Cyber Security Services in New Zealand

Independent cyber security and compliance advisory for New Zealand organisations — Privacy Act 2020, the NZISM and Protective Security Requirements, ISO/IEC 27001 certification support and SOC 2 readiness.

Cyber security and compliance in the New Zealand context

New Zealand organisations face a compliance environment that is distinct from Australia’s, and advice written for the Australian market often misses what actually applies here. Security Solution Consultants works with New Zealand clients on the obligations that genuinely bind them, rather than transplanting an offshore checklist.

The Privacy Act 2020

The Privacy Act 2020 governs how agencies collect, hold, use and disclose personal information, and is administered by the Office of the Privacy Commissioner. Its most operationally significant feature is the notifiable privacy breach scheme: where a privacy breach has caused, or is likely to cause, serious harm, the Privacy Commissioner and affected individuals must be notified. The Act also restricts disclosure of personal information to overseas recipients unless comparable safeguards are in place — a provision that catches many organisations using offshore cloud services without having assessed it.

The NZISM and the Protective Security Requirements

The New Zealand Information Security Manual, issued by the National Cyber Security Centre within the GCSB, sets the baseline technical controls for government agencies and is increasingly written into supplier contracts. The Protective Security Requirements provide the broader governance framework covering security governance, personnel, physical and information security.

If you supply government, expect to be asked how you align to these. Suppliers that can evidence alignment through a documented management system deal with procurement far more efficiently than those assembling answers per tender.

Sector-specific expectations

Health providers work to HISO 10029, the Health Information Security Framework. Financial institutions operate under Reserve Bank expectations on cyber resilience and outsourcing. Critical infrastructure operators face rising scrutiny of operational technology and third-party dependencies. These sit on top of the Privacy Act rather than replacing it.

Our cyber security services for New Zealand organisations

  • ISO/IEC 27001 implementation and certification support — scoping, gap analysis, risk assessment, Statement of Applicability, internal audit and support through the certification audit.
  • Privacy Act 2020 readiness — privacy impact assessments, breach response procedures, cross-border transfer assessment and records of processing.
  • NZISM and PSR alignment — control mapping and evidence for organisations supplying government agencies.
  • SOC 2 readiness — Trust Services Criteria mapping and system description for providers whose overseas customers require attestation.
  • Security governance and virtual CISO — ongoing security leadership for organisations without a full-time CISO.
  • Third-party and supply chain risk — vendor assessment programmes proportionate to the risk each supplier actually carries.
  • Penetration testing and external attack surface review — identifying what an attacker can reach from outside your perimeter.

ISO 27001 certification for New Zealand organisations

ISO/IEC 27001 is the certification most often requested of New Zealand suppliers, both by government and by overseas customers. Certificates are issued by certification bodies accredited by JAS-ANZ, the joint accreditation system covering Australia and New Zealand.

We are an advisory firm, not a certification body. We build and operate the management system with you, then support you through the audit — but the certificate is awarded by an independent certification body. That separation is a requirement of the scheme, and any consultancy suggesting otherwise is misrepresenting how certification works.

For most New Zealand organisations starting without a formal ISMS, six to twelve months from kick-off to certification audit is realistic. Scope is the main cost driver: certifying the specific service your customers ask about is usually far more economical than certifying the entire organisation.

How we work with New Zealand clients

We work remotely with New Zealand organisations as standard, with on-site attendance for workshops, audits and board sessions where it adds value. Our consultants work across Australia, New Zealand and the Asia-Pacific region, which means the guidance you get reflects how these frameworks are actually assessed rather than how they read on paper.

Where a client wants tooling rather than spreadsheets, our GRCLens compliance platform can run the programme — including deployment on-premises or in a New Zealand-hosted environment where data residency matters.

Frequently asked questions

Do you have consultants based in New Zealand?

We serve New Zealand clients from our Asia-Pacific practice, working remotely as standard and travelling on site for workshops, audits and board engagements. Tell us what your engagement needs and we will be straightforward about how we would resource it.

Does the Privacy Act 2020 require us to report every breach?

No. Notification is required where a privacy breach has caused, or is likely to cause, serious harm to an affected individual. Assessing whether that threshold is met is a judgement call, which is why having a documented assessment process before a breach occurs matters more than the notification itself.

We supply a government agency. Do we need to comply with the NZISM?

The NZISM binds government agencies directly, and agencies commonly pass equivalent requirements to suppliers through contract. Whether it applies to you depends on your contract terms and the classification of information you handle, so the contract is the place to start.

Can ISO 27001 cover our Privacy Act obligations too?

Substantially, yes. Many Privacy Act controls map onto ISO/IEC 27001 Annex A, so a well-scoped ISMS covers much of the ground. Privacy-specific duties such as breach notification and cross-border transfer assessment still need to be addressed explicitly rather than assumed.

Protective Security Requirements (PSR) advisory

The Protective Security Requirements are New Zealand’s protective security policy framework, overseen by the New Zealand Security Intelligence Service. The PSR spans four areas — security governance, personnel security, information security and physical security — and mandated agencies report on their maturity through an annual PSR assurance process.

If you are not a mandated agency, the PSR still reaches you through procurement. Agencies routinely flow PSR-derived expectations down to suppliers by contract, particularly where a supplier handles official information or provides a service the agency depends on. In practice that means being able to evidence security governance, vetted personnel, information handling and physical controls — not simply asserting them in a tender response.

We help organisations map what the PSR actually requires of them, close the gaps that matter, and produce evidence that survives assurance review rather than being assembled the week before it is due.

Minimum Cyber Security Standards (MCSS)

The Minimum Cyber Security Standards were released by the National Cyber Security Centre in 2025 under the Government Chief Information Security Officer mandate. They set out ten standards covering foundational cyber security practice, and are positioned deliberately between the highly detailed New Zealand Information Security Manual and the broader NCSC Cyber Security Framework — comparable in intent to Australia’s Essential Eight or the UK’s Cyber Essentials.

The standards use a Capability Maturity Model, with the minimum expectation set at CMM2, “Planned & Tracked”. That wording matters: it is not enough for a control to exist somewhere in the environment. It has to be planned, documented, assigned to an owner and actively tracked.

The standards apply to the 37 agencies mandated under the PSR, and implementation is reported through the PSR assurance process from April 2026. Suppliers to those agencies should expect the requirements to arrive through contracts even where the standards do not bind them directly.

We run MCSS gap assessments against the ten standards, establish the evidence needed to demonstrate CMM2, and prioritise remediation so that reporting deadlines are met without unnecessary spend.

Critical infrastructure cyber security in New Zealand

New Zealand’s regulatory approach to critical infrastructure is changing. The Department of the Prime Minister and Cabinet leads the Critical Infrastructure Resilience programme, and in February 2026 released a discussion document, Enhancing the cyber security of New Zealand’s critical infrastructure system, aimed squarely at owners and operators who would be affected by regulatory reform. Consultation ran from 27 February to 19 April 2026, and submissions are informing further advice to Cabinet. The New Zealand Cyber Security Strategy 2026–2030 was published alongside it.

To be clear about where this stands: these are proposals, not law. No new statutory cyber security obligations for critical infrastructure operators are in force in New Zealand today, and any consultancy telling you otherwise is overstating the position.

The direction of travel is nonetheless unambiguous, and it mirrors what Australia did through the Security of Critical Infrastructure Act and the CIRMP rules. Operators who begin building a defensible risk management programme now will be positioned to meet obligations when they arrive, rather than compressing the work into whatever transition period is granted. We help operators assess their current position against the likely shape of reform, with particular attention to operational technology and third-party dependency risk — the two areas that consistently prove hardest to evidence.

Elsewhere on this site

For background on our practice, see our profile as a cyber security company in New Zealand. For city-specific pages, see Auckland and Wellington.

Talk to us about your security and compliance programme

Tell us where you are and what you are being asked to demonstrate, and we will set out a realistic path — including where you may need less work than you expect. Get in touch.