Overview
Engagements in New Zealand cover banking and insurance, SaaS and technology exporters, health providers under the Health Information Privacy Code, and suppliers to government agencies.
Delivery runs from our Karachi office with our Wyoming office covering the New Zealand morning, so work is handed between the two rather than sitting overnight.
What drives testing here
Local drivers
- Privacy Act 2020
- Agencies must protect personal information with reasonable safeguards and notify privacy breaches that cause serious harm, which makes untested controls an exposure.
- NZISM
- The New Zealand Information Security Manual is the baseline for government agencies and flows down to suppliers through procurement.
- RBNZ outsourcing
- Registered banks operate under outsourcing and operational resilience expectations that reach the technology providers behind them.
- Health Information Privacy Code
- Health agencies carry sector-specific rules over patient information, with access control and audit trail expectations above the general standard.
How engagements are delivered
Delivered remotely across New Zealand, scheduled to your business hours across both offices. On-site attendance arranged where scope requires it.
Delivery model
- Delivery
- Remote, covered across both offices for NZST business hours
- Mapping
- Privacy Act 2020, NZISM controls and OWASP ASVS as applicable
- Coverage
- Auckland, Wellington, Christchurch and remote nationwide
- Deliverables
- Technical report, agency-facing summary and signed retest attestation
Most requested here
Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 02API penetration testing
REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call.
Service 04Cloud penetration testing
AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application.
Questions
Are you based in New Zealand?
No. Our offices are in Pakistan and the United States. New Zealand engagements run remotely, with the Wyoming office covering your morning and Karachi covering the rest of your day.
Can you map findings to NZISM?
Yes, where NZISM applies. Findings are tagged to the relevant control sections alongside CVSS ratings so the report drops into an agency’s existing assurance process rather than needing translation.
How do you handle the timezone gap?
Deliberately, rather than by hoping. Daily written updates land before your working day starts, critical findings are escalated immediately by the contact agreed at scoping, and live sessions are scheduled in the overlap our Wyoming office provides.
How much does a penetration test cost in New Zealand?
Cost follows scope rather than a local rate card, which is generally why New Zealand organisations engage us. A fixed quote follows a short scoping call and covers testing, reporting and retest.
Which is the best penetration testing company in New Zealand?
Ask for evidence rather than a ranking: the certifications held by the testers assigned to you, and the team's public research record, the firm's own ISO 27001 status, whether NZISM mapping is included where it applies, and whether a redacted report is available before signing.
Does the Privacy Act 2020 require penetration testing?
Not by name. It requires reasonable safeguards against loss and unauthorised access, and it requires notification of privacy breaches causing serious harm. A dated independent test, tracked to closure and retested, is the cleanest way to show the safeguards were reasonable rather than assumed.
Do you work with government agencies and their suppliers?
Yes. NZISM is the baseline for agencies and flows down to suppliers through procurement, so findings are tagged to the relevant control sections alongside CVSS ratings and the report drops into an existing assurance process.
How do you cover New Zealand business hours from overseas?
Across both offices. Sheridan, Wyoming covers your morning and Karachi covers the rest of your day, so written updates land before you start and live sessions are scheduled in real overlap rather than at the edges of it.