A cyber security gap assessment tells you three things in one sitting: which controls you already have, which are missing, and what to fix first. Most small businesses skip it and buy security tooling in the order vendors call them. The gap assessment reverses that — you start from what an attacker would actually exploit. The need is not theoretical: Australian organisations reported more than 84,700 cybercrime incidents to ASD in FY2024-25, one every six minutes, and the human element sits behind roughly 60% of breaches according to Verizon's 2025 Data Breach Investigations Report. Here is how to run one properly in 2026.
What a gap assessment is (and is not)
A gap assessment is a structured self-check against a recognised framework — the ASD Essential 8, SMB1001, ISO 27001 — that produces a scored list of gaps. It is not:
- A penetration test, which attacks your systems rather than measuring controls.
- An audit, which certifies compliance rather than finding the fastest path to resilience.
- A product recommendation exercise. If the output of your assessment is a shopping list, it was run by someone selling something.
The honest output is a ranked list of gaps with effort estimates — including the uncomfortable ones, like staff who cannot spot an invoice fraud email.
What a good assessment covers
| Control area | The question it answers | A typical small-business gap |
|---|---|---|
| Identity and access | Is MFA enforced everywhere, including admin accounts? | MFA on email but not on the accounting platform |
| Email security | Are inbound lures filtered, spoofing blocked, and staff tested? | No DMARC policy, no phishing testing |
| Backups | Are they tested by restore, not just by job success? | Backups run nightly; nobody has restored one in two years |
| Patching | Are devices and apps patched on a defined cycle? | Servers patched; laptops on whatever updates arrive |
| People | Can staff recognise and report a phishing email? | No training since onboarding, no simulations |
| Policies | Do written policies exist that match what people actually do? | A template acceptable-use policy nobody has read |
| Incident response | Does anyone know the first three steps after a ransomware note appears? | The plan is: call the IT person, who has no plan either |
That last column is the realistic picture for a business that has never been assessed. None of those gaps is exotic, and each one maps to a framework control you will eventually be asked about by a client, an insurer or a certification body.
Step 1: Scope it and inventory what you have
List what the business actually runs: email platform, identity provider (Microsoft 365 or Google Workspace), endpoints, servers, cloud apps, and who has admin access to each. The inventory itself routinely surfaces the first finding — an ex-staff member still holding global admin, or a file server nobody remembers buying.
Step 2: Map it to a framework
Pick one framework and score against it. For Australian small businesses the practical choice is SMB1001 Bronze or the Essential 8; larger or regulated businesses may need ISO 27001. The framework matters less than consistency — a repeatable checklist beats a bespoke one-off questionnaire, because next year's assessment can measure improvement against the same yardstick.
Step 3: Score with evidence, not memory
For every control, record how you know it is in place: a screenshot of the MFA enforcement policy, a backup restore log, a dated training completion report. Controls without evidence get scored as gaps, because in an audit or an insurance claim, undocumented controls do not exist.
Step 4: Test the human layer
This is the step most self-assessments skip, and it is where roughly 60% of the risk lives. A baseline phishing simulation converts the people section of the assessment from a guess into a number: before any training, roughly one in three employees interacts with a phishing email — the 2025 global benchmark measured 33.1% phish-prone, and 36.8% across Australia and New Zealand. Whatever your baseline is, write it down; it is the number your training programme will be judged against.
Step 5: Prioritise by risk and effort
Sort the gaps on two axes: how likely the gap is to cause an incident, and how much work closing it takes. The classic small-business result:
- Enforce MFA everywhere — days of work, blocks the most common account-takeover path.
- Test one backup restore — an hour, and it is the difference between a bad week and a closed business.
- Start monthly training and simulations — a platform subscription, and it attacks the largest single category of breaches.
- Email authentication (SPF, DKIM, DMARC) — a few hours with your IT provider.
- Policies and incident response — templates plus one afternoon.
Step 6: Put it on a calendar
A gap assessment is a rhythm, not a project. Re-run it annually at minimum — quarterly for higher-risk businesses — and track the score the way you track revenue. Human risk reporting keeps the people-layer score current between assessments by tracking training completion, phishing clicks and reporting behaviour continuously instead of once a year.
From gaps to a 90-day plan
The assessment is only worth what follows it. A workable pattern for a small team:
- Days 1-30: the quick technical wins — MFA, email authentication, backup restore test.
- Days 31-60: enrol everyone in security awareness training and run the baseline simulation.
- Days 61-90: close the documentation gaps, brief staff on the incident-response basics, and schedule the next assessment.
Ninety days is enough to move from an unassessed baseline to a defensible position that answers most client and insurer questionnaires.
FAQ
How long does a gap assessment take?
A small business with a single IT provider can complete a structured self-assessment in one to two days, including evidence gathering. A facilitated assessment with a third party runs one to two weeks.
Which framework should we use?
SMB1001 for most Australian businesses of 5-200 staff, Essential 8 where government clients require it, ISO 27001 when a contract explicitly demands certification. Score against what your buyers ask about.
Can we do it ourselves?
Yes, for a first pass — the frameworks are public and the evidence checklist is mechanical. The value of a third party is honesty: it is harder to self-score your own gaps as green when someone else is holding the checklist.
How much does it cost?
Self-assessment costs time. Facilitated assessments in Australia typically run from a few thousand dollars depending on scope — against an average small-business cybercrime loss of $56,000 per incident reported to ASD in FY2024-25, the arithmetic is not close.
What do we do with the results?
Turn the top five gaps into a dated 90-day plan with named owners, and re-score quarterly. An assessment that ends in a PDF nobody acts on is spending money to learn what you already suspected.
One last thing
Before running the assessment, decide who owns closing the gaps. The most common failure mode is not a bad assessment — it is a good assessment whose findings sat in a drawer while the phishing emails kept arriving.