A cyber security gap assessment compares the security controls your business actually has against a recognised framework — Essential Eight, NIST CSF or ISO 27001 — and produces a scored list of the gaps between the two, ranked by risk. It is not a hacking exercise and it is not an audit: it is a structured look at your defences that ends with a 90-day plan instead of a certificate.
TL;DR
- A gap assessment scores your current controls against a framework and ranks what is missing by risk.
- It covers policy, people and technology — the human layer is usually the biggest gap.
- Expect a scored report, a prioritised remediation list and evidence you can show insurers or auditors.
- Run one annually, or whenever the business changes materially — new systems, new clients, new contracts.
- It complements rather than replaces penetration testing; most businesses should do both.
What a gap assessment actually does
A gap assessment answers one question with evidence: "Where does what we have fall short of what we should have?" The assessor (or a structured self-assessment) walks through a framework control by control, tests each one against your real environment, and scores it:
| Framework | What it scores | Best for |
|---|---|---|
| Essential Eight | Eight Australian government mitigation strategies, maturity levels 0-3 | Australian businesses; the default benchmark |
| NIST CSF | Functions: identify, protect, detect, respond, recover | Businesses wanting a US-recognised structure |
| ISO 27001 | A full information security management system | Businesses pursuing certification or enterprise contracts |
The output is the same shape regardless of framework: a maturity score per control, a gap list ranked by risk, and a remediation plan.
Why the human layer is usually the biggest gap
Technical controls are the easy part of a gap assessment — firewalls, backups, patching are things a checklist can verify. What the assessment reliably exposes is the gap between what the security policy says and what staff actually do:
- Payment changes verified by phone, or just processed from the email?
- A phishing report button deployed, or an inbox habit nobody practised?
- MFA everywhere, or on everything except the executive assistant's legacy account?
The breach data explains why this layer matters most: roughly 60% of data breaches involve a human element — an error, a clicked link or a manipulated employee (Verizon, 2025 DBIR). A gap assessment that skips the human layer scores a business's MFA and ignores the one in three staff who will click a malicious email without training.
The five stages of a gap assessment
- Scope. Decide what is in: systems, locations, the people. A small business usually scopes the whole operation; a larger one starts with the crown-jewel systems.
- Gather evidence. Interviews, configuration exports, policy documents, training records. The assessment is only as honest as the evidence.
- Score against the framework. Each control gets a maturity level with the reason attached — "MFA: level 2, email and finance only" rather than "partially done".
- Prioritise by risk. A missing backup on the accounting system outranks a missing screen-lock policy on a shared lobby PC. The score turns a worry list into an ordered plan.
- Remediate and re-check. Turn the top gaps into a 90-day plan with owners and dates, then re-assess. A gap assessment that produces a report nobody re-reads has scored nothing.
What it costs — and what it saves
The cheapest version is a structured self-assessment: days of internal time and no external fees. An external assessor charges a few thousand dollars for a small business depending on scope. Against that, Australia's average self-reported cybercrime cost to a small business is $56,571 per incident, up 14% year on year (ASD, Annual Cyber Threat Report 2024-25). A single prevented incident pays for years of assessments; the report also doubles as the evidence pack cyber insurers increasingly ask for at renewal.
Who needs one, and how often
- Annual for every business with customers' data. Controls decay: staff leave, systems change, and last year's assessment goes stale.
- After material change. New premises, a merger, a move to the cloud, a major client with security requirements — re-run it.
- Before a contract or certification push. A gap assessment is the honest starting line for Essential Eight, SMB1001 or ISO 27001 work: you cannot close gaps you have not scored.
Australian government guidance, including the Essential Eight, frames the same idea: know your baseline, mitigate in priority order.
Gap assessment vs penetration test
They answer different questions and most businesses need both, in that order:
| Gap assessment | Penetration test | |
|---|---|---|
| Question asked | "What controls are missing?" | "Can an attacker get in anyway?" |
| Method | Structured review against a framework | Simulated attack on your systems |
| Output | Scored control list, remediation plan | Exploited weaknesses, technical findings |
| Frequency | Annually | Annually or after major change |
Run the gap assessment first: there is little value in paying for an attack simulation on controls that are missing. Fix the gaps, then test whether the fixes hold.
Turning the report into a plan that happens
The failure mode of every gap assessment is the report that gets filed. Three habits prevent it:
- 90-day horizon only. Twelve gaps with owners and dates inside one quarter beat a 40-page roadmap for the year.
- Measure the human layer continuously. The technical gaps close with a project; the human ones close with a cadence — monthly security awareness training and phishing simulations that give the assessment a live metric instead of a point-in-time answer.
- Re-assess on schedule. Put the next assessment in the calendar when the first one ends.
FAQ
What is a cyber security gap assessment in one sentence? A structured comparison of your current controls against a recognised framework, producing a scored, risk-ranked list of what is missing.
How long does one take? Days for a small business self-assessing; one to two weeks with an external assessor, most of it evidence-gathering.
Which framework should we use? Essential Eight for Australian businesses wanting the default benchmark; NIST CSF or ISO 27001 when contracts or certifications require them.
Can we do it ourselves? Yes, and many small businesses should start there — a structured self-assessment surfaces most gaps. An external assessor adds independence and the evidence insurers and auditors weight more heavily.
Does a gap assessment replace penetration testing? No. It finds missing controls; the pen test attacks what exists. Sequence them: gaps first, then the attack test.
What should the output look like? A maturity score per control, a risk-ranked gap list, and a 90-day remediation plan with named owners.
One last thing
A gap assessment is only as current as its data. The technical findings go stale the day a new system is switched on — the human-layer findings go stale the day a new hire starts. Pairing the annual assessment with continuous human risk reporting is what keeps the gap list honest between assessments.