We are Hoek en Blok IT

Independent IT audit and assurance for SaaS, cloud and IT services providers

About Hoek en Blok.IT

Hoek en Blok.IT is the IT audit and assurance practice of Hoek en Blok, founded by former Big Four IT audit professionals. We help SaaS, cloud and IT services providers demonstrate that their information security and privacy controls are structurally in order: through independent SOC 2, ISAE 3402 and ISAE 3000 assurance reporting, and through ISO 27001 certification support.

Our IT audit and assurance services are provided from Hoek en Blok Audit B.V. From this entity, our registered accountants and registered IT auditors (RE) deliver audit and assurance engagements to clients in the Netherlands and abroad.

Why organizations choose Hoek en Blok.IT

Controls framework aligned with your processes

No standard controls framework that insufficiently fits your organization. We align controls with your existing work processes while preserving agility: no endless checklists, but processes that remain workable and products that are demonstrably secure.

Chartered, registered IT auditors

Our teams bring a combined total of more than 30 years of experience in IT audit and advisory. Our auditors are chartered IT auditors (RE and/or CISA).

Specialized in cloud-native architectures and DevOps

We focus on IT security assurance for IT and cloud services providers. That means we understand your complex IT landscape, the risks in your services, and the technical measures that address them.

A committed, long-term partner

We aim for long-term partnerships. Once your assurance report is issued, we stay involved: your controls framework and our support keep pace with your organization, not just the audit moment.

Powered by Hoek en Blok

References

Through our IT audit and assurance services, we focus specifically on cloud service providers and organizations with complex IT landscapes. That focus means we understand the relevant risks in your services, and the controls that address them, before a project even starts.

Grid of 16 company logos (technology/IT firms) including Geldmaat, Ultimo, ISPnext, Arcus IT, Techwolf, Verzuimdata, ECare, LemonTree, TriOpSys, WoningNet, Rapit, Visma Verzuim, Exonet, Trigion, and PinkRoccade Cloud Solutions.

Our approach, in four steps

Achieving your assurance report is a structured process. We guide you through four phases, from defining the scope to a demonstrable, independently audited controls framework.

This approach pays off in three ways: you leverage our cloud and DevOps knowledge to actually improve your product security, you work from one integrated controls framework that keeps your organization agile, and you can give clients and prospects demonstrable assurance that your IT security is properly managed.

Part of Hoek en Blok

In more than thirty years, Hoek en Blok has grown into a consulting organization of around 200 colleagues, operating from two locations in the Netherlands. Our values and principles are still the same as when we first began, which leads to long-lasting relationships with both colleagues and clients.

Let’s talk

Interested in SOC 2, C5 or ISO 27001 for your organization? Get in touch for a no-obligation introduction.

Powered by Hoek en Blok