Cyber security audit — Auckland & Northland

Find the gaps before someone else does. A plain-English report and a fix list your team can actually action — free if we already manage your IT.

Know exactly where you stand

Most business owners have a nagging feeling about their IT security and no way to test it. A cyber security audit replaces that feeling with facts: what is solid, what is exposed, and what to fix first. We run them for businesses across Auckland, Whangārei and the rest of Northland — and remotely for teams anywhere in NZ, with people on the ground in Wellington and Wanaka too. Because we manage IT and security every day, the report comes with fixes, not just findings.

What we test

Microsoft 365 & identity

MFA coverage, conditional access, Secure Score, admin accounts and mailbox rules.

Devices & patching

Endpoint protection, encryption, patch compliance and end-of-life systems.

Network & firewall

Firewall rules, remote access, Wi-Fi separation and what is visible from the internet.

Backups & recovery

Whether backups exist, whether they work, and whether anyone has ever tested a restore.

Email security

SPF, DKIM and DMARC, phishing protection and payment-fraud controls.

Dark web exposure

Which of your staff credentials are already circulating from past breaches.

How it works

1. Scope

A short call to agree what we are testing and what it will cost. No surprises later.

2. Test

We assess your environment read-only. No disruption, no downtime, usually done within two weeks.

3. Report

You get the findings in plain English, ranked by risk, walked through with you in person.

What you walk away with

A plain-English report your board can read. A fix list ranked by real risk, not vendor scare tactics. A remediation roadmap with costs. Evidence your cyber insurer will accept. And a clear answer to the question you started with: how exposed are we?

Audited against real standards

We do not mark our own homework against a made-up checklist. Audits are scored against SMB1001, the Essential Eight, CIS Microsoft 365 Foundations and the NIST Cybersecurity Framework — and if you want to go further, the audit is the first step towards SMB1001 Gold certification.

What it costs

If we already manage your IT, you pay nothing. The audit and the SMB1001 Gold certification that follows it — normally $500 — are on us. That is deliberate. We are not going to tell you your security is sorted and then ask you to take our word for it, so we pay for someone independent to check it and certify the result.

If we do not manage your IT yet, the price is agreed before we start and scoped to the size of your business — not an open-ended engagement that grows an invoice every week. Book a scoping call and you will have a number the same day.

It puts money back too. We will introduce you to an insurance broker who has arranged a cyber insurance discount for SMB1001 Gold certified businesses — so the certificate we paid for can take a line off your premium.

Not ready for a call yet? Start with the free cyber readiness check. Two minutes, no cost, no sales call — and you will see roughly where you sit against SMB1001 before you talk to anyone.

Questions we get asked

What does a cyber security audit in Auckland actually involve?

Six areas, all assessed read-only – nothing gets taken offline. Microsoft 365 & identity: MFA coverage (multi-factor authentication – the second check on top of the password), conditional access, Secure Score, admin accounts & mailbox rules. Devices & patching: endpoint protection, encryption, patch compliance & end-of-life systems. Network & firewall: firewall rules, remote access, Wi-Fi separation & what’s visible from the internet. Backups & recovery: whether backups exist, whether they work, and whether anyone has ever tested a restore. Email security: SPF, DKIM & DMARC – the three DNS records that stop someone spoofing your domain – plus phishing protection & payment-fraud controls. And dark web exposure: which of your staff passwords are already circulating from past breaches. Your team barely notices it happening.

How much does a cyber security audit cost in NZ?

If we already manage your IT there is no fee at all: we cover the audit and the $500 SMB1001 Gold certification ourselves, because independent certification is the proof we have done our job properly. If we do not manage your IT yet, the price is agreed before we start and scoped to the size of your business – not an open-ended engagement that grows an invoice every week. Book a short scoping call and you’ll have the number the same day, before anything begins. We’ll also introduce you to an insurance broker who has arranged a cyber insurance discount for certified businesses. If you would rather not talk to anyone yet, the free cyber readiness check takes two minutes and costs nothing.

What is the difference between an IT audit and a cyber security audit?

An IT audit looks at your whole technology setup – what you own, what it costs, and whether it still fits the business. A cyber security audit is narrower and deeper: how exposed are you, and what could an attacker actually do. Ours leans security, but you get the IT picture with it – end-of-life systems, licences you’re paying for twice, backups nobody has tested. Most people searching for one want both.

What do IT security audit services actually deliver?

A plain-English report your board can read. A fix list ranked by real risk, not vendor scare tactics. A remediation roadmap with costs against it. Evidence your cyber insurer will accept. And a clear answer to the question you started with: how exposed are we. We walk you through it in person rather than emailing a PDF and disappearing.

How do I choose a cyber security audit company in New Zealand?

Three questions worth asking. What standard are you scoring me against? Ours run against SMB1001 (the cyber security certification standard for NZ small & medium business), the Essential Eight (eight baseline controls published by the Australian Cyber Security Centre and widely used here), CIS Microsoft 365 Foundations and the NIST Cybersecurity Framework – so if a provider is only scoring you against their own in-house checklist, be careful. Is the price agreed before we start? And can you fix what you find, or do I need a second company for that? Plenty of firms will sell you a report. Fewer will stay and do the work.

Do you run cyber security audits outside Auckland?

Yes. We’re a New Zealand business with five offices – Whangārei, North Shore, Mt Wellington, Wellington & Wanaka – and the assessment itself is done remotely, so we run audits anywhere in the country. The report walkthrough is done face to face where we can, and over Teams where that’s simpler.

Book your audit

One call to scope it, a price the same day, and a report you can act on within two weeks. Free if we already manage your IT.

Contact us today