HIVE80lab — Ops notes

How much does a small business security audit cost? Honest tiers, and what changes the price

Filed under security · pairs with the 45-point audit checklist and the one-page report template

Search for security audit pricing and you get sales pages quoting "it depends" and enterprise reports quoting $50k. Here is the honest map for a company of five to fifty people, including what we charge for the tier we sell and what that tier deliberately does not include.

1. The four tiers

TierTypical costWhat you getRight for
Self-auditOne day of your timeA checklist walkthrough with evidence, scored findings (ours is free: 45 points)Every team, twice a year, always
Fixed-fee external auditA$99–A$500 one-offAn outside pair walks the same structure, delivers a prioritized findings report with owners and datesTeams that keep deferring the self-audit, or want a second pair of eyes
Consultant / MSP engagementA$1,500–A$5,000Days of on-site work, interviews, deeper tooling, sometimes remediationRegulated teams, or 50+ seats with real estate complexity
Penetration testA$5,000–A$15,000+Simulated attack on your perimeter or apps, exploit narrative, remediation supportTeams with compliance deadlines or a real adversary model

The tiers are sequential, not alternatives: a team that has never walked a checklist gets more from a $149 audit than from a $15k pentest it is not ready to act on.

2. What actually drives the price

3. What a fixed-fee audit includes — and what it does not

We sell the fixed-fee tier, so here is the honest boundary. Our Small-Team Ops Audit is A$149 and includes: the walkthrough call (90 minutes, read-only screen-share), a numbered findings report in the one-page format with triage, owner and due date per finding, a fix-check spreadsheet, and a follow-up call — with the guarantee that you get at least ten actionable findings or the fee back.

What A$149 does not buy: exploitation attempts (that is the pentest tier), remediation work (we do not touch your systems), compliance certification, or tooling licenses. Any vendor who implies a few hundred dollars buys a pentest is selling you a scan with a logo on it.

4. The cost of skipping it

Three costs, in ascending order of pain:

5. A rule of thumb for the budget line

Teams we talk to converge on something simple: budget one fixed-fee audit (A$100–A$500) per year as the baseline, run the free self-audit six months after it, and hold the pentest budget until a compliance letter or an enterprise customer actually demands one. If an audit's critical findings take more than a month to close, the problem is not the audit budget — it is that nobody owns the fixes, which is a delegation conversation, not a spending one.

6. Five numbers that tell you the audit paid for itself

Where this fits

Price is the last question; the walkthrough is the first. Start with the free 45-point checklist, report in the one-page format, and bring in the outside pair when the criticals will not die — that is the audit-and-runbook service, and the A$149 audit is the whole fixed-fee tier in one purchase.

Prepared buyers pay the same fee and get more audit: the audit preparation checklist makes the five-day turnaround hold.

From the HIVE80lab kit