Skip to content

Cyber Security

Security advisory, certification and hands-on protection for New Zealand businesses, from vCISO to incident response.

01

What it is

We help businesses understand their security posture, lift it to a defensible standard, prove it to customers and insurers, and respond when something goes wrong. That spans ongoing advisory, framework certification, technical hardening and incident investigation. The outcome is security you can evidence, not just claim.

02

What is included

  • vCISO advisory: ongoing security leadership without a full time hire
  • Security posture assessments and roadmaps
  • Certification programmes against SMB1001 and alignment to CIS Controls v8.1, Essential Eight, NZISM and ISO 27001
  • Information security and privacy policy development, mapped across frameworks
  • Vendor and third party security risk assessments
  • Microsoft 365 and Entra ID security hardening, including conditional access and MFA rollout
  • Phishing resistance and staff security awareness training
  • Incident response and digital forensics, including business email compromise investigation
  • Cyber insurance readiness and evidence packs

03

Platforms and vendors

Microsoft 365, Entra ID and Azure security tooling, Intune baselines aligned to CIS benchmarks. Framework coverage across SMB1001, CIS Controls v8.1, Essential Eight, NZISM, ISO 27001 and the NZ Privacy Act 2020.

04

How we engage

vCISO retainers, fixed price assessments and certification programmes, and incident response on call-out. Managed security is available bundled with our managed IT agreements.

05

Standards and credentials

Practice built on SMB1001, CIS Controls v8.1, Essential Eight, NZISM and ISO 27001. Our director is the author of Resilient, a practical guide to leading cybersecurity for SMB leaders.

Next step

Book a scoping conversation.

We respond within one business day.