If you are a New Zealand organisation looking to secure your AI adoption in 2026, you have more choices than you did a year ago. Four consultancies now market AI security services in the NZ market. This guide compares them fairly so you can make an informed decision — including where CyberTeam is not the right fit.
The four AI security consultancies operating in New Zealand
As of September 2026, four consultancies actively market AI security services in the NZ market: CyberTeam, CyberCX, Bastion Security Group, and ASI Solutions. Each has a distinct focus.
CyberTeam — AI Security Engineering
CyberTeam is a New Zealand-owned specialist consultancy, ISANZ 2025 Cybersecurity Startup of the Year. Its differentiator is engineering: CyberTeam builds the infrastructure that makes AI-assisted security work defensible.
What CyberTeam does well:
- MCP server security — the only NZ consultancy publishing peer-reviewed methodology for Model Context Protocol server assessment, hardening, and monitoring
- Attestation chains — hash-linked, cryptographically signed audit logs of every AI invocation, verifiable offline by any auditor
- AI threat modelling — STRIDE/DREAD analysis of AI-integrated systems, mapped to the MCP threat taxonomy (arXiv 2603.22489)
- Playbook MCP delivery — authenticated instruction delivery to Claude, Cursor, and GitHub Copilot with supply-chain provenance
- NZ regulatory alignment — NZISM, Privacy Act 2020, APRA CPS 234, and ISO/IEC 42001
Where CyberTeam is not the right fit:
- If you need a 24/7 managed SOC monitoring AI workloads, CyberTeam does not operate one
- If you need a large delivery bench for a nationwide rollout across 500+ endpoints, larger providers have more scale
- If your requirement is off-the-shelf AI firewall product deployment, a product-led vendor will move faster
Pricing model: Scaling rate card — day rate reduces with committed engagement length.
CyberCX — Secure AI Solutions
CyberCX is the largest cybersecurity consultancy operating across Australia and New Zealand, now part of Accenture. Its Secure AI Solutions offering is broad and enterprise-scale.
What CyberCX does well:
- Scale — the largest sovereign cybersecurity capability in ANZ, with a full delivery bench for large programmes
- AI penetration testing — model extraction, adversarial attacks, prompt injection testing across enterprise AI deployments
- Managed SOC for AI — 24/7 monitoring integrated into their existing Security Operations Centre capability
- AI landing zones — reference architectures for AI-ready cloud environments, particularly on Azure
Where CyberCX may not be the right fit:
- Smaller engagements can feel expensive relative to specialist consultancies
- Standardised methodology across a large team means less bespoke engineering per engagement
- The AI security offering is a specialisation within a much larger portfolio, not the primary focus
Pricing model: Enterprise; not publicly listed.
Bastion Security Group — AI Readiness Assessment
Bastion Security offers a structured AI Readiness Assessment aligned to ISO/IEC 42001, NZISM, NIST AI RMF, and CIS Benchmarks. Bastion also has an Australian presence (Melbourne office).
What Bastion does well:
- AI governance and readiness — structured assessment framework mapping controls to multiple standards simultaneously
- AI Privacy Impact Assessments — specifically aligned to the NZ Privacy Act 2020
- Microsoft Copilot and OpenAI configuration reviews — deep dive into how these platforms are deployed and controlled
- Certification-oriented — outputs designed to support ISO 42001 certification pathways
Where Bastion may not be the right fit:
- If your need is engineering rather than assessment (build the controls vs. audit them), Bastion's core offering is assessment-led
- The offering focuses on adoption readiness rather than the deep engineering of AI-agent infrastructure
Pricing model: Not publicly listed; scoped per engagement.
ASI Solutions — AI Security (Cloudflare-backed)
ASI Solutions is a New Zealand technology reseller that markets AI Security as a product-led service built on Cloudflare's AI Gateway.
What ASI does well:
- AI firewall protection — real-time scanning of prompts and responses to block injection and data exfiltration, using Cloudflare's stack
- Automatic AI discovery — identifies AI models and APIs across web properties without manual inventory work
- Fast time-to-value — product-based deployment is faster than a bespoke engineering engagement
- NZ-based delivery — engineers on the ground with local compliance knowledge
Where ASI may not be the right fit:
- Product-led means the depth of custom engineering is limited to what the underlying Cloudflare platform supports
- If your risk is inside the AI agent workflow (MCP servers, tool poisoning, attestation), a runtime firewall does not address it
- Suited to organisations that want AI protection as a managed subscription, not a consulting engagement
Pricing model: Subscription-based product with configuration services.
How to choose
The four consultancies solve different problems. Pick based on where your risk sits:
| Your primary need | Best fit |
|---|---|
| Build defensible AI-assisted workflows for consultants and internal security teams | CyberTeam — engineering-led, MCP + attestation chain focus |
| Enterprise-scale AI deployment across a large organisation with 24/7 monitoring needs | CyberCX — scale, SOC, and full portfolio integration |
| Structured AI governance assessment aligned to ISO 42001 and NZ Privacy Act | Bastion Security — assessment-led, certification-oriented |
| Fast-deploy runtime AI protection with managed service model | ASI Solutions — Cloudflare-based product deployment |
Questions to ask any AI security consultancy in New Zealand
Regardless of who you choose, the following questions separate substance from marketing:
- What is your position on the OWASP LLM Top 10, specifically prompt injection? Prompt injection appears in over 73% of production AI deployments (Obsidian Security, 2026). If they cannot explain their approach in specifics, keep looking.
- How do you handle MCP server security? If Claude, Cursor, or GitHub Copilot are in your consulting toolchain, MCP is the attack surface. Vague answers here matter.
- What is your attestation model for AI-assisted work? How do they prove to your internal audit what the AI was asked and what it produced?
- Which standards do you map to by default? Look for NZISM, ISO/IEC 42001, NIST AI RMF, and APRA CPS 234 for financial services.
- Can I see a redacted deliverable? A consultancy that cannot show sample outputs is inexperienced or over-marketed.
- Who does the work? The consultant in the sales conversation should be the consultant on the engagement. Confirm this in writing.
The bottom line
CyberTeam is one of four NZ consultancies now offering AI security services, and we are not the right choice for every engagement. Our depth is in AI security engineering — the MCP servers, attestation chains, and threat models that make AI-assisted security defensible under audit. If that is your problem, we would like to talk. If it is not, use the table above to find the consultancy that is a better fit.
Either way, ask the six questions.
