Security Audits & Risk Assessments
An independent view of your security position, expressed as risk the board can weigh rather than findings it cannot.
Read morePosture review and hardening across AWS, Azure and GCP, ending in a prioritised remediation plan.
Cloud breaches are rarely exotic. They are overly permissive identity, a storage bucket exposed during a hurried deployment, a management port open to the internet, and logging that was never enabled. The controls that prevent them are well understood and unglamorous.
We review your environment against CIS benchmarks, the provider’s own security baselines and the expectations of NZISM and the Essential Eight where they apply, then rank every finding by exploitability and business impact so the work can be sequenced sensibly.
Every item carries a severity, an effort estimate and a named owner, not just a control reference.
Over-privileged roles and long-lived keys are the most common real-world entry point, so they lead the review.
Verification that you would actually be able to investigate an incident with the telemetry you currently retain.
We can implement the fixes as well as identify them, which is usually the faster path.
Accounts, subscriptions and workloads in scope agreed in writing, along with the standards being measured against.
Automated posture tooling combined with manual review of identity, networking, data handling and logging.
Findings ranked by exploitability and business impact, with quick wins separated from structural work.
Fixes delivered by us or by your team with our support, then re-tested to confirm closure.
A posture review examines configuration and design from the inside. A penetration test attempts to exploit from the outside. They answer different questions and complement each other.
It depends on your customers. NZISM and the Essential Eight for government-adjacent work, CIS benchmarks as a solid technical baseline, ISO 27001 or SOC 2 when enterprise customers ask.
No. It is read-only. Any change to the environment is agreed separately as remediation work.
An independent view of your security position, expressed as risk the board can weigh rather than findings it cannot.
Read moreLeast privilege that survives contact with reality, plus the joiner-mover-leaver process to keep it that way.
Read moreContinuous scanning across infrastructure, containers and dependencies — with triage so the list stays actionable.
Read moreWe will tell you what we would do, roughly what it costs, and whether it is worth doing yet.