what we do

Security services, end to end

Whether you need a one-off penetration test or an ongoing managed security partner, we scope engagements around your actual risk — not a generic checklist.

01 / offensive

Penetration Testing

Our testers hold OSCP, OSCE, and CREST certifications and think like attackers because, in a former life, that's exactly what many of them did. We go beyond automated scanning to manually chain vulnerabilities the way a real adversary would.

CREST-aligned methodology Manual + automated testing Retest included

Coverage includes

  • External & internal network penetration testing
  • Web application & API testing (OWASP Top 10 and beyond)
  • Mobile application testing (iOS & Android)
  • Cloud security review (AWS, Azure, GCP)
  • Wireless network testing
  • Social engineering & phishing campaigns
typical engagement: 1–4 weeks

Frameworks we assess against

  • ISO/IEC 27001 readiness & gap analysis
  • New Zealand Information Security Manual (NZISM)
  • Privacy Act 2020 compliance review
  • PCI DSS scoping & gap assessment
  • SOC 2 pre-audit preparation
  • Vendor & third-party risk assessments
deliverable: board-ready report
02 / assurance

Audits & Compliance

Independent, evidence-based audits that translate technical risk into language your board, insurer, and customers understand — with a practical roadmap to close the gaps.

Framework-mapped Plain-English reporting Remediation roadmap
03 / continuous

Managed Security (SOC)

Most breaches aren't caught in the first hour because nobody's watching. Our managed detection & response service puts a real analyst on your alerts, 24 hours a day, backed by an incident response retainer. We're SIEM experts with years of hands-on experience tuning, deploying, and running detection platforms — not just reading vendor dashboards.

24/7/365 monitoring SIEM experts Human-reviewed alerts NZ-based analysts

What's included

  • Managed detection & response (MDR)
  • SIEM deployment & log monitoring
  • Threat intelligence & hunting
  • Incident response retainer (guaranteed SLA)
  • Monthly security posture reporting
from a monthly retainer

Where we plug in

  • Fractional / virtual CISO
  • Security architecture & design review
  • Policy & governance development
  • M&A security due diligence
  • Board & executive reporting
day-rate or retainer
04 / strategic

Security Consulting

Not every business needs a full-time CISO — but every business needs someone accountable for security strategy. We slot in as a fractional resource to build and run your programme.

Fractional CISO Vendor-neutral Board reporting
05 / people

Training & Awareness

Technology fails the moment someone clicks the wrong link. We run practical, engaging training that turns your staff into a genuine layer of defence.

Phishing simulations Role-based training Tabletop exercises

Programmes available

  • Ongoing phishing simulation campaigns
  • All-staff security awareness workshops
  • Secure coding training for developers
  • Executive & board tabletop exercises
  • Incident response drills
delivered on-site or remote
not sure where to start?

Tell us what you're worried about

Book a scoping call and we'll recommend the right starting point — no upsell, just a straight answer.

Talk to us