Cyber security consultant comparing an audit, risk assessment and penetration test with business leaders

Cyber Security Audit vs Risk Assessment vs Penetration Test

Table of Contents

When comparing a cyber security audit vs risk assessment, the audit checks whether agreed controls are in place and operating against defined criteria, while the risk assessment identifies threats and prioritises them by likelihood and business impact. A penetration test is different again: it is an authorised, scoped attempt to exploit technical weaknesses.

Last updated: 31 July 2026

The short answerStart with a risk assessment when you need to decide what matters and where to invest. Use an audit when you need evidence that controls meet a framework, policy, contract or assurance requirement. Commission a penetration test when you need to validate whether a specific system or attack path can actually be compromised.

These services sit within Stanfield IT’s wider Cyber Security Services offering for Australian businesses. They can be purchased separately, but they are often most useful as connected parts of one security-improvement program.

The labels are not always used consistently. One provider’s “audit” may be another provider’s “assessment”. Before buying, focus on the question the engagement will answer, the agreed scope, the method used and the deliverables you will receive.

Cyber security audit vs risk assessment vs penetration test: quick comparison

Quick comparison of the three assessment types
Consideration Audit Risk assessment Penetration test
Primary purpose Control review Business risk prioritisation Find exploitable weaknesses
Main method Evidence and configuration review Systems, threats, impact and controls Controlled attack simulation
Typical output Findings and compliance gaps Risk register and roadmap Technical vulnerabilities and proof
Best used when Assurance or audit requirement Planning investment and priorities Testing actual technical exposure
Frequency Periodic Annual and after major change Risk-based and after major change

Frequency depends on the applicable framework, contract, regulator and risk profile. “Annual and after major change” is a practical planning baseline for many organisations, not a universal legal or ISO requirement. ISO 27001 calls for risk assessments at planned intervals and when significant changes are proposed or occur.

Choose an audit when…

You need evidence that defined controls or requirements are being met.

Choose a risk assessment when…

You need to decide which risks matter most and what to fund first.

Choose a penetration test when…

You need to know whether a scoped technical target can be exploited.

What is a cyber security audit?

A cyber security audit is an evidence-based review of controls against defined criteria. Those criteria may come from an internal policy, a customer contract, a framework such as the Essential Eight, a standard such as ISO 27001, an insurer’s questionnaire or another agreed control set.

This follows ISO’s definition of auditing as a systematic, independent and documented process that evaluates verifiable evidence against agreed criteria.

The core audit question is: “Can we demonstrate that the controls within scope meet the agreed criteria?”

Depending on its objective and scope, an audit may assess control design, implementation and operating effectiveness.

An auditor may inspect policies, procedures, system configurations, user and administrator access, patch records, security logs, backup tests, incident exercises, supplier arrangements and other evidence. Interviews can help explain how processes work, but a sound audit does not rely on statements alone. It verifies what can be observed, tested or documented.

Business leaders prioritising cyber risks by likelihood and impact during a risk assessment
A useful audit connects policies and control requirements with evidence from the environment.

Not every audit is a certification audit

“Audit” is an overloaded term. An organisation may conduct an internal audit, commission a readiness or gap review, undergo a customer or supplier audit, or engage an independent certification body for a formal certification audit. These are not interchangeable.

Stanfield IT’s IT Audit & Technology Assessment is a broader review of systems, security, costs, licensing, cloud services, backups, infrastructure and operational maturity. It helps a business understand its technology environment and build a prioritised roadmap. Where formal ISO certification is required, the certification decision must come from an accredited third-party certification body.

An audit may use vulnerability scans or penetration-test results as evidence, but it is not the same as either. Its main limitation is scope: an audit can only provide assurance against the criteria and evidence examined at that point in time.

For an initial self-review, Stanfield IT’s Cyber Security Audit Checklist for Australian Businesses covers common governance, identity, endpoint, cloud, network and recovery controls. A checklist can surface obvious gaps, but it does not replace independent assurance where that is required.

What is a cyber security risk assessment?

A cyber security risk assessment helps leaders make decisions. It identifies the business processes, systems, information and services that matter; considers credible threats and weaknesses; evaluates existing controls; and estimates the likelihood and consequence of each risk scenario.

The approach aligns with NIST’s Guide for Conducting Risk Assessments, which treats risk assessment as an input to prioritised risk response and decision-making.

The central question is: “What could materially harm the business, how likely is it, and what should we do first?”

A sound assessment should distinguish between inherent risk before controls and residual risk after existing controls are considered. It should also name a risk owner and a treatment decision. Common options are to reduce the risk, avoid the activity, transfer part of the financial risk or formally accept the remaining exposure.

Ethical security analyst conducting an authorised penetration test of a business network
A risk assessment connects technical weaknesses with operational, financial, privacy and customer impact.

The principal output is normally a risk register supported by an executive summary and a prioritised treatment roadmap. Stanfield IT’s Cyber Security Risk Assessment reviews systems, people, processes and controls, then prioritises findings using likelihood, business impact, urgency and remediation effort.

A risk assessment can recommend a penetration test where exploitability is uncertain or a high-value system warrants deeper validation. Its limitation is that it estimates risk; it does not usually attempt to prove every technical attack path.

What is a penetration test?

A penetration test is an authorised, controlled attack simulation against an agreed target. It may cover internet-facing infrastructure, an internal network, a web application, an API, a cloud workload or another defined environment.

The central question is: “Can a capable attacker exploit this target, how far could they get and what would the practical impact be?”

Before testing begins, the client and tester should agree on the rules of engagement: targets, exclusions, test windows, permitted techniques, escalation contacts, data-handling requirements and stop conditions. This protects live systems and keeps the work legal, controlled and relevant.

Cyber security consultant and IT manager reviewing control evidence during an audit
Penetration testing validates selected attack paths within an agreed scope and time window.

A useful penetration testing engagement provides validated findings, evidence, affected assets, severity and business impact, an attack narrative, remediation guidance and an option to retest fixes.

A penetration test is narrower and more active than an organisation-wide risk assessment. It is also a point-in-time exercise. A clean result does not prove that the whole organisation is secure; it means the tester did not identify a successful attack path within the agreed scope, constraints and test period.

Where does vulnerability management fit?

Vulnerability management sits between periodic assurance and continuous operational security. It is the repeatable process of discovering assets, scanning for known weaknesses and unsafe configurations, validating findings, prioritising remediation, assigning owners, checking fixes and reporting trends.

The Australian Signals Directorate defines vulnerability management as identifying, prioritising and responding to vulnerabilities. The important distinction is that it is a managed cycle, not a one-off scanner report.

It helps answer: “Which known technical weaknesses exist now, which ones matter most and are they being closed quickly enough?”

A scanner produces findings. A vulnerability assessment adds analyst validation and context. A mature Vulnerability Management service adds ownership, remediation tracking, exceptions, rescanning and evidence of progress.

Vulnerability management should not be sold as a penetration test. Automated scanning can cover many assets frequently, while a penetration tester uses judgement to chain weaknesses and pursue a defined objective. The two work well together: recurring scanning identifies exposure, and a penetration test validates the attack paths that matter most.

What does each service examine?

The scope matters more than the service label. The table below shows the normal emphasis, but an engagement can be broadened or narrowed by agreement.

What each service normally examines
Area examined Audit Risk assessment Penetration test Vulnerability management
Policies and required controls Primary focus Reviewed as existing controls Usually limited Usually outside scope
People, ownership and governance Strong focus Strong focus Limited unless expressly scoped Remediation ownership only
Business impact and criticality Supports finding severity Primary focus Applied to technical findings Used for prioritisation
Configuration and control evidence Primary focus Reviewed at a risk-appropriate level Tested where relevant to the target Scanned and validated where supported
Known technical vulnerabilities May use scan evidence One input to overall risk Investigated and potentially chained Primary focus
Real exploitability Not usually proven Estimated unless tested Primary focus Limited validation, not full exploitation
Change over time Periodic snapshot Periodic and event-driven Point-in-time Continuous or regularly scheduled

What deliverables should the client receive?

Do not buy an assessment based on the activity alone. The report, remediation plan and follow-through determine whether the work improves security.

Minimum useful deliverables by service
Service Minimum useful deliverables
Audit Objective, criteria, scope and exclusions; evidence reviewed; control ratings; gaps or nonconformities; limitations; executive summary; and prioritised corrective actions.
Risk assessment Methodology; critical assets and processes; threat scenarios; likelihood and impact; inherent and residual risk; existing controls; risk owners; treatment decisions; and a prioritised roadmap.
Penetration test Scope and rules of engagement; methodology; attack narrative; validated findings; affected assets; evidence of impact; severity and business context; remediation advice; and retest results where included.
Vulnerability management Asset coverage; validated findings; risk-based priorities; remediation owners and target dates; exceptions; ageing; rescans; closure evidence; and trend reporting.

Buyer tipAsk to see a redacted sample report before engaging a provider. It will quickly show whether you will receive a useful executive summary and remediation plan or merely a scanner export and a long list of technical observations.

Which service is right for your situation?

Which service is right for cyber insurance?

Start with the insurer or broker’s current questionnaire and requested evidence. Cyber-insurance requirements vary, and no single assessment guarantees cover, a lower premium or a successful claim.

Underwriting questionnaires commonly focus on whether important controls exist and can be evidenced: multi-factor authentication, backups and restore testing, patching, endpoint protection, monitoring, security awareness, privileged access and incident-response capability. The Insurance Council of Australia’s cyber insurance paper outlines the governance, identity, backup, monitoring and response information that underwriters may examine. A controls-focused audit or framework assessment can organise that evidence. A risk assessment can identify gaps and support a prioritised remediation plan.

A penetration test may be appropriate when the insurer expressly requests one, when an internet-facing application creates material exposure or when technical assurance is otherwise justified. A penetration test alone will not answer the broader governance, people, recovery and control questions in most insurance applications.

Which service is right for ISO 27001?

For ISO/IEC 27001, a formal information-security risk assessment and risk-treatment process are foundational. Internal audits are also part of the ongoing Information Security Management System, or ISMS, assurance cycle.

A penetration test is not a universal substitute for either process, and ISO 27001 does not automatically require every organisation to run the same penetration test. Technical testing should be selected according to the organisation’s risks, chosen controls, contractual requirements and environment.

In practical terms, an organisation preparing for ISO 27001 will usually need a defined scope, asset and risk information, policies and procedures, implementation evidence, internal audit findings, management review and tracked corrective actions. Penetration-test or vulnerability-management reports can support the evidence base where relevant.

Stanfield IT’s ISO 27001 Services can support risk assessment, technical uplift, evidence preparation and audit readiness. Certification itself must be issued by an accredited third-party certification body.

Which service is right after a cyber incident?

During an active incident, routine auditing and broad penetration testing are not the first priorities. Incident response comes first: confirm what happened, contain the threat, preserve useful evidence, remove the attacker’s access and restore safe operations. The Australian Signals Directorate’s Cyber Security Incident Response Planning guidance explains the preparation and response lifecycle.

After stabilisation, use a post-incident review to identify root causes and control failures. Update the risk assessment with what was learned, audit whether corrective controls have been implemented, and use targeted technical testing to verify remediation where appropriate. Avoid uncontrolled testing that could overwrite evidence or disrupt recovery.

If suspicious activity is still active, start with Cyber Security Incident Response, not a routine assessment booking.

Which service is right before a major cloud migration?

Begin with a risk and architecture assessment before migration. Identify the information and systems moving to the cloud, their sensitivity and criticality, identity and access requirements, shared-responsibility boundaries, logging, backup, recovery, supplier dependencies and incident-response needs. The Australian Signals Directorate’s cloud security guidance for tenants provides a useful Australian assurance reference.

As the environment is implemented, complete configuration and control reviews against the approved design. Before deployment of material changes where feasible, use vulnerability scanning and targeted penetration testing of customer-controlled components where justified, within the cloud provider’s current rules—such as the published Microsoft Cloud Penetration Testing Rules of Engagement and AWS penetration-testing policy—and the agreed scope.

The sensible sequence is therefore: risk assessment before the move, evidence-based control review during implementation, and targeted technical validation before production where feasible—or as soon as safely practicable after go-live. Stanfield IT’s Cloud Security service can connect these steps across Microsoft 365, Azure, AWS and other cloud platforms.

Which service is right for customer or investor due diligence?

Customer and investor due diligence usually needs transferable assurance rather than a raw technical data dump. A concise assurance pack may include the applicable certification or independent audit summary, control evidence, a risk summary, remediation status, incident-response arrangements and relevant policies.

For a customer-facing application or platform, a recent independent penetration-test executive summary can strengthen technical assurance. The full report may contain sensitive attack paths, configurations or evidence and should not be distributed without appropriate confidentiality, access and redaction controls.

A risk assessment remains useful internally because it shows management understands material exposures and has assigned treatment owners. It is usually supplementary evidence rather than a replacement for whatever assurance the customer, lender or investor has specifically requested.

Can the services be combined?

Yes. Combining the services is often the strongest approach because each answers a different question:

  • Risk assessment: Which scenarios could cause the most harm?
  • Audit: Are the required controls implemented and supported by evidence?
  • Vulnerability management: Which known technical weaknesses are appearing and being closed?
  • Penetration test: Can selected weaknesses or attack paths be exploited in practice?

The reports should still retain separate objectives, scopes and limitations. A scanner export should not be relabelled as a penetration test, and a penetration-test report should not be presented as a complete business risk assessment.

Recommended assessment sequence

For an organisation that does not yet have a clear view of its security posture, the following sequence is practical:

  1. Confirm the driver and scope. Identify the business decision, contractual or regulatory requirement, critical systems, sensitive information and stakeholders.
  2. Complete a risk or framework assessment. Establish which threats and control gaps matter most, then create a risk register and treatment roadmap.
  3. Fix urgent control weaknesses. Address obvious exposure such as missing MFA, unsupported internet-facing systems, excessive privilege or untested backups before paying to rediscover it.
  4. Establish vulnerability management. Build repeatable asset visibility, scanning, prioritisation, remediation ownership and validation.
  5. Penetration-test high-value or changed systems. Use risk and vulnerability information to focus testing on the targets and attack paths that matter.
  6. Complete the required audit or assurance review. Test control evidence against the applicable framework, policy, contract or standard.
  7. Retest and report progress. Verify corrective actions, update residual risk and show leadership what improved, what remains exposed and who owns the next action.

The order can change. A prescribed customer audit, urgent internet-facing exposure, active transaction deadline or incident may require a different starting point. The first step is always to define the outcome you need rather than purchasing a familiar service name.

Questions to ask before engaging a provider

  • What exact question will this engagement answer?
  • What is included, excluded and assumed in the scope?
  • Which framework, methodology or testing standard will be used?
  • Will evidence be verified or will the work rely mainly on interviews?
  • For active testing, what are the rules of engagement and stop conditions?
  • Who will conduct the work, and when is independence required?
  • Will the report serve both executives and technical teams?
  • Are remediation guidance, prioritisation and retesting included?
  • How will sensitive evidence and reports be stored, transmitted and destroyed?

Frequently asked questions

What is the difference between a cyber security audit and a risk assessment?

An audit tests evidence against defined criteria, such as a framework, policy or contract. A risk assessment identifies threat scenarios and prioritises them using likelihood and business impact. The audit asks whether required controls are operating; the risk assessment asks which risks matter most and how they should be treated.

Is a penetration test the same as a cyber security audit?

No. A penetration test actively attempts to exploit weaknesses in an authorised, defined scope. An audit reviews evidence and controls against agreed criteria. A penetration-test report can support an audit, but it does not examine the full range of governance, people, process and assurance requirements.

Which should we do first: a risk assessment or penetration test?

Start with a risk assessment when you do not yet know which systems and scenarios deserve priority. Start with a penetration test when the target and business objective are already clear—for example, validating a new internet-facing application. Risk information should normally guide the test scope.

Is vulnerability scanning the same as penetration testing?

No. Scanning identifies known weaknesses and configuration issues across many assets. Penetration testing uses human judgement to validate and potentially combine weaknesses in pursuit of an agreed objective. Vulnerability management also includes prioritisation, remediation ownership, rescanning and trend reporting.

Does ISO 27001 require a penetration test?

Not automatically in every case. ISO 27001 requires risk assessment, risk treatment and internal audit processes. Penetration testing may be selected where the organisation’s risks, controls, customers or technical environment justify it, but it does not replace the ISMS risk or audit requirements.

Which assessment does a cyber insurer require?

Requirements vary by insurer and policy. Begin with the current proposal or renewal questionnaire. A controls audit can organise evidence, a risk assessment can identify and prioritise gaps, and a penetration test may be requested for particular systems. None of these guarantees insurance acceptance or claim payment.

How often should these services be performed?

Use a risk- and requirement-based schedule. Audits should follow the applicable framework, contract or assurance cycle. Risk assessments should occur at planned intervals and after major change. Penetration tests should follow material change or identified exposure, while vulnerability management should run continuously or on a regular schedule.

Can one provider conduct all three services?

Yes, provided the provider has the capability and the required independence is preserved. Using one team can improve context and remediation continuity, but formal certification, regulated assurance or customer requirements may call for an independent auditor or certification body.

Key takeaways

  • An audit provides evidence against defined criteria.
  • A risk assessment prioritises business risk and investment.
  • A penetration test validates exploitability within a controlled scope.
  • Vulnerability management provides recurring technical exposure and remediation tracking.
  • The right sequence depends on the business decision, obligation, environment and current level of visibility.
  • A useful engagement ends with owners, priorities, remediation actions and a way to verify progress.

Useful sources and further reading

Experience better IT services

If your IT feels reactive or unclear, we’ll stabilise the essentials and align it to your business goals.

IT Services for Australian Businesses - Stanfield IT
Scroll to Top