
Cyber Security Audit vs Penetration Test in Australia
A cyber security audit checks your security against a defined standard and tells you where you do not meet it. A penetration test attacks your systems and tells you what an intruder could actually do. You need an audit when somebody is asking whether you comply. You need a penetration test when somebody is asking whether you can be broken into. They answer different questions, and buying the wrong one is the most common and most expensive mistake Australian businesses make here.
The deeper problem is that “cyber security audit” is not one product. In the Australian market it refers to at least four different pieces of work at wildly different prices. Working out which one you are being sold, and which one the person asking actually wants, is most of the job.
What is a cyber security audit?
A cyber security audit is a structured review of your security controls against a named benchmark, producing a documented finding for each control: met, partially met or not met. The benchmark is what makes it an audit rather than an opinion. Without a named standard to measure against, what you have bought is a consultant’s impression, which may still be useful but is not an audit and will not satisfy anyone who asked for one.
An audit is a paperwork and configuration exercise. The auditor reads policies, reviews settings, samples evidence and interviews people. In most audits nobody attempts to exploit anything. That is the defining difference from a penetration test, and it is why an audit can tell you that multi-factor authentication is enabled while a penetration test tells you that the one account without it is the domain administrator.
What are the four types of cyber security audit in Australia?
When an Australian provider quotes a “cyber security audit”, they are usually selling one of four distinct things. The prices differ by an order of magnitude, so establishing which one is on the table should be your first question.

The confusion is not accidental. All four are legitimately described as audits, and a provider who sells mainly one of them will tend to use the generic word. Ask which standard your results will be measured against, and the ambiguity disappears immediately.
How is a cyber security audit different from a penetration test?
A cyber security audit measures your controls against a standard. A penetration test measures your defences against an attacker. An audit asks whether the control exists and is configured correctly. A penetration test asks whether the control holds when somebody who knows what they are doing pushes against it.
| Cyber security audit | Penetration test | |
|---|---|---|
| The question it answers | Do we meet the standard? | What could an intruder actually do? |
| Method | Document review, configuration review, interviews, evidence sampling | Active, manual exploitation of your systems by a tester |
| Output | A control-by-control finding list against a named benchmark | Exploited findings with reproduction steps and risk ratings |
| Typical duration | A few days to a few weeks, depending on scope | One to three weeks of testing, plus reporting |
| Who asks for it | Your board, your insurer, a regulator, a compliance project | An enterprise customer, a certification auditor, a procurement team |
| What it will not tell you | Whether your controls survive a real attack | Whether your documentation and governance meet a standard |
The practical consequence is that one does not satisfy a request for the other. If an enterprise customer asks for a current penetration test report, handing them an Essential Eight audit will not close the request, and it signals that you did not understand what they asked. The reverse is equally true: a penetration test report does not demonstrate that you have an information security policy or a risk register.
If you are weighing testing options more broadly, penetration testing versus vulnerability scanning covers the third option that often gets bundled into the same conversation.
Which one do you need?
The fastest way to work out what to buy is to identify who is asking and what they will do with the answer. In almost every case the request traces back to a specific person with a specific need, and that need determines the product.

The row worth dwelling on is the insurer one. Australian cyber insurance applications and renewals increasingly ask direct control questions about multi-factor authentication, backups, patching and endpoint protection. What they want is accurate answers, not an audit report, and an Essential Eight style review is usually the cheapest way to be confident your answers are right. Cyber insurance requirements in Australia covers what they actually ask.
What does a cyber security audit involve?
A cyber security audit follows a consistent shape regardless of which benchmark it uses. Knowing the sequence helps you judge whether a quote is thorough or thin.
- Scope agreement. Which systems, which locations, which benchmark. A quote that does not name the benchmark is not yet a quote for an audit.
- Evidence request. Policies, network diagrams, user lists, configuration exports, previous reports. Expect this to take your team more time than the audit itself.
- Configuration review. The auditor examines actual settings in your identity platform, endpoints, servers and cloud tenancy, rather than taking your word.
- Interviews. Short conversations with the people who run the controls. This is where the difference between the documented process and the real one emerges.
- Findings and rating. Each control marked against the benchmark, with evidence cited and a severity or maturity rating attached.
- Report and remediation plan. A prioritised list of what to fix. A good report sequences the work. A weak one hands you a flat list of eighty items.
Be wary of an audit delivered entirely from a questionnaire you filled in yourself. A self-assessment has its place as a starting point, but it measures what you believe about your environment rather than what is true, and the gap between those two is usually where the risk lives.
How often should you do a cyber security audit?
Annually is the right default for most Australian businesses, with two triggers that should pull it forward regardless of the calendar.
- A significant change to your environment. A cloud migration, an acquisition, a new core system or a change of IT provider all invalidate parts of a previous audit.
- An incident or near miss. An audit after an incident asks a sharper question than a scheduled one, because you already know one control failed.
Frameworks impose their own rhythm on top of this. ISO 27001 requires an internal audit at least annually and a surveillance audit each year of the certification cycle. SOC 2 runs an annual observation period. If you are inside one of those programmes, your cadence is already set. What to expect at ISO 27001 Stage 1 and Stage 2 covers how the certification audits differ from an internal review.
Penetration testing follows a different and usually more frequent cadence, because your attack surface changes every time you ship code. Annual testing plus continuous scanning is the common pattern, and monthly vulnerability assessments cover the gap in between.
Common questions about cyber security audits
How much does a cyber security audit cost in Australia?
Cost is driven almost entirely by which of the four audit types you are buying and how complex your environment is. A focused Essential Eight maturity assessment for a small cloud-based business sits at the bottom of the range. A full ISO 27001 readiness audit across multiple sites sits at the top, and certification audits by an accredited body are quoted separately again using their own audit day calculation. Ask any provider to quote against a named benchmark and a defined scope, because a price without both is not comparable to anything.
What is the difference between a cyber security audit and an assessment?
An audit measures you against a defined external standard and produces a pass or fail style finding for each control. An assessment is broader and more advisory, looking at your risk picture and recommending improvements without necessarily scoring you against a benchmark. In Australian practice the words are used loosely and often interchangeably, so the useful question is not which word the provider used but whether a named standard will be applied to your results.
What does a cyber security audit analyse?
Typically identity and access management, endpoint protection and patching, network configuration and segmentation, backup and recovery arrangements, logging and monitoring, your policy set, supplier and third party risk, and your incident response plan. The exact list depends on the benchmark. An Essential Eight review covers eight specific mitigation strategies, while an ISO 27001 review covers the management clauses and the Annex A controls you declared applicable.
Can a cyber security audit replace a penetration test?
No, and the substitution fails in both directions. An audit confirms controls exist and are configured as intended. A penetration test confirms whether those controls stop someone. Most compliance frameworks that mention technical testing expect evidence of both, and enterprise customers reviewing you as a supplier will usually ask for a penetration test report specifically. How to read a penetration testing report covers what that document should contain.
Is a cyber security audit mandatory in Australia?
There is no general legal requirement for an Australian business to have a cyber security audit. Obligations attach in specific situations instead: APRA regulated entities under CPS 234, critical infrastructure under the SOCI Act, Commonwealth entities under their own policy, and any business bound by a contract or tender clause that requires one. Separately, every organisation covered by the Privacy Act carries obligations under the Notifiable Data Breach scheme whether or not it has ever been audited. Whether the Essential Eight is mandatory covers the most common version of this question.
Where to start
Before you request a single quote, write down one sentence naming who is asking and what they will accept. “Our largest customer wants a current penetration test report before renewal” points at a penetration test. “Our broker wants accurate answers on the renewal form” points at an Essential Eight review. “The board wants to know if we are exposed” points at a broad risk assessment. Those are three different purchases, and the sentence tells you which.
Then insist that every quote names the benchmark and the scope. A quote measured against the Essential Eight or an ISO 27001 Annex A control set can be compared with another quote measured the same way. The standards themselves are available through Standards Australia if you want to see what you are being measured against. A quote for an unspecified audit cannot be compared with anything, and that is usually the point.
Siege Cyber runs both sides of this work: Essential Eight assessments and compliance readiness on the audit side, and CREST-accredited penetration testing on the offensive side. If you are not sure which one the person asking actually wants, that is a short conversation worth having before you spend anything. See our cyber security advisory services or get in touch.