What is a cyber security gap assessment?

What a cyber security gap assessment is: how it scores your controls against Essential Eight, NIST or ISO 27001, the five stages, and what the report should produce.

A cyber security gap assessment compares the security controls your business actually has against a recognised framework — Essential Eight, NIST CSF or ISO 27001 — and produces a scored list of the gaps between the two, ranked by risk. It is not a hacking exercise and it is not an audit: it is a structured look at your defences that ends with a 90-day plan instead of a certificate.

TL;DR

What a gap assessment actually does

A gap assessment answers one question with evidence: "Where does what we have fall short of what we should have?" The assessor (or a structured self-assessment) walks through a framework control by control, tests each one against your real environment, and scores it:

FrameworkWhat it scoresBest for
Essential EightEight Australian government mitigation strategies, maturity levels 0-3Australian businesses; the default benchmark
NIST CSFFunctions: identify, protect, detect, respond, recoverBusinesses wanting a US-recognised structure
ISO 27001A full information security management systemBusinesses pursuing certification or enterprise contracts

The output is the same shape regardless of framework: a maturity score per control, a gap list ranked by risk, and a remediation plan.

Why the human layer is usually the biggest gap

Technical controls are the easy part of a gap assessment — firewalls, backups, patching are things a checklist can verify. What the assessment reliably exposes is the gap between what the security policy says and what staff actually do:

The breach data explains why this layer matters most: roughly 60% of data breaches involve a human element — an error, a clicked link or a manipulated employee (Verizon, 2025 DBIR). A gap assessment that skips the human layer scores a business's MFA and ignores the one in three staff who will click a malicious email without training.

The five stages of a gap assessment

  1. Scope. Decide what is in: systems, locations, the people. A small business usually scopes the whole operation; a larger one starts with the crown-jewel systems.
  2. Gather evidence. Interviews, configuration exports, policy documents, training records. The assessment is only as honest as the evidence.
  3. Score against the framework. Each control gets a maturity level with the reason attached — "MFA: level 2, email and finance only" rather than "partially done".
  4. Prioritise by risk. A missing backup on the accounting system outranks a missing screen-lock policy on a shared lobby PC. The score turns a worry list into an ordered plan.
  5. Remediate and re-check. Turn the top gaps into a 90-day plan with owners and dates, then re-assess. A gap assessment that produces a report nobody re-reads has scored nothing.

What it costs — and what it saves

The cheapest version is a structured self-assessment: days of internal time and no external fees. An external assessor charges a few thousand dollars for a small business depending on scope. Against that, Australia's average self-reported cybercrime cost to a small business is $56,571 per incident, up 14% year on year (ASD, Annual Cyber Threat Report 2024-25). A single prevented incident pays for years of assessments; the report also doubles as the evidence pack cyber insurers increasingly ask for at renewal.

Who needs one, and how often

Australian government guidance, including the Essential Eight, frames the same idea: know your baseline, mitigate in priority order.

Gap assessment vs penetration test

They answer different questions and most businesses need both, in that order:

Gap assessmentPenetration test
Question asked"What controls are missing?""Can an attacker get in anyway?"
MethodStructured review against a frameworkSimulated attack on your systems
OutputScored control list, remediation planExploited weaknesses, technical findings
FrequencyAnnuallyAnnually or after major change

Run the gap assessment first: there is little value in paying for an attack simulation on controls that are missing. Fix the gaps, then test whether the fixes hold.

Turning the report into a plan that happens

The failure mode of every gap assessment is the report that gets filed. Three habits prevent it:

FAQ

What is a cyber security gap assessment in one sentence? A structured comparison of your current controls against a recognised framework, producing a scored, risk-ranked list of what is missing.

How long does one take? Days for a small business self-assessing; one to two weeks with an external assessor, most of it evidence-gathering.

Which framework should we use? Essential Eight for Australian businesses wanting the default benchmark; NIST CSF or ISO 27001 when contracts or certifications require them.

Can we do it ourselves? Yes, and many small businesses should start there — a structured self-assessment surfaces most gaps. An external assessor adds independence and the evidence insurers and auditors weight more heavily.

Does a gap assessment replace penetration testing? No. It finds missing controls; the pen test attacks what exists. Sequence them: gaps first, then the attack test.

What should the output look like? A maturity score per control, a risk-ranked gap list, and a 90-day remediation plan with named owners.

One last thing

A gap assessment is only as current as its data. The technical findings go stale the day a new system is switched on — the human-layer findings go stale the day a new hire starts. Pairing the annual assessment with continuous human risk reporting is what keeps the gap list honest between assessments.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.