Cyber security audit

A cyber security audit in plain English

We check the systems attackers go after first, score them against the Essential Eight and tell you what to fix in order of risk. It starts with a scoping call, and you decide what happens next.

Not sure where you stand? Take the five minute scorecard, or check your email security in seconds.

Two people reviewing a laptop in a dark operations room
150+ organisationsProtected by Austin SecureShield
  • 150+Organisations protected by Austin SecureShield
  • ISO27001 and 9001 certified ourselves, audited externally by Compass Assurance Services
  • 300+Client organisations that trust us with their IT
  • 5,000+Endpoints managed and monitored by our team

Trusted by security conscious businesses across WA

thyssenkruppFLSmidthInterContinental EnergyAlliance NickelCarers WAAcclaim AccountingKoch SolutionsCallidus Process Solutions

01When to audit

The moments an audit pays for itself

The OAIC received 1,205 data breach notifications in 2025, the most since mandatory reporting began in 2018, and 59% came from malicious or criminal attacks. Most businesses book an audit after one of these moments.

  1. Your insurance renewal asks questions you cannot answer

    Proposal forms ask about MFA, backups, patching and incident response. A guess on the form is a risk if you ever need to claim.

    FixAnswers checked against your real settings, with the evidence to back each one.

  2. A client has sent a security questionnaire

    Larger clients now check their suppliers. The questionnaire lands with a deadline and nobody is sure how to answer it.

    FixA report you can use to answer it and a short list of what to fix before you reply.

  3. Staff have come and gone

    Old accounts, shared passwords and forgotten admin rights build up quietly, especially after a busy year of hiring.

    FixA review of every account with access and a list of the ones that should not exist.

  4. Nobody is sure the backups would restore

    Backups run every night, but nobody can say when a restore was last tested or whether an attacker could delete them.

    FixA check of what is backed up, where it goes, how long it is kept and when it was last restored.

02What we check

Six areas, each scored against the Essential Eight

We look where attacks on small and medium businesses usually start. Scoring against the Essential Eight gives the result a meaning your insurer and clients recognise.

01

Microsoft 365 and identity

MFA coverage, conditional access, admin roles, mailbox rules and sharing settings, checked against the Microsoft 365 CIS baselines.

02

Devices and patching

Which laptops, desktops and servers are encrypted, patched, still supported and protected by endpoint detection.

03

Email

Phishing filtering and SPF, DKIM and DMARC records, plus how easily someone could send mail that looks like yours.

04

Backups and recovery

What is backed up, how long it is kept, whether an attacker could delete it and when a restore was last tested.

05

What faces the internet

An external scan with ConnectSecure for open services, old firmware and known vulnerabilities on your public addresses.

06

Policies and people

Joiner and leaver processes, admin habits, security training and whether an incident response plan exists.

Want to know what each Essential Eight strategy means and how to reach the next level?

Essential Eight

03What you get

A report you can act on straight away

No long scan dump. You get three things, written for the person who signs off the budget and the person who does the work.

01

A score you can share

Your result against each Essential Eight strategy, in a summary a director can read quickly and an insurer or client will recognise.

Plain English summary
02

A risk register

Each finding rated by likelihood and impact, with what it affects and what it would take to fix.

Findings ranked by risk
03

A plan in order of risk

Quick wins first, then the larger pieces of work, with a fixed quote if you want us to do them.

No obligation to use us
Harman KaurKrishna MoothooJamie WebbGregory Ashley

Not sure which level you need?

Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote. Or take the scorecard to see where you stand first.

04Audit, health check or pen test

Which review do you need?

Three services that sound alike and answer different questions. If you are not sure, start with the audit.

A cyber security audit compared with an IT health check and a penetration test
CompareCyber security auditThis pageIT health checkWhole IT environmentPenetration testSimulated attack
The question it answersWhere are our security risks and what do we fix first?Is our IT reliable, supported and costing the right amount?Can a skilled attacker get in and how far could they go?
How it worksA review of settings, accounts, devices, backups and policies, plus an external scanA review of servers, network, devices, licensing and supportA specialist testing partner tries to break in under agreed rules
What you getAn Essential Eight score, risk register and planA report on your IT with priorities and costsTechnical findings, fixes and a retest
Best whenYou are unsure where you stand, or an insurer or client is askingYou are reviewing providers, costs or ageing systemsYour controls are in place and someone asks for proof they hold

Swipe the table sideways to compare all three.

Need a broader look at servers, network and support costs as well as security?

IT health checks

05How it runs

Four steps, very little of your time

Most of the work happens in the background. Your team keeps working and nothing is changed without your approval.

  1. Step 1

    Scoping call

    We agree what is in scope, who we talk to and how access is granted and removed.

  2. Step 2

    Data collection

    We review settings and accounts, run the external scan and talk to whoever looks after your IT today.

  3. Step 3

    Findings walkthrough

    We take you through what we found in plain English and answer questions before anything is finalised.

  4. Step 4

    Report and fixed quote

    You get the score, the risk register and the plan. If you want us to do the work, the quote is fixed.

06Proof

What happens after the audit

An audit is only useful if the findings get fixed. These clients started with a clear picture of their gaps.

01

Palisades

Intune, conditional access, Defender, BitLocker, Secure Score and governance documents, aligned to Essential Eight ML1. The work met a prospective client's security requirements and won the partnership.

Read the case study
02

InterContinental Energy

Reached Essential Eight ML1 using the Microsoft 365 Business Premium licences they already had.

Read the case study
03

Held to the same standard

We are certified to ISO/IEC 27001 and ISO 9001 and audited externally by Compass Assurance Services, so your data is handled under the controls we check you against.

Security and governance

Related services

07Recognised and certified

A top 50 MSP in Australia, three years running

Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.

Cloudtango Top 50 MSP in Australia 2026, 2025 and 2024
Top 50 MSP in Australia Cloudtango, 2024, 2025 and 2026. Assessed on client satisfaction, growth and the depth of our security, support and infrastructure services. Read our client reviews on Cloudtango
An Austin Technology engineer working through alerts at his desk
ISO 27001 certified by Compass Assurance Services

ISO 27001

Information security

Our information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.

How we protect your data
ISO 9001 certified by Compass Assurance Services

ISO 9001

Quality management

Support tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.

08Questions

Cyber security audit questions

What people ask before they book. Anything else, call 1300 787 429.

01

How long does an audit take and will it disrupt staff?

Most of the work happens in the background. Staff time is usually one conversation with whoever looks after IT and a short one with a director. We agree the timeline at the scoping call, and nothing in your environment is changed during the audit.

02

What does a cyber security audit cost?

The first security assessment is free. If you need a deeper audit, for example across several sites or with a formal report for a client, we give you a fixed quote before we start. Ongoing protection is priced on our SecureShield plans page.

03

What access do you need and who sees our data?

Usually read only access to Microsoft 365 and your device management, plus permission to scan your public addresses. We agree how access is granted and removed before we start. Findings are shared only with the people you nominate.

04

How is an audit different from a penetration test?

An audit reviews how your systems are set up across the whole business. A penetration test has a specialist try to break in and shows how far they get. Pen testing is a separate engagement, and it is most useful once the audit findings are fixed.

05

We have an internal IT person. Is this a judgement on them?

No. Security settings drift in every business, whoever runs IT. An audit gives your IT person an independent view and a costed plan they can take to the directors, and we can work alongside them on the fixes.

06

Do we have to use Austin to fix the findings?

No. The report is yours and is written so your own team or current provider can act on it. If you want us to do the work, we quote it at a fixed price first.

09Cyber security audit

Find out where
you really stand.

Tell us what your insurer, clients or board are asking for. A technical consultant will scope the audit with you and send a fixed quote before any work starts.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.