What Does a Vulnerability Assessment Cost in New Zealand?

All OxygenIT prices in one place. This page covers one service. Every price we publish, and what is never included in any of them, is on our pricing page.
The Real Price Range for a Vulnerability Assessment
We price Vulnerability Assessments at roughly $1500 per 10 staff on the network. A 30-user business, which is a size we see often, lands at that $4500 mark for the full technology and cyber risk assessment. That figure covers the work of actually finding the gaps in your systems, not a quick scan of one server or a single laptop.
Two things move that price. The first is staff count, since more people usually means more devices, more logins, and more entry points to check. The second is regulation. A business that has to meet specific compliance requirements, or one working towards SMB1001 certification, needs a deeper look than a business with no external obligations. We factor both into the proposal before we start, not after.
- Vulnerability scan across your network and endpoints
- Penetration testing to check how those gaps could be used against you
- A full IT review covering your wider setup, not just the security layer
That’s the scope included in the price. We don’t charge a call-out fee on top, and we don’t offer financing on this service. It’s a fixed piece of work with a fixed cost, so the number in your proposal is the number you’ll see on the invoice.
The proposal you get isn’t pulled from a template. It comes out of a Cyber Risk Assessment we run after two calls, a 15-minute founder call and a 45-minute discovery call, so the scope actually matches what your business has running. If you want to see how this fits with wider security work, our Vulnerability Assessments page sets out where it sits alongside the rest of what we do.
What Drives Your Price Up or Down
Two things move the number on your quote. The first is staff count. We price at roughly $1500 per 10 staff, so a 30-user business lands at $4500 for the full assessment. Add more people or more endpoints and the price climbs in that same step, simply because there’s more ground to cover: more devices to scan, more accounts to check for exposed passwords or weak access controls.
The second is regulation. A business that has to prove compliance, whether that’s for cyber insurance, a client contract, or a framework like SMB1001, needs a deeper look at policy and process on top of the technical scan. That takes more of our time, so it costs more than a business that just wants a baseline read on their exposure.
What doesn’t move the price is scope creep on our end. Every assessment, no matter the size, includes the same three components: a vulnerability scan across your network and endpoints, penetration testing to see how far a real attack could get, and an IT review that looks at how your systems are set up day to day. We don’t sell a stripped-down version and then charge extra to fill in the gaps later.
- Staff and endpoint count, since each device and account adds scanning and review time
- Regulatory or insurance requirements that call for deeper documentation and policy checks
- Number of separate sites or networks if your business operates across more than one location
- How much existing documentation you have, since starting from nothing takes longer than updating known gaps
There’s no call-out fee and we don’t offer financing on this work. It’s a fixed-scope job, quoted after the discovery call rather than run as an open-ended hourly arrangement. If your business has fewer than 5 staff, this usually isn’t the right fit financially. The 30-user version gives you a working example, but every quote is built from your actual staff count and setup, which you can talk through on our Vulnerability Assessments page before you commit to anything.
We won’t inflate a scope just to hit a bigger number. If a 20-person business doesn’t need the same depth as a 100-person one facing insurance renewal, we’ll say so on the call. That’s part of why the 45-minute discovery session happens before any proposal goes out, so the price ends up matching the actual work, not a standard package that doesn’t fit your business.
What’s Included in Our Vulnerability Assessment Pricing
Our vulnerability assessment pricing runs at roughly $1500 per 10 staff. A 30-user business sits at $4500 for the technology and cyber risk assessment that finds where the gaps are. That number covers three things done together: a vulnerability scan across your network and endpoints, a penetration test component to check how far a real attack could get, and an IT review that looks at how your systems are set up day to day.
The two things that move the price are staff numbers and regulatory load. More staff means more endpoints, more logins, and more devices to check, so the cost climbs with headcount. Businesses working towards SMB1001 certification or preparing for a cyber insurance renewal usually need a wider check, because the assessor or insurer wants specific gaps documented, not just a general health check.
- Vulnerability scan across servers, endpoints, and network devices
- Penetration test component to check exploitability of what’s found
- IT review of configuration, patching status, and access setup
- A written proposal setting out the gaps found and what to fix first
There’s no call-out fee added on top and we don’t offer financing on this. It’s a fixed quote based on staff numbers once we’ve scoped the business. What’s not in the base price is remediation work itself. The assessment tells you what’s wrong and what order to fix it in; actually doing the fixing, patching, or system changes is a separate piece of work we’d quote once we know what the assessment turns up. Some businesses just want us to hand over the findings so their own IT person can action them, and that’s fine. Others ask us to run the fixes too. Either way the assessment price stays the same, because it’s the scanning and reporting work that’s priced, not what happens after.
If you’re weighing this up against a broader security programme, it’s worth reading through our vulnerability assessments page for how this fits alongside penetration testing and ongoing managed security work. Some businesses start with the assessment and build from there rather than doing everything at once.
If your business has fewer than 5 staff, this level of assessment is usually more than you need. We’d rather say that upfront than quote a job that doesn’t fit your risk profile.
Thinking about Vulnerability Assessments? Let’s talk.
Get a free 15-minute IT health check. OxygenIT is ready to help.
The Most Common Engagement and What It Runs
Most businesses that come to us for a vulnerability assessment land around $1500 per 10 staff. A job we run often, a full technology and cyber risk assessment for a 30-user business, sits at $4500. That figure covers the scan, the analysis, and a written report we walk through with you. It’s not a placeholder number. It’s what we’ve charged repeatedly for this exact size of business.
Two things move that price. The first is headcount. More staff means more endpoints, more logins, more places for a gap to hide, so the scope of the assessment grows with the business. The second is regulatory load. A business chasing SMB1001 certification or working towards cyber insurance readiness needs a deeper look at policy and process, not just the network. That takes more of our time, and it shows up in the quote.
What’s included in that price is the vulnerability scan itself, a penetration test component, and an IT review that looks at how your systems are set up day to day. We don’t scope a job down to just the scan and call it done. If we find something during the assessment, it goes in the report along with a plain-English explanation of what it means for your business.
There’s no call-out fee to get this started. We don’t add a truck fee or a site visit charge on top of the quoted price. We also don’t offer financing on this work; it’s billed as one project fee, not spread across instalments. If you’re weighing this up against other IT spend for the year, that’s worth knowing upfront rather than finding out partway through a quote conversation.
What we won’t do is quote you a number before we know your staff count and whether you’re chasing a specific compliance outcome. A 12-person business with no regulatory pressure and a 60-person business preparing for cyber insurance are not the same job, even though both might call it a vulnerability assessment. We’d rather ask two questions upfront and give you a real figure than throw out a range that doesn’t hold up once we’re in your systems.
This pricing sits inside the wider work we do under our Vulnerability Assessments service, alongside penetration testing and security audits for businesses that want the full picture rather than a single scan.
How We Confirm Your Final Price
The $1500 per 10 staff figure and the $4500 example at 30 users are starting points, not quotes. We don’t hand over a fixed number until we’ve actually looked at your business. Here’s the order we work through it in.
- A fit check first, so we’re not wasting your time if we’re not the right match. We don’t take on residential clients or businesses under 5 staff.
- A 15 minute founder call to talk through where you’re at and what’s driving the request, whether that’s a client asking for it, insurance renewal, or a compliance deadline.
- A 45 minute discovery call once we’re aligned, where we get into your network, staff count, systems, and any regulatory pressure specific to your industry.
- A Cyber Risk Assessment, which is where we find the gaps. This is the technical step that tells us the real scope, not just headcount.
- A custom proposal built off that assessment, with a fixed price for the Vulnerability Assessment work and the Penetration Testing and IT review components, if those are part of what you need.
Staff count moves the price the most, since it drives how many endpoints and accounts we’re checking. Regulatory pressure is the other big driver. A business chasing SMB1001 Gold or preparing for a compliance audit needs a wider assessment than one doing this as a general check, and that shows up in the proposal, not the headline range.
There’s no call-out fee at any stage of this process and no financing option attached to the pricing. What you’re quoted is what you pay for the scope agreed. If your business doesn’t need the full assessment, we’ll say so in the discovery call rather than scoping you into a bigger job than you need.
If you want to see where a Vulnerability Assessment sits against our other Vulnerability Assessments and security work before you book a call, that page has the wider detail.
Vulnerability Assessment: Frequently Asked Questions
What’s included in the price, and what isn’t?
The price covers a vulnerability scan, a penetration test, and a full IT review. Those three parts make up every assessment we run, no matter the business size. What’s not included is the actual fix-up work. Once the assessment shows where the gaps are, patching them or changing systems is a separate piece of work. We’d quote that once we know what needs doing, after we see the results together.
Is there a call-out fee to get a quote?
No. We don’t charge a call-out fee on this service. The price you’re quoted is based on your staff count, and that’s the number that shows up on the invoice. There’s nothing added on top for us to come out, run the scoping calls, or put the proposal together.
Do you offer financing for a Vulnerability Assessment?
No, we don’t offer financing on this service. It’s a fixed-scope job with a fixed cost, paid as a single invoice rather than spread out. If budgeting matters to your decision, staff count is the main thing that sets the price, so a smaller team means a smaller number to plan for.
Why do quotes for this vary so much between businesses?
Two things move the number: staff count and regulation. More staff means more devices, logins, and endpoints for us to check, so the price climbs in steps from there. Regulation adds to that. A business working towards SMB1001, or one facing a cyber insurance renewal, needs a deeper look at policy and documentation, not just a technical scan. Both get factored into the proposal before any work starts.
Is a Vulnerability Assessment worth it for a very small business?
If your business has fewer than 5 staff, this usually isn’t the right fit financially. The scope and depth of the assessment, the scan, the penetration test, and the IT review, are built for businesses with enough staff and systems to make that depth worthwhile. We’ll say so on the discovery call if your setup doesn’t need the full scope priced here.
This is not the same as a cyber security audit. A vulnerability assessment is the technical testing: the scan across your network and endpoints, the penetration test component, and the IT review. It is not the advisory review. If you want your gaps mapped against a framework with a remediation proposal, that is a cyber security audit, priced from $4,500. A 30-user business also lands at $4,500 here, so the two meet at the same number. They are different services with different outcomes, not two names for one thing.
Related reading