ISO 27001
Certified
96.8% Client Satisfaction

2025 CSAT, measured in Simplesat

4.8 Stars from 44 Google Reviews

Understand your real risk before insurers or attackers do. Scan your network, endpoints and cloud for the security gaps your antivirus and firewall miss, then get a prioritised, plain-English fix list your leadership team can act on.

Get a free 15-minute IT health check Or call our Christchurch team on 0800 242 206
OxygenIT engineer running a vulnerability scan on a server rack for a Christchurch business

Watch: what a vulnerability assessment actually gets you

Key points from the video:

  • The difference between a vulnerability assessment and a penetration test, and which one to start with.
  • What a proper scan actually checks: your network, endpoints, cloud, patching and multi-factor authentication.
  • The three ways assessments are priced, and how to compare quotes without getting caught out.
  • When a full assessment can safely wait, and the triggers that mean it cannot.

Why Christchurch Businesses Are Turning to Vulnerability Assessments

Something shifted in the last few years. We used to get calls after an incident – a ransomware hit, a data breach, or a client's email account sending invoices to the wrong people. Now business owners contact us before an incident occurs.

Practical pressure drives this change.

CERT NZ reported over 7,100 cyber security incidents in 2022. Small and medium businesses made up a large share of those reports. Christchurch organisations are not immune. The city's rebuild brought modern office fit-outs across the CBD and light commercial zones around Addington and Riccarton. Yet, modern buildings do not always mean modern network security. We see brand-new offices running outdated firewalls and unpatched servers every week.

Compliance also drives this. More Christchurch accounting firms, legal practices, and insurance brokers must now prove they have done a vulnerability assessment. Their own clients and insurers are asking for this. Cyber insurance applications now routinely ask for evidence. Without an assessment, cover may be refused. It is that blunt.

The Privacy Act 2020 matters here. It requires organisations to notify the Office of the Privacy Commissioner of breaches that cause serious harm. A vulnerability assessment does not stop breaches on its own. It shows you knew where the gaps were and acted on them. This matters if you ever explain your position to a regulator.

Most of the businesses we work with are not doing this because they are scared. They want to stop guessing, seeking a clear list of what is weak, what is fine, and what to fix first. A vulnerability assessment provides this: a direct look at your network, your endpoints, your cloud setup, and your exposure.

Many businesses find this surprising. Most Christchurch businesses with 20 to 200 staff have never had one done properly. They assume their antivirus or firewall covers it, but it does not. A vulnerability assessment finds the things your existing tools miss.

Christchurch business owner reviewing a vulnerability assessment report with an OxygenIT engineer

Vulnerability Assessment or Penetration Test: Which One Do You Need

We get this question constantly. It is the right one to ask before spending any money.

A vulnerability assessment scans your systems, applications, and network to find known weaknesses. It builds a clear picture of where your gaps are. Think of it like a building inspection: you get a report showing every crack, unlocked window, and spot that needs fixing. It is broad, covering everything and giving you a prioritised list so you know what to sort first.

A penetration test is different. It takes one of those cracks and tries to break through it. A pen tester acts like an attacker, pushing past defences to see how far they can get. It is useful, but narrow by design. It tests specific entry points rather than mapping the whole surface.

Which do you need? For most Christchurch businesses running 20 to 200 endpoints, a vulnerability assessment is where you start. Most organisations have not done a proper scan in over a year. You cannot test a door if you do not know which doors exist; the assessment finds them all.

Penetration testing makes sense after you have already run assessments and closed the obvious gaps. You use it to stress-test specific controls. It is a later step, not the first one.

Consider the practical difference in outcome. A vulnerability assessment gives your team a roadmap, suggesting you fix five things this month and ten next quarter. A penetration test gives you a story about one attack path. Both matter, serving different purposes at different stages.

We offer both vulnerability assessments and penetration testing as separate services because they solve separate problems. Most of our clients across Canterbury start with assessments on a regular cycle. They add penetration testing once their security posture matures. This order reduces risk. It avoids producing a report nobody acts on.

Not sure which fits where you are right now? Call our Christchurch team on 0800 242 206. We explain your options, with no obligation or jargon.

When a Full Vulnerability Assessment Can Wait

Not every business needs a full vulnerability assessment right now. We prefer to advise on what you need, rather than push an unnecessary service.

If you have just had one done in the last six months and nothing major has changed in your environment, you can probably hold off. Your network, staff count, and applications are the same, with no new cloud services or remote access points added. In that case, your existing report still has value. You need to make sure someone acts on the findings.

Small teams running a handful of devices with no server infrastructure might not need a full assessment. If you have five people using Microsoft 365 with multi-factor authentication and no on-premise systems, a lighter security review could be enough. This applies to newer Christchurch businesses operating out of shared workspaces around the central city rebuild, where the IT footprint is still small and relatively simple.

People often misunderstand this point. They assume "small" means "safe." A business with 15 staff and one cloud app still holds client data, sends invoices, and has email accounts that attackers want. While a full vulnerability assessment might wait, doing nothing at all is a different conversation entirely.

Your compliance framework dictates the schedule at times. If you are not facing an audit or a renewal in the next quarter, you might have room to plan the assessment around your budget cycle, avoiding a rush. That is fine; timing matters.

A full assessment cannot wait when you have added new systems, changed providers, opened a second site, or had a security incident. Any of those triggers means your old picture of risk is outdated. When someone tells us "nothing has changed," we often find three things that have. Common examples include new staff laptops, a SaaS tool someone signed up for, or a firewall rule loosened for a project and never tightened.

If you are unsure whether now is the right time, that uncertainty is worth a quick conversation – not a full engagement.

Vulnerability scan dashboard showing detected weaknesses across a Christchurch network

Inside the Assessment: Scoping, Scanning and Reporting

We follow three stages for every vulnerability assessment. Skipping any one of them gives you a report that is either too vague or too noisy to act on.

Scoping comes first. We sit down with you and map out what needs testing. This includes network boundaries, cloud services, endpoints, and line-of-business applications. A Christchurch accounting firm with 40 staff running a private cloud setup has a very different scope. This differs from a logistics company with drivers connecting from mobile devices across the Canterbury Plains. We define what is in, what is out, and what matters most to your operations. This keeps the assessment focused and the results useful.

How the scanning works

Once scoping is locked in, we scan. We use a mix of automated tools and manual checks against your systems. The scanners look for known weaknesses: outdated software, misconfigured firewalls, open ports that should not be open, missing patches.

Many people do not realise this. Automated scanners throw up false positives constantly. The raw output almost always needs a human eye before it means anything. Our engineers in Christchurch review every finding before it goes into your report.

We check authentication settings. We also look at how your network segments communicate. We test whether your multi-factor authentication is enforced, or only switched on in name.

Reporting follows. This is where most providers fall short. They hand over a 90-page PDF full of severity scores and walk away. We do not do that. Your report ranks each vulnerability by real business risk, not technical severity. A critical vulnerability on an isolated test server is not the same as a medium one on your finance team's shared drive.

You get a clear summary your leadership team can read in five minutes. The report includes technical detail for your IT staff or our managed IT team to fix things. Every item has a recommended action and a priority.

The whole process typically runs over a few days, not weeks. We have refined it to cause minimal disruption to your working day.

Completed vulnerability assessment report with prioritised findings for a Christchurch business

How Vulnerability Assessment Costs Are Structured

Most providers in the managed IT space price vulnerability assessments in one of three ways. Knowing the model before you sign anything prevents surprises on the invoice.

The first is a fixed-fee project model. You pay a set amount for a single assessment covering an agreed scope. This works well for businesses that want a one-off check or need a report for an insurance renewal. The second is a recurring subscription model. Assessments run monthly or quarterly as part of a managed security agreement. That is the approach we use with most of our clients. Threats change constantly, and one scan a year does not cut it. The third is a per-asset model. You are charged based on the number of IP addresses, devices, or applications being scanned.

Several factors push the cost up or down across all three models:

  • Network size and complexity. A 30-person accounting firm in the Christchurch CBD with a single office is a different job. This differs from a 150-person logistics operation with warehouse sites across the Canterbury plains and remote workers on VPN.
  • Whether external-facing systems, internal networks, or both are in scope.
  • Reporting depth. A raw scan output costs less than a prioritised report with plain-language recommendations your board can read.
  • Frequency. Quarterly scans cost more annually than a single engagement but far less per assessment.

Before you commit to any provider, ask three questions. What is included in the report? Do they re-test after you have fixed things? Is the assessment aligned to a recognised framework like SMB1001 or ISO 27001?

A vulnerability assessment that dumps a list of findings on your desk is not worth much. The value sits in the prioritisation, the context around each finding, and the clear next steps. The cheapest quote usually skips all three. We build our assessments into ongoing managed security agreements so the findings get acted on, not filed away. That is the difference between a report and a result.

Frequently Asked Questions

How long does a vulnerability assessment take for a Christchurch business?

Most assessments take between three and five business days, depending on how many devices and systems you run. A business with 20 to 50 endpoints usually falls at the shorter end. Larger setups with cloud services, remote staff, and multiple office locations take longer to scan properly. We schedule the work around your team so daily operations keep running. You get a clear timeline before we start, so there are no surprises partway through.

What happens when your team starts a vulnerability assessment?

We begin by scanning your network, endpoints, and cloud systems for known weaknesses, without disrupting your staff's daily work. Most of the process runs in the background using tools that check for outdated software, weak passwords, and open ports. We do not need to shut down systems or take over workstations. Once scanning is done, we walk you through the findings in plain language, not technical jargon, so you understand what needs fixing first.

Why do so many new Christchurch offices still have security gaps?

New buildings do not automatically mean new network security. Across the CBD and areas like Addington and Riccarton, the rebuild brought modern fit-outs, but many businesses moved their old servers and firewalls straight into the new space. We regularly find brand-new offices running outdated firewall software and unpatched servers. A fresh office does not fix old habits. That gap between physical upgrades and IT upgrades is exactly what a vulnerability assessment catches.

How often should a Christchurch business repeat a vulnerability assessment?

Most businesses should run a full assessment at least once a year, or sooner if something in your environment changes. Adding new cloud services, changing IT providers, opening a second site, or facing a security incident all reset the clock. If your last assessment was under six months ago and nothing has changed, your existing report likely still holds value. Regular cycles matter more than one-off checks, because new weaknesses show up as your systems grow.

Do we still need a vulnerability assessment if we already have cyber insurance?

Yes, most cyber insurance applications now ask for proof you have run a vulnerability assessment before they will offer cover. No assessment often means no cover, or a higher premium. Insurers want evidence you know your weak points and are working through them. Beyond the insurance side, the Privacy Act 2020 also expects you to show you acted on known gaps. An assessment gives you that paper trail if you ever need it.

Stop guessing where your gaps are

Book a free 15-minute IT health check and we will show you where to start.

Get a free 15-minute IT health check

Table of Contents

Contact us

Talk to an IT Support Expert

Get quick, friendly IT helpdesk support from experts who understand your business. Our local Christchurch engineers are ready to jump in and fix issues as quickly as they start.

Don’t let downtime slow you down. Boost productivity and peace of mind with reliable IT support services personalised to your needs.

Book a IT Support Consultation

This field is for validation purposes and should be left unchanged.
Please use your company email (no Gmail/Yahoo addresses).
I agree to OxygenIT storing my information in their CRM and contacting me about my inquiry. I have read the Privacy Policy(Required)