Djtal

Security audit

IT security audit for Swiss companies

A methodical audit of your IT ecosystem: infrastructure, applications, data and access. We identify the vulnerabilities, check the policies in place and hand you a prioritised action plan to carry out in-house or with us.

In brief

What does Djtal's IT security audit involve?

Djtal, the operational AI specialist for Swiss companies, reviews your IT ecosystem in four phases (infrastructure, business applications, data and access) and delivers a report your management can read and a prioritised remediation plan, both owned by you. Systems engineer and co-founder Faisal Al Tayyari leads it in person. The initial audit costs CHF 800 excl. VAT (4 hours).

Why an audit

Why an independent security audit pays off.

01

Identify vulnerabilities before they are exploited

A methodical audit brings to light the technical and human weaknesses, the points of exposure and the blind spots that day-to-day routine makes invisible.

02

Measure your practices against recognised standards

We measure the gap between your practices and recognised standards, point by point, across internal good practice, rights and permissions management, and security policies.

03

Ensure business continuity

The audit identifies which risks could paralyse your operations (a system outage, a ransomware attack, the departure of a key person, a supplier failure) and the order in which to deal with them.

04

Protect your strategic assets

Customer files, price lists, methods and code are what your competitors would like to read. The audit checks who can access them, from where, and what would be left of them after a staff departure or a breach.

05

Strengthen stakeholder confidence

Tenders and major customers increasingly require a documented security policy. Arriving with an audit report and a dated plan means answering before you are asked.

06

Secure your GDPR and Swiss FADP compliance

The audit covers personal data, traceability, individuals' rights and transfers outside Switzerland and the EU. An audit that follows the EU GDPR and the Swiss Federal Act on Data Protection (FADP, in force since 2023) protects your company and your customers. It limits your legal exposure.

Our method

Four phases to give you a clear picture of your security posture.

  1. 1
    Phase 1

    Ecosystem analysis

    • Mapping of the infrastructure: servers, networks, cloud environments.
    • Inventory of business applications: ERP, CRM, websites, internal tools.
    • Review of data and access management.
  2. 2
    Phase 2

    Vulnerability detection

    • Identification of exploitable technical weaknesses.
    • Analysis of human and organisational risks.
    • Assessment of exposure to threats.
  3. 3
    Phase 3

    Security policy review

    • Review of the rights and permissions in place.
    • Examination of internal good practice.
    • Gap analysis against recognised standards.
  4. 4
    Phase 4

    Prioritised action plan

    • Technical and organisational recommendations.
    • A sequenced remediation roadmap.
    • Prioritisation by risk, in line with your business priorities.

What we deliver

A report your management can read, a plan your teams can carry out.

  1. 01

    Audit report

    The overall security posture, the vulnerabilities identified, and the criticality and impact of each. Your management can read it and your technical teams can act on it.

  2. 02

    Tailored improvement plan

    Corrective measures you can apply, prioritised for your business context. We can help you apply them if you wish, with no obligation.

The report and the improvement plan are your property. You can use them with your own teams, another firm or Djtal for the implementation.

Our security lead

One point of contact, from the initial discussion to the action plan.

Faisal Al Tayyari

Djtal co-founder · Systems engineer

At Djtal, security is Faisal's subject.

A systems engineer, Faisal has extensive experience of infrastructure, application architecture and information systems security. Co-founder of Djtal and Laurent Cuénoud's business partner for 30 years, he heads our engineering hub and personally leads every security engagement we take on for our clients.

You deal with him directly at every stage, with no sales intermediary.

Our scope

The full scope, from infrastructure to access.

An IT security audit is a structured review of your infrastructure, business applications, data and access that ends in a prioritised action plan. Our own rules for handling data are published in our privacy policy. For a self-hosted ERP, data sovereignty is covered on our Odoo page. For an AI agent project, the guarantees for your IT department have a dedicated page.

Infrastructure

We examine servers, networks, cloud environments and workstations, the technical foundations your business rests on.

Business applications

We examine ERP, CRM, websites and internal tools, the systems that carry your day-to-day operational processes.

Data and access management

Storage, backups, rights, authentication and traceability. We check who accesses what, and what is done with it.

Pricing

CHF 160/hour

excl. VAT · implementation as capped time and materials · CHF 1,280/day

  • Initial security audit · CHF 800 excl. VAT (4 hours, or half a day). It defines the scope, assesses criticality and sets out the priority actions. A tailored scope for the extended audit is provided afterwards.
  • Extended audit · CHF 200/hour excl. VAT (CHF 1,600/day, strategic advisory tier). Fixes are implemented as capped time and materials, so you pay for the hours used, within a budget cap agreed up front.
  • Scoping and a quote come first. Before work starts, Faisal gives you an estimate of the hours expected for your scope.
  • A non-disclosure agreement is signed at the outset. All client data stays strictly within the scope of the audit.
  • 8.1% Swiss VAT is added.
Request a quote

Frequently asked questions

Your questions about the security audit.

How much does an IT security audit cost in Switzerland?

At Djtal, the initial security audit costs CHF 800 excl. VAT (4 hours, or half a day). It defines the scope, assesses criticality and sets out the priority actions. The extended audit is then carried out at the strategic advisory tier, CHF 200 an hour excl. VAT (CHF 1,600 a day), with an estimate of the hours involved supplied before work starts. Implementing the fixes is billed as capped time and materials at CHF 160 an hour excl. VAT. 8.1% Swiss VAT is added.

What does an IT security audit cover?

Djtal's audit covers three areas: infrastructure (servers, networks, cloud environments, workstations), business applications (ERP, CRM, websites, internal tools) and data and access management (storage, backups, rights, authentication, traceability). It runs in four phases, from mapping to the prioritised action plan.

Who carries out the security audit at Djtal?

Faisal Al Tayyari, systems engineer and co-founder of Djtal, personally leads every security engagement, from the first listening session to the delivered action plan. You deal with him directly, with no sales intermediary. A non-disclosure agreement is signed at the start of every engagement.

Does the audit cover GDPR and Swiss FADP compliance?

Yes. The audit checks how personal data is handled and traced, how individual rights are upheld and which data is transferred outside Switzerland and the EU, in line with the EU GDPR and the Swiss Federal Act on Data Protection (FADP, in force since 2023). It limits your legal exposure as well as your technical exposure.

Should we host our data in Switzerland or in Europe?

Data sovereignty has become a buying criterion, with 62% of European organisations looking for sovereign solutions (McKinsey, 2026). Djtal's audit maps where your data and backups are stored, who can access them and which transfers leave Switzerland or the EU. It then gives you a plan to bring your hosting into line with your FADP and GDPR obligations. For sensitive components, Djtal favours European hosting.

What do we receive at the end of the audit?

Two deliverables: an audit report (overall security posture, vulnerabilities, criticality and impact, readable by management) and an improvement plan prioritised for your business context. Both documents are your property, and you can implement the plan in-house, with another firm or with Djtal.

Speak directly with Faisal Al Tayyari.

Start with a conversation about your context, your concerns and the areas you are unsure of. At the end, Faisal tells you whether an audit makes sense for you and proposes a scope suited to your environment.

Last updated: