and built to scale.