Hozit Domain Hosting — Smart technology. Powerful results.010 502 2517 · info@hozit.co.za · 24/7 Support
Level 1 B-BBEE100% Black Owned24/7 SupportSouth African Technology Partner
Independent Technology Risk and Control Assurance

Identify IT risks, strengthen controls and improve compliance readiness

Hozit provides structured IT auditing and compliance services covering governance, cybersecurity, infrastructure, access control, data protection, backups, business continuity, cloud environments, policies and regulatory readiness.

Service Overview

Professional IT support for growing and established organisations

Technology risks can affect business continuity, customer trust, regulatory compliance and financial performance.

An IT audit provides an independent view of whether systems, processes and controls are appropriately designed and operating effectively.

Hozit assists organisations with IT risk assessments, control reviews, evidence collection, compliance readiness, policy development and remediation planning.

Our approach can cover infrastructure, cloud services, cybersecurity, user access, data protection, backups, third parties, incident response, business continuity and governance.

Engagements are tailored to the organisation’s size, industry, systems, risk profile and applicable compliance obligations.

Business Challenges

Common IT problems we help solve

Unclear IT risk exposure

Management may not have a consolidated view of technology risks.

Weak access controls

Users may retain excessive or inappropriate system privileges.

Incomplete policies

Required IT and information-security policies may be missing or outdated.

Poor evidence retention

The organisation may struggle to prove that controls are operating.

Backup uncertainty

Backups may exist without regular testing or reliable restoration evidence.

Cybersecurity gaps

Patch, endpoint, firewall and monitoring controls may be inconsistent.

POPIA readiness concerns

Personal-information handling may not be fully documented or controlled.

Third-party risk

Vendors may access systems or data without sufficient oversight.

Business continuity weaknesses

Recovery plans may be untested or incomplete.

Audit remediation delays

Previous findings may remain open without ownership or deadlines.

What Is Included

Comprehensive managed IT support services

The final scope is tailored to the organisation's users, systems, locations, risks and internal capabilities.

IT audit scoping

Define systems, locations, processes, risks, stakeholders and reporting objectives.

Pre-audit information request

Prepare a structured list of documents, evidence and system records required.

Management interviews

Engage responsible stakeholders to understand processes and control ownership.

IT governance assessment

Review decision-making, accountability, oversight and technology planning.

IT strategy review

Assess alignment between business objectives and technology investment.

IT organisational review

Evaluate roles, responsibilities, segregation of duties and resource capacity.

IT policy review

Assess whether policies are complete, current, approved and communicated.

Procedure review

Evaluate operational procedures supporting key IT controls.

IT risk assessment

Identify, rate and document technology risks and control gaps.

IT risk register development

Create or improve a structured technology risk register.

Control framework mapping

Map controls to selected standards, policies or regulatory requirements.

IT general controls review

Assess access, change management, operations, backups and governance controls.

Logical access review

Evaluate account creation, modification, termination and periodic review.

Privileged access review

Assess administrator, root, domain and elevated account controls.

User access recertification

Support periodic review and approval of user permissions.

Password policy review

Assess password length, complexity, reuse and expiration requirements.

Multi-factor authentication review

Evaluate MFA implementation for key systems and remote access.

Joiner-mover-leaver review

Assess user lifecycle controls for employees and contractors.

Inactive account review

Identify dormant, duplicate or unnecessary accounts.

Segregation-of-duties review

Assess conflicting access and incompatible responsibilities.

Active Directory assessment

Review domain administration, group policy, accounts and security settings.

Microsoft 365 security review

Assess identity, email, collaboration, sharing and administrative controls.

Cloud governance review

Evaluate ownership, configuration, access, logging and cost controls in cloud environments.

AWS control review

Assess selected AWS identity, networking, logging, storage and security controls.

Microsoft Azure control review

Assess selected Azure identity, networking, logging and governance controls.

Endpoint security review

Evaluate antivirus, EDR, patching, encryption and device management.

Server security review

Assess operating systems, hardening, patching, access and monitoring.

Network security review

Review segmentation, firewall rules, remote access and network administration.

Firewall rule review

Assess selected rules for necessity, risk, ownership and documentation.

Wireless security review

Evaluate corporate, guest and administrative wireless controls.

Remote access review

Assess VPN, RDP, remote-support and third-party access controls.

Vulnerability management review

Assess scanning, prioritisation, remediation and exception handling.

Patch management audit

Review patch identification, testing, deployment and reporting.

Configuration management review

Evaluate secure baselines and change control for critical systems.

Change management audit

Assess approvals, testing, segregation, emergency changes and evidence.

Software licensing review

Assess selected software inventory and licensing compliance.

Asset management audit

Review hardware and software inventories, ownership and lifecycle controls.

Mobile-device control review

Assess security and management of smartphones and tablets.

Data classification review

Evaluate how information is categorised and protected.

Data retention review

Assess retention periods, disposal practices and legal requirements.

Data loss prevention review

Evaluate controls limiting unauthorised data transfer or disclosure.

Encryption control review

Assess encryption for endpoints, servers, backups and data transfer.

Email security review

Evaluate anti-spam, phishing protection, SPF, DKIM and DMARC controls.

Backup audit

Assess backup scope, frequency, retention, monitoring and ownership.

Restore testing review

Verify whether recovery tests are performed and documented.

Disaster-recovery audit

Assess recovery plans, priorities, dependencies and testing.

Business continuity review

Evaluate continuity arrangements for technology-dependent operations.

Incident-response review

Assess preparation, detection, escalation, containment and lessons learned.

Security monitoring review

Evaluate log collection, alerting, response and retention.

SIEM control review

Assess selected security event management configuration and use.

Physical security review

Review access to server rooms, network cabinets and critical equipment.

Environmental control review

Assess power, cooling, fire and equipment-protection measures.

Data-centre control review

Evaluate selected physical, operational and security controls.

Supplier risk assessment

Assess security and compliance risks introduced by third parties.

Vendor due diligence

Review selected supplier controls, contracts and assurance evidence.

Cloud supplier review

Assess responsibilities, data locations, access and service continuity.

Service provider SLA review

Evaluate selected service commitments, responsibilities and escalation paths.

Outsourced IT control review

Assess governance and oversight of managed service providers.

POPIA readiness assessment

Evaluate selected personal-information governance and technology controls.

Privacy control review

Assess access, retention, sharing, breach response and data-subject support.

Information officer support

Assist with technical evidence and risk information for privacy governance.

Processing activity review

Support identification of systems and vendors handling personal information.

Data breach readiness review

Assess detection, escalation, notification and evidence preservation.

ISO 27001 readiness assessment

Evaluate gaps against selected information-security management requirements.

ISO 27001 control mapping

Map existing controls to applicable Annex A control areas.

ISMS documentation support

Develop selected policies, registers, procedures and evidence structures.

ISO 22301 readiness support

Assess selected business continuity management capabilities.

COBIT-aligned review

Evaluate selected governance and management practices against COBIT principles.

ITIL process review

Assess selected service management practices and operational controls.

NIST-aligned cybersecurity assessment

Review selected identify, protect, detect, respond and recover capabilities.

CIS Controls assessment

Assess selected safeguards against recognised security practices.

PCI DSS readiness support

Review selected payment-card environment controls and remediation needs.

King IV technology governance support

Assess selected technology governance responsibilities and reporting.

Internal audit support

Provide technical audit capability to internal audit teams.

External audit support

Prepare technical evidence and remediation responses for external auditors.

Tender compliance assessment

Review IT controls and evidence required for procurement submissions.

Customer assurance questionnaire support

Assist with security and compliance questionnaires from clients.

Control design assessment

Determine whether a control is appropriately designed to address the risk.

Control operating-effectiveness testing

Test whether selected controls operated consistently during the review period.

Evidence sampling

Review selected records, logs, tickets and approvals.

Configuration evidence review

Inspect selected system settings supporting control claims.

Audit finding classification

Rate findings according to impact, likelihood and urgency.

Root-cause analysis

Identify underlying reasons for recurring or significant control failures.

Remediation roadmap

Develop prioritised actions, owners and target completion dates.

Management action plan

Document agreed responses and accountability for each finding.

Risk acceptance documentation

Record approved exceptions and compensating controls.

Audit report preparation

Provide an executive summary, findings, ratings and recommendations.

Executive presentation

Present key risks and recommended actions to management or governance committees.

Board and audit committee reporting

Prepare selected technology-risk summaries for oversight structures.

Remediation tracking

Monitor progress against agreed corrective actions.

Follow-up audit

Reassess selected findings after remediation.

Continuous compliance support

Provide scheduled reviews and evidence management assistance.

Policy development

Create selected IT, cybersecurity, privacy and continuity policies.

Procedure development

Document repeatable operational and control procedures.

Control owner training

Train responsible staff on evidence, ownership and control operation.

Audit readiness workshops

Prepare teams for internal, external or certification assessments.

Compliance evidence repository design

Organise policies, records, reports and approvals for efficient retrieval.

Business Benefits

Why organisations choose managed IT support

Improved risk visibility

Management receives a clear view of significant technology risks and priorities.

Stronger controls

Findings and recommendations support practical control improvement.

Better audit readiness

Policies, evidence and ownership are organised before formal reviews.

Reduced compliance exposure

Gaps in privacy, security and governance can be addressed proactively.

Clear accountability

Remediation actions are assigned to owners with target dates.

Improved resilience

Backup, recovery and incident-response weaknesses are identified.

Greater stakeholder confidence

Independent assessment supports customers, auditors and governance structures.

Continuous improvement

Follow-up reviews help confirm that corrective actions are effective.

Our Methodology

From discovery to ongoing improvement

1

Define scope and objectives

Confirm systems, locations, frameworks, stakeholders and reporting requirements.

2

Issue information request

Collect policies, registers, reports, configurations and evidence.

3

Conduct interviews and walkthroughs

Understand processes, responsibilities and actual control operation.

4

Assess control design

Evaluate whether controls appropriately address identified risks.

5

Test operating effectiveness

Review samples, logs, approvals and system evidence.

6

Rate risks and findings

Classify issues according to impact, likelihood and urgency.

7

Validate observations

Discuss preliminary findings with control owners and management.

8

Develop remediation actions

Define practical corrective actions, owners and target dates.

9

Issue final report

Provide executive findings, detailed observations and recommendations.

10

Track remediation

Perform follow-up reviews and confirm closure where required.

Engagement Options

Flexible IT support models

Comprehensive IT audit

Review governance, infrastructure, security, access, backups and operations.

Cybersecurity control assessment

Evaluate technical and procedural cybersecurity controls.

POPIA readiness assessment

Assess selected privacy governance and technology controls.

ISO 27001 readiness review

Identify gaps before certification or surveillance activities.

IT general controls audit

Review access, change management, operations and continuity controls.

Cloud security and compliance review

Assess selected AWS, Azure or Microsoft 365 environments.

Supplier assurance review

Evaluate technology and data risks introduced by service providers.

Continuous compliance support

Provide scheduled testing, evidence reviews and remediation tracking.

Technology Coverage

Platforms and technologies we support

Support is subject to the agreed scope, vendor requirements, licences and available technical documentation.

Microsoft 365 Microsoft Entra ID Active Directory Windows Server Linux VMware Hyper-V AWS Microsoft Azure Firewalls VPN Endpoint Detection and Response Antivirus SIEM Backup Platforms Disaster Recovery Email Security SPF DKIM DMARC Multi-Factor Authentication Encryption BitLocker Mobile Device Management Patch Management Vulnerability Management Asset Management Change Management IT General Controls POPIA ISO 27001 ISO 22301 COBIT ITIL NIST Cybersecurity Framework CIS Controls PCI DSS King IV Risk Registers Control Testing Audit Evidence Compliance Reporting Remediation Tracking
Industries

Managed IT support across key sectors

Why Hozit

A practical technology partner for your organisation

Practical technology expertise

Our recommendations are grounded in real infrastructure, security and support experience.

Business-focused reporting

Findings are explained in terms of operational and organisational impact.

Framework-aware approach

Assessments can align with selected governance, privacy and security requirements.

Actionable remediation

Reports include prioritised steps rather than findings alone.

Independent perspective

Hozit provides objective review outside day-to-day system administration.

Implementation support

Our technical teams can assist with approved remediation projects.

Example Scenarios

How managed IT support can be applied

These are illustrative examples and are not presented as named customer case studies.

POPIA readiness review

A company can assess how personal information is accessed, stored, shared and retained.

Microsoft 365 security audit

Identity, MFA, email, sharing and administrative settings can be reviewed.

IT general controls audit

User access, changes, backups and operational evidence can be tested.

ISO 27001 gap assessment

Existing controls can be mapped against selected certification requirements.

Supplier security review

A service provider’s access, responsibilities and assurance evidence can be assessed.

Remediation follow-up

Previously reported findings can be retested to confirm closure.

Frequently Asked Questions

Managed IT support FAQs

What is an IT audit?

An IT audit evaluates technology risks, processes and controls to determine whether they are appropriately designed and operating effectively.

What areas can an IT audit cover?

It can cover governance, access, cybersecurity, cloud, infrastructure, backups, change management, suppliers and continuity.

Do you perform IT general controls audits?

Yes. We review selected access, change management, operations, backup and governance controls.

Can you help with POPIA readiness?

Yes. We assess selected technical and organisational controls supporting personal-information protection.

Do you provide ISO 27001 readiness assessments?

Yes. We identify selected gaps in policies, risk management, controls and evidence.

Can you help us prepare for an external audit?

Yes. We can review evidence, identify gaps and help organise remediation before the audit.

Do you audit Microsoft 365?

Yes. Selected identity, email, sharing, administrative and security controls can be assessed.

Can you audit AWS or Azure environments?

Yes. Selected identity, network, logging, storage and governance controls can be reviewed.

Do you perform vulnerability assessments?

Vulnerability-management controls and selected technical assessment activities can be included.

Will you test user access?

Yes. Access provisioning, termination, privileged accounts and periodic reviews can be assessed.

Can you review our IT policies?

Yes. Policies can be assessed for completeness, approval, currency and practical implementation.

Do you develop policies and procedures?

Yes. Selected IT, cybersecurity, privacy and continuity documents can be developed.

What evidence is normally required?

Typical evidence includes policies, user lists, tickets, logs, reports, approvals, configurations and test records.

How are findings rated?

Findings are generally rated according to impact, likelihood, control weakness and urgency.

Will we receive a remediation plan?

Yes. Reports can include recommended actions, owners, priorities and target dates.

Can you track remediation after the audit?

Yes. Follow-up reviews and remediation tracking can be included.

How long does an IT audit take?

Duration depends on scope, organisation size, locations, systems and evidence availability.

Is the audit confidential?

Yes. Information and evidence are handled as confidential customer material.

Can you present findings to management or the board?

Yes. Executive presentations and selected governance reporting can be provided.

How do we request a quotation?

Provide the audit objective, systems, locations, applicable frameworks and desired completion date.

Related Services

Build a stronger technology environment

Improve the reliability and security of your IT environment

Speak to Hozit about your users, infrastructure, support challenges and technology priorities.

Request an IT Assessment
Request a Quote WhatsApp