Noverys Ltd Company No. 16686328 England & Wales

Independent audit & assurance

We tell you what your systems will actually withstand.

Noverys Ltd is a UK-based cyber security audit, penetration testing and compliance consultancy. At the core of what we do is formal information-security certification: every engagement is led by consultants who hold recognised, professionally awarded credentials (CISA, CISM, CRISC, CGEIT, AAIA, AAIR) — not a generic team working from a checklist. We assess, test and evidence the controls that protect your organisation, and write it up the way a regulator, insurer or board expects to see it.

Engagement snapshot
Firm
Noverys Ltd
Registered
England & Wales
Company No.
16686328
Base
Manchester, UK
Engagements
Audit · Pen test · GRC
Contact
info@noverys.co.uk

SVC · Service lines

Three ways we work with you

Audit

Security & Compliance Audits

Independent assessment of your controls against recognised regulatory baselines, led by consultants formally certified to CISA, CRISC and CGEIT level, with a findings register your board can act on.

Test

Penetration Testing

Network, web application and infrastructure penetration tests carried out under a defined scope and rules of engagement, reported with reproducible evidence and remediation guidance.

Advisory

Governance, Risk & Compliance

Practical GRC support — policy design, risk registers, third-party risk reviews and audit readiness — scaled to your size rather than a generic template.

CRD · Consultant credentials

Formal certification is the core of who leads your engagement

These are not frameworks we measure you against — they are formal information-security certifications personally held by the members of our professional team who lead your audit or test:

CISA
Certified Information Systems Auditor — held by our lead auditors
CISM
Certified Information Security Manager — held by our security leads
CRISC
Certified in Risk & Information Systems Control — held by our risk consultants
CGEIT
Certified in the Governance of Enterprise IT — held by our governance consultants
AAIA
Professional credential held by our assurance consultants
AAIR
Professional credential held by our assurance consultants

Which named individual's credentials apply to a given engagement is confirmed in each proposal. See About for our approach.


Service catalogue

Services

Every engagement is scoped in writing before work starts: what's in, what's out, how long it runs, and what you'll receive at the end. Below are our core service lines.

GRC-01 Security & Compliance Audits

An independent review of your organisation's controls against a named standard or framework, carried out by a formally certified auditor. You get a findings register scored by severity, not just a narrative report.

ScopeTypically coversLed by consultant certified
IT general controls auditIT general controls, access management, systems acquisition & change controlCISA
IT risk auditRisk identification, assessment, response and IT risk control monitoringCRISC
Assurance assessmentAssurance and audit assessment against agreed professional standardsAAIA
Assurance reviewAssurance and audit review of controls, processes and reportingAAIR
IT governance auditIT governance framework, strategic alignment, resource & performance managementCGEIT
Third-party / supplier security reviewVendor questionnaires, contractual controls, data-handling practices—
Internal controls auditAccess management, change control, logging & monitoring, incident response—

PEN-01 Penetration Testing

Authorised, scoped testing of your systems to identify exploitable weaknesses before someone else does. Every test runs under a signed rules-of-engagement document and a defined test window.

Test typeWhat we assess
External network penetration testInternet-facing infrastructure, exposed services, perimeter controls
Internal network penetration testLateral movement, privilege escalation, segmentation effectiveness
Web application penetration testAuthentication, session handling, input validation, business-logic flaws
Cloud configuration reviewIdentity & access, storage exposure, logging, baseline hardening

Each test concludes with a technical report (reproduction steps, evidence, CVSS-aligned severity) plus a non-technical executive summary for your board or client.

GRC-02 Governance, Risk & Compliance Advisory

Ongoing or project-based support to build and run the governance layer around your technical controls.

PRC-01 How an engagement runs

StageWhat happens
ScopingWe agree scope, method, timeline and exclusions in writing before any work or testing begins.
FieldworkAudit interviews and evidence review, or authorised testing within the agreed window.
ReportingFindings rated by severity, with reproduction detail (for tests) or evidence references (for audits).
DebriefA walkthrough call to answer questions and agree remediation priorities.
Retest / follow-upOptional verification once fixes are in place.
Data handling during engagements: Any personal data or credentials shared with us for a live engagement are handled under the terms of the engagement contract, not the general website privacy notice. See our Privacy Policy for how we handle general enquiries.

Scope an engagement

Send us a short description of the system, application or organisation you need assessed and we'll come back with a proposed scope.

Contact us

Who we are

About Noverys

Noverys Ltd is a private limited company registered in England and Wales, providing independent cyber security audit, penetration testing and compliance advisory services.

Registered details

Legal nameNoverys Ltd
Company number16686328
Registered inEngland and Wales
Registered officeUnit 7, Initial Business Centre, Wilson Business Park, Manchester, England, M40 8WN
Contactinfo@noverys.co.uk

How we work

We take on a limited number of engagements at a time so that every audit and test is led directly by a formally certified consultant, not handed off to a junior team unsupervised. Scope, method and reporting format are agreed in writing before any fieldwork or testing begins.

Formal certification is central to our activity

Formal information-security certification of the people who lead your engagement is the core of what Noverys offers. Consultants leading engagements personally hold recognised information-security and governance certifications, including CISA, CISM, CRISC, CGEIT, AAIA and AAIR. Which named consultant's credentials apply to a given piece of work is confirmed in the engagement proposal.

Noverys Ltd itself is not an accredited certification body and does not issue these credentials. Where a client requires formal certification of their organisation (for example against ISO/IEC 27001), we prepare them for assessment by an accredited certification body and can advise on selecting one.

Regulatory frameworks we reference

Our audit and advisory work is carried out with reference to recognised frameworks, including:

Confidentiality

Findings from audits and penetration tests — including any vulnerabilities identified — are shared only with the client and are not disclosed to third parties without the client's consent, except where we are legally required to do so.

Want to know more before you scope an engagement?

Email us directly — we're happy to talk through fit before any proposal is written.

info@noverys.co.uk

Get in touch

Contact

This site doesn't run a contact form. Email us directly and tell us what you'd like assessed — we reply from a person, not a ticketing system.

Contact details
Email
info@noverys.co.uk
Company
Noverys Ltd
Company No.
16686328
Registered office
Unit 7, Initial Business Centre,
Wilson Business Park,
Manchester, England, M40 8WN

What to include in your first email

Please don't send passwords, payment-card details or other sensitive data in an initial enquiry — see our Privacy Policy for how we handle information you send us.

Data protection

For information on how we process personal data submitted by email, retention periods, and your rights, see our Privacy Policy below.


Privacy Policy

Last updated: 9 August 2026

Current website configuration: This website has no contact form and does not use cookies, analytics or tracking technologies. Limited technical information, such as IP address, request time and browser information, may be processed automatically by our hosting infrastructure where necessary to deliver and secure the website. All fonts used on this site are hosted on our own server; no connection is made to any third-party font service.

1. Who we are

Noverys Ltd ("Noverys", "we", "us") is the controller of the personal data described in this policy. We are a private limited company registered in England and Wales under company number 16686328.

Our registered office is Unit 7, Initial Business Centre, Wilson Business Park, Manchester, England, M40 8WN.

This policy explains how we handle personal data when you contact us about our cyber security audit, compliance and information-systems risk consultancy services. Privacy enquiries may be sent to info@noverys.co.uk or to our registered office.

2. Personal data we process

The website has no contact form. It displays only info@noverys.co.uk for contact. If you choose to email us, we may process your name, email address, business contact details, organisation, the content of your message, service interests, correspondence and other information you choose to provide.

If a business relationship is established, we may also process business contact, engagement, contract, service-delivery, billing, security and compliance records obtained from you, your organisation, contracts and service activity.

Please do not send passwords, payment-card data, special-category personal data, client secrets or other unnecessary sensitive information through a general enquiry.

3. How and why we use personal data

We use personal data to:

Our lawful bases are legitimate interests in managing enquiries and business relationships, steps requested before a contract, performance of a contract where applicable, and compliance with legal obligations. Where we rely on legitimate interests, we consider necessity, proportionality and the rights and reasonable expectations of affected people.

We do not use personal data for automated decision-making producing legal or similarly significant effects.

4. Website technical data and cookies

We do not use cookies, analytics or tracking technologies. Limited technical information, such as IP address, request time and browser information, may be processed automatically by our hosting infrastructure where necessary to deliver and secure the website. This processing is carried out by our hosting provider as part of ordinary web server operation (for example, connection logs and security protection) and is not used by Noverys for analytics, profiling or marketing purposes.

All fonts used on this website are self-hosted on our own server (noverys.co.uk). No connection is made to Google Fonts or any other third-party font service, and no font-related data is shared with, or requested from, any external provider.

The website does not set or use cookies or similar browser-storage technologies. If this changes, we will update this policy and, where required, provide clear information and obtain valid consent before non-essential technology is used.

5. Sharing personal data

We disclose personal data only where necessary and proportionate. Recipients may include authorised Noverys Directors, providers supporting business email, professional advisers, competent authorities where legally required, and parties needed to establish, exercise or defend legal claims.

Providers are subject to appropriate contractual and confidentiality controls where required. We do not sell personal data.

External websites linked from our site have their own privacy practices. Please review their notices before providing information.

6. International transfers

A business email provider or its infrastructure may process correspondence outside the UK. Before introducing or materially changing a provider, we assess data location and transfer arrangements. Where UK data-protection law restricts a transfer, we use an applicable adequacy regulation, recognised contractual safeguard or another lawful mechanism, together with supplementary measures where appropriate.

You may contact us for information relevant to a particular transfer.

7. Retention

We keep personal data only for as long as needed for the purpose collected, legal and contractual duties, security, dispute handling and the establishment or defence of claims.

A legal hold, active dispute, investigation or other applicable requirement may require longer retention.

8. Security

We use proportionate organisational and technical safeguards, including controlled access, confidentiality requirements, secure configuration, monitoring, backup and incident management. Internet transmission cannot be guaranteed completely secure.

If you believe information sent to or held by Noverys may be at risk, contact us promptly at info@noverys.co.uk.

9. Your rights

Depending on the circumstances, UK data-protection law may give you rights to request access, correction, erasure, restriction, objection or portability, and to withdraw consent where processing relies on consent. Rights may be limited by law and may not apply in every case.

To make a request, contact info@noverys.co.uk. We may ask for proportionate information to verify identity and scope and normally respond within one month, subject to any lawful extension.

10. Data-protection complaints

You may make a data-protection complaint to info@noverys.co.uk. We acknowledge a complaint within 30 days, take appropriate steps to investigate without undue delay, keep you informed where appropriate and tell you the outcome.

You may also complain to the UK Information Commissioner's Office through ico.org.uk. Your right to contact the ICO is not affected by contacting us first.

11. Changes to this policy

We review this policy at least annually and after a material change to the website, processing, provider or applicable law. The current version will be published on noverys.co.uk.