Article
What a Cyber Security Audit Covers for Australian SMBs
A cyber security audit for Australian SMBs is not a scare report. It is a ranked map of website, email, cloud, and device gaps you can actually close.
Most Melbourne SMBs do not need an enterprise security theatre. They need a clear answer to four questions: what is exposed, what would an opportunistic attacker try first, what would an insurer or tender ask for, and what should we fix this quarter.
A cyber security audit answers those questions in plain English. This guide explains what typically gets reviewed, the kinds of findings we see (anonymised), how an audit differs from a penetration test, and how the work connects to ASD Essential Eight adoption.
If you want the service scoped for your stack, start with our cyber security audit in Melbourne page or the broader cyber security services overview.
What gets audited
Scope always follows your business model, but for Australian SMBs the practical surface is usually four layers. We document each layer, rate severity, and rank remediation by risk and effort.
Website and public web apps
- TLS configuration, certificate hygiene, and mixed-content issues
- Admin and staging exposure, default credentials, and forgotten subdomains
- CMS and plugin patch currency, form spam controls, and file upload paths
- Headers, cookie flags, and basic injection or XSS signals where in scope
Email and identity
- SPF, DKIM, and DMARC alignment for spoofing resistance
- MFA coverage on Microsoft 365, Google Workspace, and privileged accounts
- Mailbox forwarding rules, shared mailboxes, and dormant admin seats
- Password reset and SSO paths that skip second-factor checks
Cloud and SaaS
- Identity and access: who has Owner or Admin, and whether MFA is enforced
- Storage buckets, shared drives, and public links that should not be public
- API keys, service accounts, and secrets living in repos or chat history
- Backup retention, restore testing evidence, and region residency where relevant
Devices and endpoints
- Patch levels on laptops and servers that touch customer data
- Disk encryption, screen-lock policy, and lost-device response
- Local admin rights, unmanaged BYOD, and remote access tools
- Antivirus or EDR presence versus "we think it is installed"
Not every engagement deep-dives every control. A focused SMB audit prioritises the systems that would actually hurt revenue, privacy, or insurance renewal if they failed.
Sample anonymised findings
These are composite examples from recent Australian SMB reviews. No client names, no unique identifiers.
- Staging site indexed with production data. A forgotten staging hostname accepted the same admin password as production and appeared in search results. Fix: lock staging behind auth, rotate credentials, request deindex.
- DMARC at none with spoofable brand domain. Marketing mail looked legitimate while anyone could forge the domain. Fix: move to quarantine, then reject, after aligning SPF and DKIM.
- Cloud storage folder shared "anyone with the link". Contained invoices and customer emails. Fix: revoke link, migrate to named users, review sharing defaults org-wide.
- Backups existed but restore was never tested. Ransomware readiness looked fine on paper. A restore drill failed on day one. Fix: quarterly restore tests with written evidence for insurers.
- Local admin on every laptop, no disk encryption on two sales machines. High likelihood of credential theft on a cafe Wi-Fi day. Fix: standard user accounts, BitLocker or FileVault, remote wipe readiness.
Good audits turn findings into a ranked backlog: critical this week, important this month, hygiene this quarter. Theatre reports that bury severity under jargon help nobody.
Audit vs penetration test
Teams often ask for a "pen test" when they actually need an audit (or the reverse). The difference matters for budget and for what you can tell an insurer.
| Question | Cyber security audit | Penetration test |
|---|---|---|
| Primary goal | Map controls, gaps, and priorities across systems | Prove specific exploits against an agreed scope |
| Typical depth | Configuration, process, and exposure review | Hands-on exploitation within rules of engagement |
| Best when | You lack a baseline or need insurer-ready evidence | You already hardened and need validation |
| Output | Ranked findings and remediation plan | Exploit proof, impact, and targeted fixes |
Many SMBs should start with an audit. Once MFA, patching, backups, and identity hygiene are in place, a scoped penetration test becomes useful validation rather than an expensive surprise list of basics.
How this links to Essential Eight
An SMB audit often surfaces the same themes as ASD's Essential Eight: patch applications and operating systems, multi-factor authentication, backups, application control, and related strategies. The official Essential Eight Maturity Model on cyber.gov.au is the authoritative control text.
We treat Essential Eight as the technical floor many insurers and tenders recognise. After an audit, some clients move straight into our Essential Eight adoption service. Others start with a light score using the free Essential Eight self-assessment, then book a deeper review.
Read the plain-English maturity guide: Essential Eight maturity levels explained.
Cyber security audit FAQs
How long does an SMB cyber security audit take?
Most focused reviews for a single website plus Microsoft 365 or Google Workspace land in one to three weeks of calendar time, depending on access and how quickly stakeholders answer questions.
Will you break our production systems?
A standard audit is non-destructive configuration and exposure review. Destructive or exploit-heavy testing only happens under a separate, written penetration-test scope.
Do we need Essential Eight before an audit?
No. The audit often tells you how far you are from ML1 and what to prioritise. Essential Eight adoption can follow with a clear backlog.
Who should sit in the kickoff?
Someone who owns IT or the MSP relationship, plus someone who owns customer data and insurance renewals. Decisions stall when only one side is in the room.
Ready to scope an audit?
Book a free Discovery Session. We will confirm scope, access needs, and a fixed quote before any work starts.