Cyber Security Audit: The Problems We Uncover Most Often

Most businesses booking a first cyber security audit want to know three things: how disruptive it will be, what happens to the findings, and whether the process even fits a business their size. This page answers those, and sets out what a Cyber Risk Assessment actually turns up in practice. For the full scope of what gets tested, see our main cyber security audit page.
The Questions Most Businesses Ask Before Booking a Cyber Security Audit
Will a cyber security audit stop our staff working?
No. The audit does not touch production systems in any way that causes downtime. We review configurations, policies and controls against the SMB1001 framework, and talk to a handful of key people along the way. Staff answer a few questions and get on with their day.
What do we actually get at the end of the audit?
A clear picture of where your gaps sit, mapped against the framework, along with a proposal that ranks the recommended fixes by risk. It is specific to your business, not a generic checklist someone printed off.
Do we need to already use OxygenIT for IT support?
No, the audit stands on its own. Some businesses run it as a one-off check before renewing cyber insurance or chasing a certification, then take the follow-up work elsewhere.
How do you decide if we are a fit before we pay for anything?
We start with a free 15-minute founder call to check basic alignment. If that goes well, we book a 45-minute discovery call to dig into your setup and risk profile. Only after that do we run the Cyber Risk Assessment and put together a proposal. You are never paying for a full audit blind.
Is a cyber security audit only worth it for big companies?
We work with businesses running more than 5 staff. Below that the audit is not priced sensibly for what you would get back, and we will say so on the founder call rather than take the job anyway.
What if we are not happy after we start?
There is a 90 day money back guarantee, and at 9 months you can walk away without extra fees if the engagement is not working for you. That covers the audit and any ongoing arrangement that follows it. The only exclusion is third party product we buy on your behalf, Microsoft licences, hardware and subscriptions.
Who actually does the work?
The assessment is done by our Christchurch team, New Zealand based, during business hours. We have been operating since 2005, hold ISO 27001 and ISO 42001 certification, and build our cybersecurity approach around the SMB1001 framework. Where a client takes the optional after-hours add-on, that cover is staffed by our United Kingdom team.
Cyber Security Audit vs Penetration Test: Two Different Things
These two get mixed up a lot, and it is a fair mix-up, since both sound like someone poking around your systems. A cyber security audit looks at the whole picture: your policies, your access controls, your backups, your staff training, your compliance position against something like SMB1001. A penetration test does one narrower thing well. It tries to break into a specific system or network to see if it can be done.
- A cyber security audit reviews people, process and technology together, not just the network
- A penetration test is an active attempt to exploit a defined target, like a website or a login system
- An audit produces a set of gaps and priorities, a penetration test produces a list of exploitable weaknesses in that one target
- Audits support compliance and insurance readiness work. Penetration tests are one input into that picture, not the whole thing
We see businesses book a penetration test when what they actually need is the wider view, or the other way round. If a business has never had either done, an audit usually makes more sense first. It tells you where the real gaps sit, and from there a penetration test can be pointed at whatever area matters most, rather than testing everything at flat cost. If budget is the deciding factor, our penetration testing cost guide sets out the bands.
Our own audit work starts with a 15 minute call to check fit, then a 45 minute discovery call, then a Cyber Risk Assessment that maps out the gaps against a customised proposal. That is a review process, not an attack simulation. Vulnerability assessments and penetration testing are separate services we also offer, and sometimes a proposal includes one alongside the audit depending on what the risk assessment turns up.
If your business runs standard business systems, Microsoft 365, a shared network, remote staff, an audit will usually surface more of the risk that matters day to day. If you have a public-facing application or one specific system you are worried about, a targeted penetration test answers that question directly. We would tell a client straight if a full audit is overkill for what they are asking, and point them to the narrower test instead.
What It Means When the Report Turns Up More Gaps Than Expected
Most businesses we audit end up with more findings than they expected. That is normal. A Cyber Risk Assessment looks at staff access, backups, firewall rules, email protection, password practices and a dozen other fields all at once. Most businesses have never had all of those looked at together before. Ten or fifteen findings on a first report usually just means nobody had checked those specific things in one sitting.
There is a difference between a finding and a failure. A finding might be that multi-factor authentication is switched on for email but not for a finance system. Or that a firewall rule was set up three years ago for a supplier who no longer needs access. These are gaps, not disasters, and a lot of them get fixed quickly once someone knows they exist.
We rank findings so a business owner can see what matters first. Some things sit on a list for months with no real exposure. Others we would flag straight away, things like an admin account with no multi-factor authentication, or backups that have never been tested. The number on the page is simply what we found.
A bigger list often correlates with a bigger business, not a worse one. A business with 40 staff and several cloud systems will naturally generate more findings than a five-person office, purely because there is more surface area to check. We price our IT and Cyber Assessment work on staff numbers starting at 20 staff, and the scope of a report tends to scale the same way.
- A high number of findings usually reflects the number of systems checked, not the state of the business
- Findings are ranked by exposure, not listed in order of how they look on paper
- Some gaps close in days, others take longer depending on the system involved
- The report and proposal are built from what is found, not a standard template
Once the report is done, the proposal that follows is built around what the findings actually show, not a generic package. Some businesses handle a portion of the remediation themselves. Others ask us to take it on as part of ongoing managed security work. Either way, the report belongs to the business, and what happens next is a decision, not an obligation.
Why Legacy Accounts and Shadow IT Often Surface During the Audit
Most businesses that come to us for a cyber security audit have a few accounts and tools floating around that nobody quite remembers setting up. That is normal, and it is one of the most common things a Cyber Risk Assessment turns up. Usually it is just what happens after a few years of hiring, staff turnover, and people trying to get their job done quickly.
Legacy accounts are the login credentials left behind after someone leaves the business or changes role. A former staff member’s email might still be active. An old contractor might still have access to a shared drive. A system admin login from a project three years ago might never have been switched off. Growth and staff changes create gaps faster than most internal teams have time to close them.
Shadow IT is the other side of it, software or hardware being used in the business that IT never signed off on. Common examples we see during a Cyber Risk Assessment include:
- A team using a free file-sharing tool instead of the approved system, because it was faster on a deadline
- A department paying for its own project management app on a personal card
- An old server or device still connected to the network but no longer monitored
- Personal devices used for work email without multi-factor authentication set up
Usually it just means the business has been busy, and IT decisions got made at the edges rather than through a central process. That is exactly what the audit is built to find. We map everything against the SMB1001 framework during the assessment, so gaps get flagged in the same order a Gold-level certification would expect them fixed.
What we do with that list depends on the business. Some items get fixed immediately, like disabling an old admin account. Others get scoped into a wider proposal, particularly if a legacy tool is doing a job the business still needs and a replacement has to be planned rather than switched off overnight. That call gets made case by case, based on risk and cost.
See How We Handle a Cyber Security Audit in Christchurch
Key points from the video:
- What a cyber security audit typically uncovers
- Why the finding count reflects surface area, not failure
- How findings get ranked by exposure
- What happens after the report lands
How Much Staff Time and Access the Audit Requires
Most people picture an audit as days of staff pulled off their real jobs. That is not how we run it. Our process starts with a 15-minute founder call, just to check whether your business is a fit for what we do. If it is, we book a 45-minute discovery call to get properly aligned on what you need and what you are trying to fix.
That discovery call is usually the biggest single time cost for you: one person, one meeting, 45 minutes. It is where we ask what systems you run, who has access to what, and what has kept you up at night. From there we move into the Cyber Risk Assessment itself, which is where we find the actual gaps.
This is the stage that needs system access, not staff hours. Depending on what you have told us during discovery, that can include admin visibility into your network, a look at your Microsoft 365 environment, or read access to your firewall and endpoint tools. We are not asking your team to sit with us while we do it, just for the door to be opened so we can look properly.
- One person available for the 45-minute discovery call
- Admin or read access to core systems relevant to what was discussed
- A point of contact who can answer follow-up questions if a gap needs context
- No requirement for staff to be pulled off daily work for the assessment itself
What comes out the other end is a proposal built specifically around what the Cyber Risk Assessment found. It reflects your systems, your gaps, and your risk profile.
We will say plainly that this process is not built for every business. We do not take on residential clients or businesses with fewer than 5 employees. If that is you, an audit like this is more than you need right now, and we would rather tell you that upfront than sign you up for something oversized.
If you want a clearer picture of what a full cyber security audit covers before you commit any access at all, our cyber security audit page runs through the scope in more detail.