A cyber security gap assessment is a structured check of where your security practices stand today against a recognised framework — Australia's Essential 8, NIST CSF or ISO 27001 — compiled into a report of findings and priorities that a non-technical owner can actually read. It is not a pass/fail exam and not a penetration test: nobody attacks your systems during one. This walkthrough covers exactly what happens, stage by stage, so you know what you are signing up for before you start.
Key takeaways
- A gap assessment measures current practice against a framework and produces a ranked fix list — not a certificate and not a fail.
- Five stages: scoping, guided questionnaire, evidence review, framework mapping and scoring, then the report.
- The questionnaire itself takes most businesses one to two hours; the full assessment typically wraps within two weeks.
- Findings usually cluster around multi-factor authentication, patching, backups, email security and phishing awareness — the baseline the Australian Signals Directorate's Essential 8 prioritises.
- The report is the start, not the finish: the human-risk gaps it surfaces are closed with ongoing security awareness training and phishing simulations, not a one-off memo.
What a gap assessment is — and is not
A gap assessment answers one question: "where do we stand against the practices a framework expects, and what are the biggest gaps?" It is a guided questionnaire plus evidence review, scored and mapped to a framework, and delivered as a branded report of findings and priorities.
What it is not:
- Not a penetration test. A pen test simulates an attack against your systems. A gap assessment interviews and reviews — nothing is exploited.
- Not an audit. An audit checks compliance against a standard for certification. A gap assessment is a snapshot you own, usually run before an audit rather than instead of one.
- Not a product sales pitch in disguise. A good one produces findings that stand on their own, whether or not you buy anything from the assessor.
Stage 1: Scoping (30 minutes)
The assessor — or a self-guided platform — establishes the shape of the review: how many staff, what systems you run (email, accounting, file storage, devices), what data you hold, and any client or regulatory obligations. This decides which framework mapping makes sense. Australian small businesses most often map to the Essential 8 because the Australian Signals Directorate designed it as a practical baseline, while businesses with European or enterprise clients may be asked for ISO 27001 or NIST CSF coverage.
Stage 2: The guided questionnaire (1–2 hours)
The core of the assessment is a maturity-style question set. Questions are graded, not yes/no — each asks how regularly something happens, on a scale from "not consistently applied" to "automated and verified." For example:
- How are application patches deployed across workstations, and how quickly after release?
- Is multi-factor authentication enforced on email, remote access and admin accounts — for all users or only some?
- How are backups performed, and has a restore ever been tested?
- Do staff receive recurring phishing simulations and security awareness training, and is completion tracked per person?
- How are bank-detail or payment changes verified before money moves?
- Who has admin access, and when was that list last reviewed?
You can complete it yourself or walk through it with the assessor in a session — the findings compile either way.
Stage 3: Evidence and verification
For each answer, light evidence confirms the practice is real: a screenshot of the MFA policy, a backup restore log, a recent phishing simulation result. This stage is what separates a gap assessment from a self-assessment survey — claims are checked, and maturity levels are scored on what can be shown, not what was remembered.
Stage 4: Framework mapping and scoring
Your answers are mapped to the chosen framework's controls — the Essential 8's eight mitigation strategies, NIST CSF's functions, or ISO 27001's Annex A — and each area is scored from Level 0 (not applied) to Level 3 (automated, verified, reviewed). The output is a maturity score per control area plus an overall score, so you can see at a glance that patching sits at Level 2 while backups sit at Level 0.
Stage 5: The report and priorities
The assessment compiles into a branded report a non-technical stakeholder can read: overall score, per-area maturity, the gaps ranked by risk, and recommended next actions. A useful report names the two or three fixes that reduce the most risk for the least effort — typically enforcing MFA everywhere, verifying backups restore, and standing up recurring phishing simulations with auto-enrolled remediation training.
What happens after the assessment
The report is only useful if it triggers work. The highest-leverage sequence for most small businesses:
- Close the technical quick wins first — MFA coverage, patching cadence, backup restore tests. These are configuration changes, not projects.
- Measure the human layer. The assessment flags training gaps; a monthly phishing simulation programme quantifies them. The benchmark that matters: an average 80% reduction in clicked links within eight months on monthly cadence — see how often you should run phishing simulations.
- Track movement monthly. Rolling assessment findings, training completion and phishing behaviour into one view — what human risk reporting is built for — turns a one-off snapshot into a trend your leadership or clients can see improving.
- Re-assess in 6–12 months to prove the gaps closed.
How long the whole thing takes
| Stage | Typical time |
|---|---|
| Scoping | 30 minutes |
| Questionnaire | 1–2 hours (self-guided or facilitated) |
| Evidence review | 1–3 days |
| Scoring and report | 2–5 days |
| Total | Under two weeks end to end |
FAQ
What is a cyber security gap assessment? A structured assessment of where an organisation's security practices stand, scored against a framework such as the Essential 8, NIST CSF or ISO 27001 and compiled into a report of findings and priorities.
Is a gap assessment the same as a penetration test? No. A penetration test simulates attacks against your systems. A gap assessment reviews practices through a questionnaire and evidence — nothing is attacked or exploited.
Which framework should a small Australian business use? The Essential 8 is the usual starting point because the Australian Signals Directorate designed it as a practical prioritised baseline; ISO 27001 or NIST CSF mappings matter when clients or contracts require them.
Who fills in the assessment? The business owner or IT lead — it is a guided questionnaire you can complete yourself or walk through with the assessor in a single session.
How often should we repeat it? Every 6–12 months, or after a major change such as new systems, rapid headcount growth or an incident. Repeat assessments are also how you evidence improvement to clients and insurers.
Related guides
- Gap Assessment
- Security awareness training
- Phishing simulations
- Human Risk Reporting
- What to do when an employee clicks a real phishing link
Sources
- Australian Signals Directorate: Essential Eight, accessed 29 September 2026.