Enterprise-wide 360° risk assessments across physical, cyber and third-party domains.
We evaluate the full risk surface of your organisation, from perimeter security and access control to network posture, application security and third-party exposure, and translate findings into board-ready decisions and prioritised remediation roadmaps.
Delivered onsite or remotely worldwide by AACL Global (Audits and Assurance Consult Ltd), headquartered in Nairobi, Kenya, for organisations across Africa and international markets.
We evaluate the full risk surface of your organisation, from perimeter security and access control to network posture, application security and third-party exposure, and translate findings into board-ready decisions and prioritised remediation roadmaps.
AACL delivers integrated 360° assessments that combine physical security review, cybersecurity posture analysis and Vulnerability Assessment & Penetration Testing (VAPT). Our engagements are structured around ISO 31000 risk principles and calibrated to your regulatory environment, threat profile and business priorities.
Assessments are executed by a multi-disciplinary team of security engineers, ISO lead auditors and former corporate security leaders. Every finding is contextualised. We do not simply hand over a tool output; we quantify likelihood, business impact and mitigation cost so executives can make defensible investment decisions.
We work alongside your teams throughout the assessment lifecycle: scoping and asset discovery, controlled testing, evidence-based reporting, mitigation planning, and follow-up validation. The result is a durable improvement in resilience. Not a one-off report.
The conditions that bring organisations to AACL.
- 01Fragmented visibility across physical premises, IT estate and third parties
- 02Regulatory pressure from data protection, financial services and industry-specific regimes
- 03Undocumented shadow infrastructure and legacy systems accumulating unmanaged risk
- 04Board-level demand for quantified, prioritised risk reporting
- 05Vendor and supply-chain exposure with limited assurance mechanisms
A structured, evidence-based delivery model.
Scoping & context
Business-driven scoping workshop to define assets, threat scenarios, testing rules of engagement and success criteria.
Discovery & profiling
Asset inventory, network mapping, physical walk-through, control baseline and stakeholder interviews.
Assessment & testing
Controlled VAPT, configuration review, physical intrusion testing, third-party questionnaires and evidence collection.
Analysis & prioritisation
Risk quantification against ISO 31000 / NIST SP 800-30, mapped to business impact and treatment cost.
Reporting & roadmap
Executive summary, technical findings, prioritised remediation roadmap and board-ready dashboard.
Validation & continuous improvement
Remediation support, control retesting and integration into your ongoing risk management cycle.
What you receive.
- Executive risk report with quantified heat map
- Technical findings register with reproducible evidence
- Prioritised remediation roadmap with cost and effort estimates
- Third-party risk register
- Board briefing pack and stakeholder presentation
- Post-remediation validation report
