Independent audit · Leeds

Prove your data is safe.

Every year someone asks you to show that patient and client data is protected. We answer it once, evidence it properly, and keep the answer current all year.

No charge. No obligation. No access to your systems.

0Critical
4High
3Medium
2Low
1Info
Example findingUSEC-1-3
HighFinding 01No DMARC record published

Without DMARC there is no instruction to receivers about what to do with spoofed mail, and no reporting, so an impersonation campaign against your patients could run without you ever knowing.

Domain examplepractice.co.uk Record not found Checked 5 August 2026

What to doPublish a DMARC record at p=none with an rua address, review the reports, then move to p=quarantine and p=reject.

Owner: Your IT providerEffort: LowDSPT 4.3

The situation

The same question, from six directions

It arrives in different envelopes, but it is always the same: can you show us the personal data you hold is protected, and can you prove it.

Who asksWhenWhat a weak answer costs you
NHS England, via the DSPTEvery year, 30 JuneYour NHS contract is put at risk
Your insurerAt renewalHigher premium, added exclusions, or cover declined
Local authority commissionersEvery tenderScored down or removed from the process
CQC or OfstedAt inspectionA finding recorded against you
A patient or family memberWithout warningA complaint that escalates to the ICO
The ICO, after an incidentRarely, but it happensA reprimand, or a penalty
Version 8 made this harder

The DSP Toolkit moved to outcome-based evidence. Holding a policy is no longer enough; you have to show the control described in it actually operates, and produce the records that prove it. Read our plain-English DSPT guide →

What we check

Four components, one engagement

26 automated technical checks and 59 documentation review criteria, covering all ten National Data Guardian standards behind the DSPT and all five Cyber Essentials controls.

01

Your external attack surface

Everything about your organisation reachable from the internet, assessed without any access to your systems.

  • Encryption, certificates and obsolete protocols
  • Email impersonation: SPF, DKIM and DMARC
  • Browser protections and version disclosure
  • Software running with known vulnerabilities
  • Forgotten test and staging sites still live
02

Cookies, trackers and consent

We load your site in a real browser and record what happens before anyone agrees to anything.

  • What is set on first load, before consent
  • Whether refusing is as easy as accepting
  • Third party trackers and where the data goes
  • Whether your policy matches actual behaviour
03

Your governance documentation

The half no scanner reaches, and where most of the real risk sits.

  • Processing records, privacy notice, retention
  • Supplier contracts and international transfers
  • Breach readiness and access request handling
  • Impact assessments and staff training evidence
  • All ten DSPT standards, plus the version 8 additions
04

Your internal systems

Assessed on evidence your IT provider produces. We check it against the standard and write it up.

  • Boundary firewall and exposed inbound services
  • Device configuration and disk encryption
  • Patching, supported software, malware protection
  • Access control and multi-factor authentication
  • Backup isolation and tested restores

What you receive

A report you can hand to someone

Written to be read by a practice manager, not an IT specialist, and presentable to an insurer, a commissioner or an inspector.

Findings register

Every issue rated by severity and effort, with a named owner: you, your IT provider, or us.

Standards mapping

Each finding tied to the DSPT standard, Cyber Essentials control or UK GDPR article it affects.

Evidence pack

Your supporting documentation assembled, indexed and kept current against expiry dates.

Remediation plan

What to do, in what order, and roughly how long each item takes.

Re-test at 60 days

Written confirmation of everything resolved since. Your record of action taken.

Executive summary

One page your partners or trustees will actually read.

How it works

Six steps, no surprises

1

Scoping call

Thirty minutes. What you hold, who asks you to prove it, what deadline you are working to. No charge and no obligation.

2

Free external audit

We assess your public web and email presence and send you the findings. You see the quality of the work before you spend anything.

3

Written authorisation

Before anything active happens we agree exactly what will be tested, when, and how to stop it. Nothing proceeds until you have signed.

4

Full audit

Two to three weeks. Technical assessment, documentation review and evidence assembly.

5

Report and walkthrough

We talk you through it in plain terms, with your IT provider present if that helps.

6

Re-test and upkeep

Re-test at 60 days. On a retainer we then keep the evidence current and handle the annual submission.

Scope

Clear boundaries, stated up front

We assess and evidence. Your IT provider implements. That division is deliberate, and it is why IT providers tend to welcome us: we take the governance paperwork off their desk and leave them the technical work.

What we do

  • External web and email surface
  • Public facing pages and forms
  • Cookies, trackers and consent
  • Governance documentation review
  • Internal controls, assessed on evidence
  • Standards gap analysis and evidence pack
  • Prioritised remediation plan and re-test

What we refer out

  • Physical security of the premises
  • In-depth manual penetration testing
  • Carrying out the technical fixes
  • Legal advice, or acting as your DPO

Where a client needs penetration testing we introduce them to a CREST-registered partner rather than stretching our own scope.

Investment

Fixed fees, quoted after the call

No hourly rates. We quote a fixed fee once we know the size of your organisation and which standards apply to you.

External audit

Assessment of your public web and email surface, delivered as a written report.

No charge

Full audit

All four components, evidence pack, remediation plan, and a re-test at 60 days.

From £950

Standards readiness

Everything above, plus DSPT or Cyber Essentials evidence assembly and support through to submission.

From £1,500

Ongoing assurance

Continuous monitoring, quarterly re-assessment, evidence kept current, annual submission handled.

From £250 pm

Where you move from an audit onto ongoing assurance, the first months of the retainer are discounted against the audit fee.

Start here

Start with the free external audit

No charge, no obligation, and no access to your systems. You see the quality of the work before you commit to anything.