Security Audits & Risk Assessments
An independent view of your security position, expressed as risk the board can weigh rather than findings it cannot.
Read moreReadiness, controls and evidence for the frameworks your customers ask about — without stalling delivery.
Compliance work becomes destructive when it is run as a documentation exercise disconnected from engineering. Controls get written to satisfy an auditor, engineers ignore them, and the evidence is assembled in a panic each year.
We implement controls where the work actually happens — in pipelines, in infrastructure as code, in access management — so evidence is produced automatically as a by-product of normal operation rather than gathered manually before each audit.
A clear view of what you already satisfy, since mature engineering practice usually covers more than expected.
Controls implemented in tooling so the audit trail accumulates without anyone assembling it.
A narrow, defensible scope keeps both the audit cost and the ongoing burden down.
A maintained response pack so enterprise security questionnaires stop consuming a week each.
The right framework and scope chosen based on what your customers and regulators genuinely require.
Current state mapped against the control set, with gaps ranked by effort and risk.
Technical controls, policies and automated evidence collection delivered alongside your engineers.
Internal review and auditor liaison, with evidence organised before the assessment begins.
SOC 2 is usually asked for by North American customers; ISO 27001 is more common in Europe, Asia-Pacific and government procurement. If neither is specifically demanded, ISO 27001 tends to travel further.
Yes. If you handle personal information about New Zealanders, the Privacy Act 2020 applies regardless of any other framework you are certified against.
No. Certification must come from an accredited body. We prepare you, implement the controls and support you through their assessment.
An independent view of your security position, expressed as risk the board can weigh rather than findings it cannot.
Read morePosture review and hardening across AWS, Azure and GCP, ending in a prioritised remediation plan.
Read moreLeast privilege that survives contact with reality, plus the joiner-mover-leaver process to keep it that way.
Read moreWe will tell you what we would do, roughly what it costs, and whether it is worth doing yet.