Cyber security audit — Auckland & Northland

Find the gaps before someone else does. Fixed fee, plain-English report, and a fix list your team can actually action.

Know exactly where you stand

Most business owners have a nagging feeling about their IT security and no way to test it. A cyber security audit replaces that feeling with facts: what is solid, what is exposed, and what to fix first. We run them for businesses across Auckland, Whangārei and the rest of Northland — and remotely for teams anywhere in NZ, with people on the ground in Wellington and Wanaka too. Because we manage IT and security every day, the report comes with fixes, not just findings.

What we test

Microsoft 365 & identity

MFA coverage, conditional access, Secure Score, admin accounts and mailbox rules.

Devices & patching

Endpoint protection, encryption, patch compliance and end-of-life systems.

Network & firewall

Firewall rules, remote access, Wi-Fi separation and what is visible from the internet.

Backups & recovery

Whether backups exist, whether they work, and whether anyone has ever tested a restore.

Email security

SPF, DKIM and DMARC, phishing protection and payment-fraud controls.

Dark web exposure

Which of your staff credentials are already circulating from past breaches.

How it works

1. Scope

A short call to agree what we are testing and a fixed fee. No surprises later.

2. Test

We assess your environment read-only. No disruption, no downtime, usually done within two weeks.

3. Report

You get the findings in plain English, ranked by risk, walked through with you in person.

What you walk away with

A plain-English report your board can read. A fix list ranked by real risk, not vendor scare tactics. A remediation roadmap with costs. Evidence your cyber insurer will accept. And a clear answer to the question you started with: how exposed are we?

Audited against real standards

We do not mark our own homework against a made-up checklist. Audits are scored against SMB1001, the Essential Eight, CIS Microsoft 365 Foundations and the NIST Cybersecurity Framework — and if you want to go further, the audit is the first step towards SMB1001 Gold certification.

What it costs

A fixed fee, agreed before we start, scoped to the size of your business — not an open-ended engagement that grows an invoice every week. Book a scoping call and you will have a number the same day.

Questions we get asked

How much does a cyber security audit cost in NZ?

It depends on the size of your environment, which is why we fix the fee up front after a short scoping call. You will know the full cost before anything starts.

How long does it take?

Most audits run one to two weeks from kickoff to the report walkthrough. Your team barely notices — the assessment is read-only.

Will it disrupt our business?

No. We do not take systems offline or run disruptive scans during business hours. Staff keep working as normal.

Can we not just do it ourselves?

You can self-assess, and it is better than nothing. But an external audit finds the things you have stopped seeing, and insurers and larger customers increasingly want independent evidence.

How often should we audit?

Annually, or after any big change — new premises, a merger, a move to new systems, or a near miss.

What does this have to do with SMB1001?

SMB1001 is the cyber security certification standard for NZ small and medium businesses. Our audit scores you against it, so certification afterwards is a step, not a second project.

Book your audit

One call to scope it, a fixed fee the same day, and a report you can act on within two weeks.

Contact us today