Most organisations asking for a cyber security audit want one of three quite different things. Knowing which one you need before you buy saves a great deal of money and disappointment.

This page sets out what an audit covers, what it does not, how long it takes and what you get at the end. If you already know you need one, talk to us directly.

Three things people mean by “audit”

The word covers a wide range in practice, and vendors are not always careful about the distinction.

1. A compliance audit

Assessment against a defined standard: ISO 27001, the Privacy Act 2020, the New Zealand Information Security Manual, or a customer’s contractual schedule. The output is a statement of conformity with findings against specific clauses. This is what you need when a customer, regulator or board is asking for evidence.

2. A technical security assessment

Examination of how systems are actually configured and exposed: patch currency, access control, network segmentation, internet-facing services. The output is a prioritised list of technical weaknesses. This is what you need when the question is “are we actually secure”, not “can we prove we are compliant”.

3. A penetration test

An authorised attempt to exploit weaknesses, not merely observe them. Narrow, deep, and time-boxed. A penetration test is not an audit and will not satisfy a compliance requirement on its own, though the two are often confused and sometimes sold interchangeably.

An audit tells you whether the controls exist and work. A penetration test tells you whether a determined attacker gets through anyway. Organisations frequently buy the second when a customer has asked for the first.

What a compliance audit involves

Assuming the compliance case, which is the most common driver in Auckland, the work runs roughly as follows.

Scoping. Which entities, systems and locations are in scope. This is the single largest cost driver and the one you control. Auditing one product line rather than an entire group can change the effort by more than half.

Documentation review. Policies, procedures, risk register, asset inventory, supplier agreements. Where documentation does not exist, that is itself a finding, and usually the most common one.

Control testing. Sampling to establish whether documented controls operate in practice. A policy nobody follows is worse than no policy, because it evidences awareness without action.

Interviews. Control owners, IT, and whoever actually performs the task. This is where the gap between the documented process and the real one becomes visible.

Reporting. Findings rated by severity, mapped to the relevant clauses, with remediation guidance that is specific enough to act on.

What you receive

  • A findings report mapped to the standard or obligation being assessed, clause by clause
  • Severity ratings with the reasoning behind each, not just a colour
  • Remediation guidance specific to your environment rather than generic advice
  • An executive summary a board can read without translation
  • A working session to walk through the findings, because a report nobody understands changes nothing

How long it takes

For a single-site organisation with a contained scope, fieldwork is typically a matter of days rather than weeks, with reporting following. Multi-site, multi-entity or heavily regulated scopes take proportionately longer.

The honest variable is not our effort. It is how quickly your team can produce the evidence requested. Audits that stall almost always stall waiting on documentation, not on the auditor.

What it costs

Audit cost is driven by scope, not by organisation size. A thirty-person fintech with three cloud environments and a payments integration is more work than a two-hundred-person firm certifying one office.

Rather than publish a number that would be wrong for most readers, we scope first and quote against what is actually in scope. If your driver is ISO 27001 specifically, we have published our readiness and certification cost ranges, which is the closest published figure we have.

One thing worth knowing before you compare quotes: if you need certification rather than assurance, the certification audit must be performed by an accredited certification body independently of whoever prepared you. Any single quote covering both preparation and certification is worth questioning.

New Zealand specifics that affect scope

Privacy Act 2020. Notifiable privacy breaches must be reported to the Office of the Privacy Commissioner. IPP 3A governs disclosure of personal information overseas, which in practice means your cloud hosting and any offshore processing sit in scope whether you intended them to or not.

Minimum Cyber Security Standards. If you are a GCISO-mandated agency, the ten Minimum Cyber Security Standards published on 30 October 2025 apply, assured through Protective Security Requirements reporting. Their stated scope is all business-critical and externally facing systems.

Supplier obligations. Most audits we run in Auckland are triggered by a customer contract rather than a regulator. If that is your situation, bring the contract clause to the scoping conversation. The scope only needs to be as wide as the clause requires, and narrowing it is the fastest way to reduce cost.

Frequently asked questions

Is an audit the same as a penetration test?

No. An audit establishes whether controls exist and operate. A penetration test attempts to exploit weaknesses. A penetration test alone will not satisfy a compliance obligation, and the two are priced and scoped quite differently.

Can you audit us and then certify us?

Not for ISO 27001, and no legitimate firm can. Certification must be performed by an accredited certification body independently of whoever prepared you. We can prepare you, tell you which bodies suit your sector, and support you through their audit.

How much does a cyber security audit cost in Auckland?

It depends on scope rather than headcount, so we scope before quoting. For ISO 27001 specifically, our published readiness range is the nearest guide. Narrowing scope to what your customer or regulator actually requires is usually the largest available saving.

We have never done this before. Where do we start?

With the reason you are asking. If a customer contract is driving it, start with the clause. If a regulator is, start with the obligation. If it is board concern, a technical assessment usually answers the question faster and cheaper than a compliance audit.

Do you work outside Auckland?

Yes, across New Zealand and Australia. Fieldwork can be performed remotely for most scopes, with site visits where physical security is in scope.

Next step

Tell us what triggered the question and we will tell you which of the three types of work you actually need, including if that turns out to be none of them. Get in touch.