What Actually Happens in a Cyber Strength Audit

An auditor takes notes while a client's office manager talks him through the environment, an audit scope checklist on the desk between them

A Cyber Strength Audit is inSUPPORT's own examination of your live IT environment. It documents what you actually run, inspects five areas of that environment directly, tests what an attacker could reach from the outside and from the inside, measures the findings against the security frameworks your industry uses, and finishes with a costed list of what to fix rather than a report and a farewell. That is inSUPPORT's own description of the service, and more than 1,500 of these audits have been run for Australian businesses, which is why this piece can walk you through the actual steps instead of the theory.

The reason it tends to sit on a to-do list for months is not doubt about the value. It is that letting someone catalogue every weakness in a system you are accountable for feels exposing, and the catalogue has a habit of arriving with a repair bill stapled to it. So here is what the exercise involves, in order, before you agree to any of it.

How an audit is built follows what it is built for. When the audit itself is the product, it is done the moment the document lands. inSUPPORT runs it to scope work that already sits inside the monthly support fee, so it is not done until the gaps are closed. That single difference changes what the audit goes looking for. Same word, different job.

TL;DR: What to remember

  • ✅ The audit documents your environment, examines five areas directly, tests what is reachable from inside and out, and reads the results against the frameworks your industry references.
  • ✅ It ends with three things: a plain English risk assessment ranked by business impact, an audit trail you can hand to a board or an insurer, and a costed list of fixes.
  • ✅ Because remediation sits inside the support fee, the audit is scoping work that is already paid for, not writing you a fresh project to quote.
  • ✅ The Essential Eight is a baseline, not a certificate. No set of controls is guaranteed to stop every threat, and inSUPPORT is aligned to ISO 27001, not certified against it.

Contents

What the audit examines, and how a gap surfaces

The examination covers five areas of the live environment, followed by a testing pass. Each area produces findings tied to specific systems and accounts, not a general impression, so a gap arrives with an address rather than a hunch.

Identity and access

Identity and access goes first, and not by accident. Two of the eight essential mitigation strategies the Australian Signals Directorate (ASD) recommends, restricting administrative privileges and multi-factor authentication, live in this area. When too many people hold elevated access, one stolen password reaches far more of the business than it should. So the audit maps who can get to what, and where the extra keys are sitting unused. If it finds them, that is the first thing on the list.

Patching, backup, email and configuration drift

Then the rest of the live environment. Patching and currency, because software that is behind is software with known holes in it. Backup and recovery testing, because the only backup that counts is one somebody has restored from. Email and endpoint security, because that is where most attacks arrive. And configuration drift, which is the slow gap that opens between how a system was set up and how it is actually running today. Drift is quiet, it is normal, and it is why the audit looks at the environment as it is now rather than as the paperwork says it should be.

Testing what is actually reachable

Penetration testing sits inside the onboarding audit, internal and external. An external test asks what someone outside the business can reach. An internal test asks what one compromised account could do once it is already inside. Those are two separate questions, and an environment can answer one of them well and the other badly. Running the pair tells you more than either test on its own.

Reading the findings against the frameworks

The findings are then measured against the references that apply to your industry. inSUPPORT works with eight: the Essential Eight, CIS Controls, the Cloud Control Matrix, NIST CSF, SMB1001, ISO 27001 and SOC 2, plus IRAP, which is ASD's assessor program rather than a framework in its own right. Keeping those categories straight matters, because they do different jobs. SOC 2 is an attestation standard. ISO 27001 is a certifiable standard. The Essential Eight is a baseline, and ASD is direct about the limits of a baseline: no set of mitigation strategies is guaranteed to protect against all cyber threats. It is a floor to build up from, not a certificate to hang on the wall. The framework references in this article were last reviewed on 14 August 2026.

The negotiables conversation, and why it happens before any work starts

Once the gaps are on the table, the engagement changes character. inSUPPORT sorts the findings into three groups: what must change, what can be handled another way, and what stays as it is with the risk understood and written down. Formal assessments tuck exceptions away somewhere in the process. Doing it as an open conversation with the client, before any remediation begins, is the part worth insisting on.

Why the exceptions get named out loud

Every real environment has legitimate constraints. An application that will not work with modern authentication. A piece of machinery running an operating system nobody supports any more. A director who genuinely needs an exception to do their job. Pretend those do not exist and you get a remediation plan that stalls in week two. Name them at the start and you get one that actually finishes. The point of the conversation is a plan that survives contact with the business it belongs to.

How the findings get sorted, and written down

Each finding lands in one of the three groups, and each accepted exception gets a compensating control and a place in an exception register, so it is a recorded decision rather than a habit nobody remembers making. ASD's own maturity model supports working this way. It advises minimising exceptions and their scope, putting compensating controls in place where an exception is necessary, and documenting and approving exceptions through an appropriate process, with the need for each one monitored and reviewed. It also notes that using exceptions properly should not stop an organisation being assessed as meeting the requirements for a maturity level. inSUPPORT standardises the controls because exceptions create risk, so every negotiable that survives has to earn its place on paper. You can see how that carries through into the ongoing model on the managed IT services page.

What you walk away with

Three things are meant to come out of the audit, and each of them answers a different reader.

A risk assessment your board can read

A plain English risk assessment, ranked by business impact rather than technical severity. The point of ranking it that way is that the people who have to fund the fixes can read the list without a translator, and can see which gap actually threatens the business first. Technical severity and business impact are not always the same order, and the board needs the second one.

An audit trail, and a costed path

A documented audit trail you can put in front of a board, an insurer or a client asking questions in a procurement process. What any particular insurer or client will accept is their call, not ours, so the trail is evidence, never a promise about how someone else will treat it. Alongside it comes a costed remediation path that names the specific steps to close each gap. That last piece is the difference. Where remediation sits inside the support fee rather than arriving as a separate project, the audit is scoping work that is already paid for, which takes away the audit-then-quote-the-fix incentive built into the traditional model. The pricing page sets out the three support tiers and the items that are quoted separately.

How long it takes

Technical onboarding takes about four hours on inSUPPORT's own reported figures. The remediation work that follows runs over a period set by how complex the environment is and how many negotiables came out of the sorting conversation. A dependable timeline needs a defined scope and a look at the environment first, which is the honest reason nobody should hand you a date in a first meeting. And alignment is a state you maintain, not a line you cross once, which is exactly why configuration drift is on the examination list in the first place. The audit ends. The drift starts again the next day. The 6 Step Cyber Strength System shows where the audit sits in the wider sequence.

The awkward questions, answered plainly

What actually happens in a Cyber Strength Audit?

The environment is documented, five areas are examined directly, internal and external penetration testing is run, and the findings are read against the frameworks that apply to your industry. Then comes the negotiables conversation, where findings are sorted into what must change, what can be handled another way, and what is accepted and recorded with a compensating control. It ends with a plain English risk assessment ranked by business impact, a documented audit trail, and a costed path to closing the gaps.

Does this certify us against the Essential Eight or ISO 27001?

No. ASD is explicit that there is no requirement to have an Essential Eight implementation certified by an independent party, though an independent assessment may be required by a government directive or policy, by a regulator, or under a contract. An audit like this documents where your environment stands and what would close the gaps. It is not an independent certification, and inSUPPORT is aligned to the ISO 27001 standard rather than certified against it. If you need formal certification, that is a separate engagement with a certification body.

How long does it take, and what does it disrupt?

Technical onboarding takes about four hours on inSUPPORT's own reported figures, and the examination is planned to run alongside normal operations. Anything with a real chance of interruption, penetration testing in particular, is agreed in advance and booked into a maintenance window rather than sprung on you. The remediation that follows runs over a period set by the complexity of the environment. Treat a firm date offered before anyone has looked at the environment as a number worth testing.

What is the first step?

Book the audit, and put whoever knows the environment best in the room for the first hour, even if that person is an office manager rather than a technologist. Bring the people who understand the undocumented processes: the machine that cannot be rebooted, the account nobody has touched in three years, the workaround everyone relies on and nobody wrote down. That first hour is where the honest picture comes from.

Trade the suspicion for a list you can act on

Most businesses booking an audit already suspect what it will find. The value is turning that suspicion into a documented list with costs against it, so the conversation with your board, your insurer or your clients rests on evidence instead of opinion. A Cyber Strength Audit examines the environment as it actually runs today, reads it against the frameworks that apply to your industry, and hands back a ranked risk assessment, an audit trail and a costed path to closing the gaps. inSUPPORT has run more than 1,500 of these audits and supports more than 5,500 desktops and users, on the back of Kane Nawrocki's 25-plus years in IT. We do not run an audit, hand you a report and disappear.

Book a Cyber Strength Audit →

Citations

  • Essential Eight, Australian Signals Directorate. States that while no set of mitigation strategies is guaranteed to protect against all cyber threats, organisations are recommended to implement the eight essential mitigation strategies as a baseline. cyber.gov.au
  • Essential Eight maturity model, Australian Signals Directorate. Defines four maturity levels from Zero to Three, advises implementing the same maturity level across all eight strategies before moving higher, sets out how exceptions and compensating controls should be documented and approved, and states there is no requirement for an organisation's implementation to be certified by an independent party. First published 30 June 2017, last updated 27 November 2023. cyber.gov.au
  • Consultation on evolution of Essential Eight, Australian Signals Directorate. Published 15 June 2026. ASD consulted on evolving the Essential Eight into a new Essentials series, beginning with Essentials for enterprise IT, and stated that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Consultation ran until 12 July 2026. cyber.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE