Cyber security audit
A cyber security audit in plain English
We check the systems attackers go after first, score them against the Essential Eight and tell you what to fix in order of risk. It starts with a scoping call, and you decide what happens next.
Not sure where you stand? Take the five minute scorecard, or check your email security in seconds.

- 150+Organisations protected by Austin SecureShield
- ISO27001 and 9001 certified ourselves, audited externally by Compass Assurance Services
- 300+Client organisations that trust us with their IT
- 5,000+Endpoints managed and monitored by our team
Trusted by security conscious businesses across WA








01When to audit
The moments an audit pays for itself
The OAIC received 1,205 data breach notifications in 2025, the most since mandatory reporting began in 2018, and 59% came from malicious or criminal attacks. Most businesses book an audit after one of these moments.
- 01
Your insurance renewal asks questions you cannot answer
Proposal forms ask about MFA, backups, patching and incident response. A guess on the form is a risk if you ever need to claim.
FixAnswers checked against your real settings, with the evidence to back each one.
- 02
A client has sent a security questionnaire
Larger clients now check their suppliers. The questionnaire lands with a deadline and nobody is sure how to answer it.
FixA report you can use to answer it and a short list of what to fix before you reply.
- 03
Staff have come and gone
Old accounts, shared passwords and forgotten admin rights build up quietly, especially after a busy year of hiring.
FixA review of every account with access and a list of the ones that should not exist.
- 04
Nobody is sure the backups would restore
Backups run every night, but nobody can say when a restore was last tested or whether an attacker could delete them.
FixA check of what is backed up, where it goes, how long it is kept and when it was last restored.
02What we check
Six areas, each scored against the Essential Eight
We look where attacks on small and medium businesses usually start. Scoring against the Essential Eight gives the result a meaning your insurer and clients recognise.
Microsoft 365 and identity
MFA coverage, conditional access, admin roles, mailbox rules and sharing settings, checked against the Microsoft 365 CIS baselines.
Devices and patching
Which laptops, desktops and servers are encrypted, patched, still supported and protected by endpoint detection.
Phishing filtering and SPF, DKIM and DMARC records, plus how easily someone could send mail that looks like yours.
Backups and recovery
What is backed up, how long it is kept, whether an attacker could delete it and when a restore was last tested.
What faces the internet
An external scan with ConnectSecure for open services, old firmware and known vulnerabilities on your public addresses.
Policies and people
Joiner and leaver processes, admin habits, security training and whether an incident response plan exists.
Want to know what each Essential Eight strategy means and how to reach the next level?
Essential Eight03What you get
A report you can act on straight away
No long scan dump. You get three things, written for the person who signs off the budget and the person who does the work.
A score you can share
Your result against each Essential Eight strategy, in a summary a director can read quickly and an insurer or client will recognise.
Plain English summaryA risk register
Each finding rated by likelihood and impact, with what it affects and what it would take to fix.
Findings ranked by riskA plan in order of risk
Quick wins first, then the larger pieces of work, with a fixed quote if you want us to do them.
No obligation to use us



Not sure which level you need?
Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote. Or take the scorecard to see where you stand first.
04Audit, health check or pen test
Which review do you need?
Three services that sound alike and answer different questions. If you are not sure, start with the audit.
| Compare | Cyber security auditThis page | IT health checkWhole IT environment | Penetration testSimulated attack |
|---|---|---|---|
| The question it answers | Where are our security risks and what do we fix first? | Is our IT reliable, supported and costing the right amount? | Can a skilled attacker get in and how far could they go? |
| How it works | A review of settings, accounts, devices, backups and policies, plus an external scan | A review of servers, network, devices, licensing and support | A specialist testing partner tries to break in under agreed rules |
| What you get | An Essential Eight score, risk register and plan | A report on your IT with priorities and costs | Technical findings, fixes and a retest |
| Best when | You are unsure where you stand, or an insurer or client is asking | You are reviewing providers, costs or ageing systems | Your controls are in place and someone asks for proof they hold |
Swipe the table sideways to compare all three.
Need a broader look at servers, network and support costs as well as security?
IT health checks05How it runs
Four steps, very little of your time
Most of the work happens in the background. Your team keeps working and nothing is changed without your approval.
- Step 1
Scoping call
We agree what is in scope, who we talk to and how access is granted and removed.
- Step 2
Data collection
We review settings and accounts, run the external scan and talk to whoever looks after your IT today.
- Step 3
Findings walkthrough
We take you through what we found in plain English and answer questions before anything is finalised.
- Step 4
Report and fixed quote
You get the score, the risk register and the plan. If you want us to do the work, the quote is fixed.
06Proof
What happens after the audit
An audit is only useful if the findings get fixed. These clients started with a clear picture of their gaps.
Palisades
Intune, conditional access, Defender, BitLocker, Secure Score and governance documents, aligned to Essential Eight ML1. The work met a prospective client's security requirements and won the partnership.
Read the case studyInterContinental Energy
Reached Essential Eight ML1 using the Microsoft 365 Business Premium licences they already had.
Read the case studyHeld to the same standard
We are certified to ISO/IEC 27001 and ISO 9001 and audited externally by Compass Assurance Services, so your data is handled under the controls we check you against.
Security and governanceRelated services
07Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
08Questions
Cyber security audit questions
What people ask before they book. Anything else, call 1300 787 429.
01How long does an audit take and will it disrupt staff?
Most of the work happens in the background. Staff time is usually one conversation with whoever looks after IT and a short one with a director. We agree the timeline at the scoping call, and nothing in your environment is changed during the audit.
02What does a cyber security audit cost?
The first security assessment is free. If you need a deeper audit, for example across several sites or with a formal report for a client, we give you a fixed quote before we start. Ongoing protection is priced on our SecureShield plans page.
03What access do you need and who sees our data?
Usually read only access to Microsoft 365 and your device management, plus permission to scan your public addresses. We agree how access is granted and removed before we start. Findings are shared only with the people you nominate.
04How is an audit different from a penetration test?
An audit reviews how your systems are set up across the whole business. A penetration test has a specialist try to break in and shows how far they get. Pen testing is a separate engagement, and it is most useful once the audit findings are fixed.
05We have an internal IT person. Is this a judgement on them?
No. Security settings drift in every business, whoever runs IT. An audit gives your IT person an independent view and a costed plan they can take to the directors, and we can work alongside them on the fixes.
06Do we have to use Austin to fix the findings?
No. The report is yours and is written so your own team or current provider can act on it. If you want us to do the work, we quote it at a fixed price first.
09Cyber security audit
Find out where
you really stand.
Tell us what your insurer, clients or board are asking for. A technical consultant will scope the audit with you and send a fixed quote before any work starts.