How much does a small business security audit cost? Honest tiers, and what changes the price
Filed under security · pairs with the 45-point audit checklist and the one-page report template
Search for security audit pricing and you get sales pages quoting "it depends" and enterprise reports quoting $50k. Here is the honest map for a company of five to fifty people, including what we charge for the tier we sell and what that tier deliberately does not include.
1. The four tiers
| Tier | Typical cost | What you get | Right for |
|---|---|---|---|
| Self-audit | One day of your time | A checklist walkthrough with evidence, scored findings (ours is free: 45 points) | Every team, twice a year, always |
| Fixed-fee external audit | A$99–A$500 one-off | An outside pair walks the same structure, delivers a prioritized findings report with owners and dates | Teams that keep deferring the self-audit, or want a second pair of eyes |
| Consultant / MSP engagement | A$1,500–A$5,000 | Days of on-site work, interviews, deeper tooling, sometimes remediation | Regulated teams, or 50+ seats with real estate complexity |
| Penetration test | A$5,000–A$15,000+ | Simulated attack on your perimeter or apps, exploit narrative, remediation support | Teams with compliance deadlines or a real adversary model |
The tiers are sequential, not alternatives: a team that has never walked a checklist gets more from a $149 audit than from a $15k pentest it is not ready to act on.
2. What actually drives the price
- Number of identity providers: one Google Workspace is an afternoon; Google + Microsoft + a code forge + a cloud console is four walks of the same zone.
- Estate size: laptops, phones, NAS boxes, printers — each device class adds verification time.
- Evidence method: read-only screen-share (fast, cheap) versus agent-based scanning (slower to start, deeper results).
- Report depth: a one-page findings report with owners is hours; a 40-page compliance-style document is days.
- Cloud account count: every AWS/GCP/Azure tenant is its own sweep of buckets, IAM roles, and forgotten test environments.
3. What a fixed-fee audit includes — and what it does not
We sell the fixed-fee tier, so here is the honest boundary. Our Small-Team Ops Audit is A$149 and includes: the walkthrough call (90 minutes, read-only screen-share), a numbered findings report in the one-page format with triage, owner and due date per finding, a fix-check spreadsheet, and a follow-up call — with the guarantee that you get at least ten actionable findings or the fee back.
What A$149 does not buy: exploitation attempts (that is the pentest tier), remediation work (we do not touch your systems), compliance certification, or tooling licenses. Any vendor who implies a few hundred dollars buys a pentest is selling you a scan with a logo on it.
4. The cost of skipping it
Three costs, in ascending order of pain:
- The deferral tax: every quarter without an audit, the checklist's hygiene items compound — stale access, untested backups, drifted configurations. The same audit costs more to recover from later because there is more to unwind.
- The insurance surprise: cyber insurance applications ask what you attest to — MFA everywhere, backups tested, an IR plan. Answering truthfully requires exactly what an audit produces. Overstating on the form is how claims get denied (see the insurance requirements checklist).
- The incident itself: the first hour of an unpracticed incident is spent deciding who is in charge. The free first-30-minutes card exists precisely because most of that cost is preventable with a page of preparation.
5. A rule of thumb for the budget line
Teams we talk to converge on something simple: budget one fixed-fee audit (A$100–A$500) per year as the baseline, run the free self-audit six months after it, and hold the pentest budget until a compliance letter or an enterprise customer actually demands one. If an audit's critical findings take more than a month to close, the problem is not the audit budget — it is that nobody owns the fixes, which is a delegation conversation, not a spending one.
6. Five numbers that tell you the audit paid for itself
- Cost per critical closed: audit fee ÷ criticals closed within 30 days. A$149 ÷ 3 is cheaper than any hour of downtime.
- Days-to-first-fix: from report delivery to the first closed critical. Target: under 7 days.
- Restore-test result: passed or failed — the single finding that most often separates a bad day from a company-ending one.
- Open-criticals trend: this audit's critical count versus last audit's. Down and to the right is the whole point.
- Hours spent: the walkthrough plus fixes. If a $149 audit saved a single evening of an incident, it paid for itself.
Where this fits
Price is the last question; the walkthrough is the first. Start with the free 45-point checklist, report in the one-page format, and bring in the outside pair when the criticals will not die — that is the audit-and-runbook service, and the A$149 audit is the whole fixed-fee tier in one purchase.
Prepared buyers pay the same fee and get more audit: the audit preparation checklist makes the five-day turnaround hold.
From the HIVE80lab kit
- The interactive Security Audit Scorecard — free, private, 45 checks scored in your browser.
- Ops Starter Kit — full incident-response kit for small teams — $14
- Small-Team Ops Audit — prioritized findings + fix plan, five-day turnaround — $149
- Custom Incident Runbook — done-for-you, built from your estate, 48h — $249
- Ops Mega Bundle — all 5 kits in one download — $29