A cyber security gap assessment compares the security controls you already have against a standard you need to meet — the Essential Eight, SMB1001 or an insurer's checklist — and ends with a ranked list of what is missing, what each gap risks and what to fix first. Six components make it up: scoping, a control-by-control review, evidence collection, risk scoring, benchmark reporting and a remediation roadmap. Nothing gets fixed during the assessment itself; the roadmap you leave with is the deliverable.
What does a cyber security gap assessment include?
The same six components appear in almost every credible assessment, whether a consultant runs it over several weeks or a guided platform walks a small team through it in days:
| Component | What happens | What you leave with |
|---|---|---|
| Scoping | Systems, data and people in scope are inventoried | An asset and data-flow list |
| Standards benchmark | The chosen standard is broken into individual controls | A control checklist |
| Control review | Every control is rated met, partial or missing | A gap register |
| Evidence collection | Configurations, screenshots and logs are checked, not just promised | An evidence pack per control |
| Risk scoring | Each gap is rated for likelihood and business impact | A ranked risk list |
| Remediation roadmap | Fixes are ordered by risk, effort and dependency | A prioritised action plan |
The evidence step is where cheap assessments fall apart. A control is either demonstrable — configured, tested, dated — or it is a gap. A backup that has never been test-restored is not a working backup control; it is a partial, and partials belong on the fix list with the missing ones.
That ranked list is also the budget instrument. The average data breach costs an Australian small business $56,600 (2024-25 government-reported figures, cited in Cyber Aware's breach-cost guide), and in 2026 most breaches start with an email someone clicked. A gap assessment turns a vague worry — are we secure? — into a finite, dated list of tasks, each with an owner. It tells you which fixes are cheap and urgent, and which can safely wait a quarter.
How the assessment runs, step by step
- Scope and inventory. List every system that holds business data: email, file storage, finance, CRM, laptops, phones — and everyone with access. Forgotten systems surface at this stage more often than anywhere else, which is why scoping comes first.
- Pick the yardstick. Choose the standard that matches your obligation. For the Australian baseline that is the Essential Eight — ASD's eight essential mitigation strategies, each with maturity levels from 0 to 3. For a certifiable small-business mark it is SMB1001, whose tiers start at Bronze.
- Review every control. Each control gets one of three verdicts: met, partial or missing. Partial is where the honest work happens — say so plainly and move on.
- Score the gaps. Rate each gap by how likely the related attack is and what it would cost the business. An unpatched, internet-facing system outranks a forgotten USB port every time.
- Build the roadmap. Order fixes by risk divided by effort. Multi-factor authentication, tested backups and monthly staff training usually land in month one, because they cost little and close the biggest attack paths of 2026.
Gap assessment vs penetration test vs audit
The three get used interchangeably in conversation but answer different questions:
| Gap assessment | Penetration test | Compliance audit | |
|---|---|---|---|
| Question answered | What are we missing? | What can an attacker actually break? | Do we comply on paper? |
| Typical output | Ranked fix list | Exploit write-up | Pass, fail or certificate |
| Best moment | Before spending on security | Once the basics are in place | When certification is the goal |
For a small business the sensible order is gap assessment first, penetration test once the big gaps are closed, and an audit last — when a certificate is the actual goal.
How long does it take and what does it cost?
Scope decides both. A single-standard review for a small team is measured in weeks, not months; add standards, sites and headcount and it stretches accordingly. Cost models differ: consultants quote fixed fees or day rates, and guided platforms bundle assessments into a training subscription — check the current options on Cyber Aware's gap assessment page. Either way, set the quote against the $56,600 average breach before deciding the exercise can wait another year.
How often should you run one?
Annually is the common rhythm, plus after any major change: a new system handling customer data, an office move, a merger or a jump in headcount. Run one before certification attempts and before insurance renewals — insurers ask evidence-shaped questions in 2026, and a fresh gap register answers them in a single document.
What happens after the assessment?
The roadmap converts into projects. Two categories of fix appear on almost every small-business roadmap:
- Close the technical gaps. Multi-factor authentication, tested backups, patching. These belong to your IT provider and usually take weeks, not quarters.
- Close the human gaps. Most incidents start with an email someone clicked. Security awareness training is the fix, and monthly phishing simulations with human risk reporting are the evidence that it worked.
The human fix is also what turns the next assessment's control review into a column of met verdicts — an assessor reads a 12-month training and reporting record as demonstrable evidence, not a promise.
FAQ
What is a cyber security gap assessment in one sentence? A structured comparison of your current security controls against a chosen standard that ends in a ranked list of what to fix first.
Is a gap assessment the same as an Essential Eight self-assessment? No. A self-assessment is you marking your own homework against the Essential Eight's maturity levels; a gap assessment brings evidence discipline to the same exercise and usually spans more than one framework.
Do I need one before buying security tools? Yes — the roadmap prevents the classic 2026 mistake of buying tools for risks you do not have while the big gaps stay open.
Can I run a gap assessment myself? You can run the control review, and many businesses do. The value of an external pass is evidence discipline: it is harder to argue with your own configuration screenshots when someone else is holding them.
Will the assessor need access to our systems? For the evidence step, yes — read-only access or configuration screenshots. A paper-only assessment cannot verify anything.
Does a gap assessment give me Essential Eight compliance? No — it tells you exactly where you stand and what to close. Formal recognition is a separate step, and for most small businesses SMB1001 certification is the realistic target.