What Does a Cyber Security Audit Cost in New Zealand?

Consultant reviewing cyber security audit pricing with a client in Christchurch
A cyber security audit with OxygenIT costs between $4,500 and $10,000. Most businesses land at $4,500 for the standard IT and Cyber Assessment. The number moves on staff count, number of sites, and whether a compliance framework is in scope. There is no call-out fee and no charge for the founder or discovery call. That range covers New Zealand small and mid-sized businesses, up to roughly 70 staff. Enterprise audits run by the large consultancies cost several times more.
ISO 27001 and ISO 42001 certifiedNZ based engineers onlyOperating since 2005100+ NZ businesses supported

All OxygenIT prices in one place. This page covers one service. Every price we publish, and what is never included in any of them, is on our pricing page.

Our Cyber Security Audit Costs Between $4,500 and $10,000

Quick Summary: A Cyber Security Audit with us runs from $4,500 to $10,000. Most businesses land at the $4,500 mark for our standard IT and Cyber Assessment. What pushes the number up is staff count and how much regulation your industry carries.

We price a Cyber Security Audit on staff numbers, and that scale starts at businesses with 20 staff and up. It’s the main lever we pull. A 25-person accounting firm and a 70-person manufacturer aren’t the same job, and we’re not going to pretend otherwise. The standard IT and Cyber Assessment sits at $4,500 and covers the core review most businesses need. From there, the price climbs as headcount grows and as regulatory complexity increases, think finance, health, or anyone who needs to prove compliance to a third party like an insurer or a board.

There’s no call-out fee attached to this work, and we don’t offer financing on a Cyber Security Audit either, it’s a fixed-scope engagement, not a payment plan product. What’s included doesn’t shift from project to project: you get the same level of rigour whether you’re at the $4,500 end or the $10,000 end. The difference is how much environment we’re reviewing and how deep the regulatory mapping needs to go.

We won’t quote a number before we’ve looked at your business. That’s not us dodging a price, it’s simply how a Cyber Security Audit has to work. Our process starts with a 15 minute founder call to check fit, then a 45 minute discovery call to get properly aligned on what you need. From there we run the Cyber Risk Assessment itself to find the actual gaps, and only then do you get a customised proposal with a final number inside that $4,500 to $10,000 range. If we don’t have a full picture of your staff count, systems, and regulatory obligations, any number we gave you upfront would just be a guess, and we don’t guess on security pricing.

If your business sits under 20 staff, this particular audit format isn’t built for you, and we’ll say so on the founder call rather than squeeze you into a scope that doesn’t fit. You can read more about what a Cyber Security Audit covers on our Cyber Security Audit page before you book a call.

Call 0800 242 206

What Moves the Price Within That Range

Two things move the price inside that $4,500 to $10,000 range: how many staff you have, and how complex your regulatory position is. Everything else is detail work sitting inside those two drivers.

Pricing starts at 20 staff. A 22-person firm with a straightforward setup and no industry-specific compliance sits close to the $4,500 base, the same figure we quote for our most common job, the IT and Cyber Assessment. As headcount climbs past 20, the price climbs with it. More people means more devices, more logins, more endpoints to check, and more time spent tracing where data actually lives across the business.

Regulation is the other big lever. A business with no external compliance obligations is a simpler audit than one that has to answer to a bank, an insurer, a government contract, or an industry body. We’re seeing more Christchurch firms asked for SMB1001 evidence by their bank or insurer before renewal, and that kind of requirement adds scope. Checking against a named framework takes longer than a general review, because we’re documenting evidence, not just spotting gaps.

There’s no call-out fee attached to this work, and we don’t offer financing on it either. The number we quote after the discovery call is the number you pay. If your business is smaller and simpler, expect to sit near the base. If you’re a 70-person firm with a mix of legacy systems and a bank asking questions, expect to sit toward the top of the range, and we’ll tell you why during the proposal, not after the invoice.

If you want a figure specific to your business rather than a range, the fastest way is to book a discovery call so we can scope it properly through our Cyber Security Audit service.

What’s Included in the Audit Price – and What Isn’t

A Cyber Security Audit with us runs from $4,500 to $10,000. The most common job, a standard IT and Cyber Assessment for a business around the 20-staff mark, sits at $4,500. From there, the price moves up based on two things: how many staff and endpoints we’re covering, and how much regulatory complexity your industry carries. A 20-person retailer and a 60-person financial services firm aren’t the same job, even if both are simply asking for a security audit.

Included in that price is the full process: the founder call, the discovery call, the scoping Cyber Risk Assessment, and then the IT and Cyber Assessment itself with a customised proposal that lays out the gaps we found and what we’d recommend to close them. You get a document you can hand to a board, an insurer, or an auditor. There’s no call-out fee added on top, and we don’t attach financing charges to the audit price. What you’re quoted is what you pay.

What’s not included is the remediation work itself. The audit tells you where the gaps are. Fixing them, whether that’s firewall management, multi-factor authentication setup, or a password management rollout, gets quoted separately once we know what’s actually needed. We don’t bundle guesswork into the audit fee, because until we’ve looked at your environment, we don’t know what the fix list will cost.

If your business is under 5 staff, this isn’t the right fit and we’ll tell you that up front rather than take the job anyway. Pricing starts scaling from around the 20-staff mark, and our full Cyber Security Audit process is built for organisations that already have some IT structure in place to assess.

Call now

Thinking about Cyber Security Audit? Let’s talk.

0800 242 206

Get a free 15-minute IT health check. OxygenIT is ready to help.

The Process Before You See a Number

We don’t hand out a number before we’ve looked at your business. That’s not a stalling tactic. A firewall audit for a 22-person accounting firm and a full cyber security audit for a 90-person logistics company aren’t the same job, even though both might get called a cyber security audit. The process exists to work out which one you actually need.

It starts with a fit check. We work with businesses over 5 employees, typically 20 to 200 staff. Residential customers and businesses under 5 staff aren’t a fit for us, and we’ll say so early rather than let you sit through calls that go nowhere.

What we’re checking for in that 45-minute call is usually the same handful of things: how staff access systems remotely, whether multi-factor authentication is switched on everywhere it should be, what happens to backups if the office loses power for a day, and whether anyone outside the business has admin rights they shouldn’t. The gaps we find usually aren’t dramatic. They’re small, overlooked settings that add up.

If you want to see how this connects to the broader work, our Cyber Security Audit page walks through what the audit itself covers once the proposal is signed off.

The reason this takes two calls instead of one quote is regulation. A business chasing SMB1001 Gold or preparing for cyber insurance has different documentation needs than one that just wants fewer risky logins. We’d rather find that out before we price the job than adjust the invoice halfway through.

None of this costs you anything up front. The founder call and discovery call are how we work out if we’re the right fit for each other before either of us commits to anything.

Call 0800 242 206

What Happens If It’s Not the Right Fit After We Start

We build in an exit before we ever ask for a signature. Our process starts with a 15 minute founder call, then a 45 minute discovery call, before we run the actual Cyber Risk Assessment. That’s three separate points where either side can say this isn’t lining up, and nobody has spent real money yet.

If we do move ahead and it still doesn’t work out, we back it with a 90 day money back period. If something about the fit, the reporting, or the way we work with your team isn’t landing inside those first three months, you get your money back. That’s not a soft promise, it’s how the agreement is written.

Past the 90 days, we set a nine month mark where you can exit the agreement with no extra fees attached. We don’t lock businesses into multi-year contracts they can’t get out of without a penalty. If your business changes direction, gets acquired, or decides to bring security in house, at nine months in you’re free to go without a cancellation charge sitting on top.

Some of this gets sorted before we even start. We don’t take on residential clients or businesses with fewer than five employees, because a Cyber Security Audit built around SMB1001 and ISO 27001 style controls is overbuilt for that size of operation, and the cost simply won’t make sense for them. Telling a business that upfront saves everyone a discovery call that was never going to end in a proposal.

None of this means we expect audits to fall over halfway through. It means the way out is written down and specific, not left for you to negotiate if things don’t sit right.

Talk to the team

How Often Should You Run a Cyber Security Audit?

Most New Zealand businesses without a specific regulatory driver should budget for this annually, with an extra assessment triggered by a breach, a merger, a cloud migration or a major infrastructure change. A business in a regulated sector, or one renewing cyber insurance, often needs a tighter cycle than that. This page covers cost and process only. For the full breakdown of what sets the cadence, including how insurance renewal and continuous monitoring fit in, see how often a New Zealand business should run a cybersecurity assessment.

Cyber Security Audit: Frequently Asked Questions

What happens if our business has fewer than 20 staff?

We don’t run our standard Cyber Security Audit for businesses under 20 staff. Our audit is priced starting at 20 staff, and the scope is built for that size and up. If your business is smaller, we’ll say so on the founder call rather than force you into a format that doesn’t fit. That call checks fit before any quote gets made. We’d rather say no upfront than sell a scope that doesn’t match your business.

Does the audit price cover fixing the problems you find?

No, fixing the gaps we find isn’t included in the audit price. The audit tells you where the problems are, but fixing them, like firewall changes or password management setup, gets quoted as separate work. We don’t bundle guesswork into the audit fee, since we don’t know what the fix list costs until we’ve looked at your systems. The $4,500 to $10,000 range covers only the assessment and the proposal document.

Is there a fee for the founder call or discovery call before we get a price?

No, there’s no fee for the founder call or the discovery call. There’s also no call-out fee attached to any part of the Cyber Security Audit process. The $0 call-out fee applies across the whole engagement, not just a single visit. You only pay the fixed price we quote after the discovery call and Cyber Risk Assessment are complete.

Can we pay for the audit in installments?

No, we don’t offer financing on a Cyber Security Audit. It’s priced as a fixed-scope engagement, not a payment plan product, so the quoted number is paid in full rather than spread over time. This applies across the whole $4,500 to $10,000 range, regardless of where your business lands in it.

Why would two businesses our size get different quotes for the same audit?

Quotes vary mainly because of two things: staff count and regulatory complexity. A 25-person firm with no compliance obligations sits closer to the $4,500 base, while a 70-person business answering to a bank or insurer sits toward the $10,000 end. Other factors, like whether Multi-Factor Authentication and password management are already set up, and how many systems and vendors are in scope, add detail on top of those two main drivers.

This is not the same as a vulnerability assessment. A cyber security audit is the review and the proposal: we map your gaps against a framework and tell you what to fix, in what order. It is not the technical testing. If you want the scan and the penetration test, that is a vulnerability assessment, priced separately at about $1,500 per 10 staff. A 30-user business lands at $4,500 for that, which is the same number as our most common audit. They are different services that happen to meet at the same price, with different outcomes.