A security gap assessment compares what your business actually does about cyber security against a benchmark you are expected to meet — Essential Eight, SMB1001, ISO 27001 or a client's own security questionnaire — and produces a ranked list of everything missing in between. It is the starting point for nearly every certification project, insurance renewal and serious client contract, because "we're probably fine" is not an answer any of them accept.
Key takeaways
- A gap assessment scores your current controls against a framework — Essential Eight, SMB1001, ISO 27001 — rather than producing a generic to-do list.
- Australian small businesses reported an average self-reported cost of cybercrime of $56,600 in FY2024–25, up 14% on the prior year, according to ASD's ACSC Annual Cyber Threat Report.
- A cybercrime report landed every 6 minutes in Australia in FY2024–25; ASD's ACSC received more than 84,700 of them.
- Most gaps are missing processes, not missing products: untested backups, no training records, no incident plan, MFA left unenforced.
- Run one annually as a baseline, and again after any major change — a new system, a new client contract, a new certification target.
What is a security gap assessment?
A gap assessment answers one question: where does what we do fall short of what we are supposed to do?
It produces three outputs. First, a picture of your current state — which controls exist, which are partial, which do not exist at all. Second, a ranked gap list, ordered by how much risk each gap leaves on the table. Third, a remediation plan with owners and dates, so the findings become work instead of a PDF nobody opens again.
The benchmark is what makes it an assessment rather than an opinion. Without a framework to measure against, every finding is arguable. With one, every finding maps to a control an auditor, a client or an insurer will eventually ask about — and you can put a number on how far away you are.
Gap assessment vs security audit vs penetration test
| Gap assessment | Audit | Penetration test | |
|---|---|---|---|
| Question answered | What are we missing? | Did we follow the rules? | Can we be broken into? |
| Output | A ranked list of gaps | A compliance verdict | Exploit findings |
| Best used | Before an uplift or certification | Periodic compliance checks | Once the basics are in place |
The three overlap, but they answer different questions and run in that order in practice: gap assessment first, audit to confirm, penetration test to stress-test the result.
What a gap assessment covers
A useful assessment walks the same ground the frameworks do:
- Identity and access — MFA coverage, password policy, separation of admin accounts.
- Patching — how quickly known vulnerabilities get fixed across every device.
- Backups — whether they exist, whether they are tested, whether a restore has actually been rehearsed.
- Email security and training — filtering in place, and evidence that staff are trained against the phishing that gets through.
- Incident response — a written plan, and whether anyone has practised using it.
- Vendor and remote access — who can reach your systems from outside, and how that access is controlled.
- Documentation — the policies, registers and records an auditor or client questionnaire will ask you to produce.
How a gap assessment works, step by step
- Pick the benchmark. Essential Eight if you serve government or want the Australian default; SMB1001 for small-business certification; a client's own questionnaire if a contract drives the deadline.
- Score the current state against each control — with evidence, not memory.
- Rank the gaps by risk and effort. A backup that has never been restore-tested outranks a policy rewrite.
- Build the remediation plan with a named owner and a date for each item.
- Re-check the open items on a fixed date, and repeat annually.
Why small businesses run one
The price of not knowing is on the record. ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — one every 6 minutes — and the average self-reported cost of cybercrime to small business rose 14% to $56,600. Business email compromise fraud, an attack that needs no technical gap at all, just an untrained payment process, accounted for 15% of business cybercrime reports that year.
At the global end of the scale, IBM's 2026 Cost of a Data Breach Report puts the average breach at USD 4.99 million, up 12% year over year. A small business will never see that figure, but the proportion is the point: the cheapest time to find a gap is before someone else finds it for you.
How often should you run a security gap assessment?
Annually as a baseline, plus after any material change: a new line-of-business system, a new certification target, a new major client whose contract carries security clauses. Frameworks move — Essential Eight maturity levels get revised, SMB1001 is updated edition by edition — so a two-year-old assessment is a historical document, not a current one.
From findings to fixes
Most gaps in a small business are process gaps, and two of them — training records and phishing-simulation evidence — are among the fastest to close and the easiest to evidence later. Cyber Aware's gap assessment turns your training and phishing data into the evidence pack those frameworks ask for, and human risk reporting keeps it current month after month.
FAQ
What is a security gap assessment? A structured comparison of your current cyber security controls against a benchmark such as Essential Eight or SMB1001, ending in a ranked list of gaps and a remediation plan.
How long does a gap assessment take? Long enough to gather real evidence for each control and short enough to act on. The pace is set by how quickly you can produce evidence, not by the framework itself.
What is the difference between a gap assessment and a risk assessment? A gap assessment measures you against a defined target. A risk assessment identifies and rates risks generally, with no fixed benchmark to measure against.
Is a gap assessment required for Essential Eight or SMB1001? Certification against either framework starts by knowing where you stand, so an assessment is the standard first step — though neither mandates one specific document.
How much does a gap assessment cost? It varies with scope. A self-service assessment costs staff time; a consultant-led one is priced per framework and per site. Check current pricing before you commit.
What happens after a gap assessment? A ranked remediation plan. Fix the high-risk gaps first, re-check on a date, and keep the evidence — it doubles as your audit pack.
One last thing
The most common finding in a small business gap assessment is not a missing firewall. It is missing evidence: the control exists, but nothing was ever written down. Documentation is the cheapest gap you will ever close, and the first thing an auditor asks for.