Loading...
Resources
Practical guides, checklists, and threat intelligence from our consulting team. New Zealand-specific, practitioner-written, no form required.
We analysed adversary activity across 21 New Zealand organisations. This report maps the techniques used, the sectors most targeted, and the controls that stopped them. Required reading for any security team operating in the New Zealand market.
No forms, no gates. Download or read anything below directly.
What to look for, what to negotiate, and what to watch out for before you sign an AI services agreement with any major vendor. Covers data use and model training, IP indemnification, customer responsibilities, and a 10-point negotiation checklist.
A practitioner checklist for Azure and AWS environments. Covers identity, network segmentation, logging, and incident response posture.
A one-page template for presenting security risk to a board or executive team. Metric-led, plain English, no jargon.
Condensed reference mapping the most commonly tested NZISM controls to practical technical implementations for government agencies.
A 12-month engagement across a Māori health provider. What we found, how we prioritised remediation, and what the outcomes were.
On the horizon
Coming July 2026
A 90-day security programme for organisations without a full-time CISO. Prioritised controls, board reporting template, and a maturity baseline included.
Webinar — 10 July 2026
Tom Britton and Chris Hawksworth walk through how we layer AI analysis on top of threat-informed defence programmes to cut investigation time by 60%.
Coming August 2026
Our process for embedding organisational and company context into security controls — so controls get adopted, not ignored.
If you need a resource tailored to your environment, talk to Tom. A 30-minute conversation is usually enough to point you in the right direction.
Talk to Tom