Independent cyber security and compliance advisory for New Zealand organisations — Privacy Act 2020, the NZISM and Protective Security Requirements, ISO/IEC 27001 certification support and SOC 2 readiness.
New Zealand organisations face a compliance environment that is distinct from Australia’s, and advice written for the Australian market often misses what actually applies here. Security Solution Consultants works with New Zealand clients on the obligations that genuinely bind them, rather than transplanting an offshore checklist.
The Privacy Act 2020 governs how agencies collect, hold, use and disclose personal information, and is administered by the Office of the Privacy Commissioner. Its most operationally significant feature is the notifiable privacy breach scheme: where a privacy breach has caused, or is likely to cause, serious harm, the Privacy Commissioner and affected individuals must be notified. The Act also restricts disclosure of personal information to overseas recipients unless comparable safeguards are in place — a provision that catches many organisations using offshore cloud services without having assessed it.
The New Zealand Information Security Manual, issued by the National Cyber Security Centre within the GCSB, sets the baseline technical controls for government agencies and is increasingly written into supplier contracts. The Protective Security Requirements provide the broader governance framework covering security governance, personnel, physical and information security.
If you supply government, expect to be asked how you align to these. Suppliers that can evidence alignment through a documented management system deal with procurement far more efficiently than those assembling answers per tender.
Health providers work to HISO 10029, the Health Information Security Framework. Financial institutions operate under Reserve Bank expectations on cyber resilience and outsourcing. Critical infrastructure operators face rising scrutiny of operational technology and third-party dependencies. These sit on top of the Privacy Act rather than replacing it.
ISO/IEC 27001 is the certification most often requested of New Zealand suppliers, both by government and by overseas customers. Certificates are issued by certification bodies accredited by JAS-ANZ, the joint accreditation system covering Australia and New Zealand.
We are an advisory firm, not a certification body. We build and operate the management system with you, then support you through the audit — but the certificate is awarded by an independent certification body. That separation is a requirement of the scheme, and any consultancy suggesting otherwise is misrepresenting how certification works.
For most New Zealand organisations starting without a formal ISMS, six to twelve months from kick-off to certification audit is realistic. Scope is the main cost driver: certifying the specific service your customers ask about is usually far more economical than certifying the entire organisation.
We work remotely with New Zealand organisations as standard, with on-site attendance for workshops, audits and board sessions where it adds value. Our consultants work across Australia, New Zealand and the Asia-Pacific region, which means the guidance you get reflects how these frameworks are actually assessed rather than how they read on paper.
Where a client wants tooling rather than spreadsheets, our GRCLens compliance platform can run the programme — including deployment on-premises or in a New Zealand-hosted environment where data residency matters.
We serve New Zealand clients from our Asia-Pacific practice, working remotely as standard and travelling on site for workshops, audits and board engagements. Tell us what your engagement needs and we will be straightforward about how we would resource it.
No. Notification is required where a privacy breach has caused, or is likely to cause, serious harm to an affected individual. Assessing whether that threshold is met is a judgement call, which is why having a documented assessment process before a breach occurs matters more than the notification itself.
The NZISM binds government agencies directly, and agencies commonly pass equivalent requirements to suppliers through contract. Whether it applies to you depends on your contract terms and the classification of information you handle, so the contract is the place to start.
Substantially, yes. Many Privacy Act controls map onto ISO/IEC 27001 Annex A, so a well-scoped ISMS covers much of the ground. Privacy-specific duties such as breach notification and cross-border transfer assessment still need to be addressed explicitly rather than assumed.
The Protective Security Requirements are New Zealand’s protective security policy framework, overseen by the New Zealand Security Intelligence Service. The PSR spans four areas — security governance, personnel security, information security and physical security — and mandated agencies report on their maturity through an annual PSR assurance process.
If you are not a mandated agency, the PSR still reaches you through procurement. Agencies routinely flow PSR-derived expectations down to suppliers by contract, particularly where a supplier handles official information or provides a service the agency depends on. In practice that means being able to evidence security governance, vetted personnel, information handling and physical controls — not simply asserting them in a tender response.
We help organisations map what the PSR actually requires of them, close the gaps that matter, and produce evidence that survives assurance review rather than being assembled the week before it is due.
The Minimum Cyber Security Standards were released by the National Cyber Security Centre in 2025 under the Government Chief Information Security Officer mandate. They set out ten standards covering foundational cyber security practice, and are positioned deliberately between the highly detailed New Zealand Information Security Manual and the broader NCSC Cyber Security Framework — comparable in intent to Australia’s Essential Eight or the UK’s Cyber Essentials.
The standards use a Capability Maturity Model, with the minimum expectation set at CMM2, “Planned & Tracked”. That wording matters: it is not enough for a control to exist somewhere in the environment. It has to be planned, documented, assigned to an owner and actively tracked.
The standards apply to the 37 agencies mandated under the PSR, and implementation is reported through the PSR assurance process from April 2026. Suppliers to those agencies should expect the requirements to arrive through contracts even where the standards do not bind them directly.
We run MCSS gap assessments against the ten standards, establish the evidence needed to demonstrate CMM2, and prioritise remediation so that reporting deadlines are met without unnecessary spend.
New Zealand’s regulatory approach to critical infrastructure is changing. The Department of the Prime Minister and Cabinet leads the Critical Infrastructure Resilience programme, and in February 2026 released a discussion document, Enhancing the cyber security of New Zealand’s critical infrastructure system, aimed squarely at owners and operators who would be affected by regulatory reform. Consultation ran from 27 February to 19 April 2026, and submissions are informing further advice to Cabinet. The New Zealand Cyber Security Strategy 2026–2030 was published alongside it.
To be clear about where this stands: these are proposals, not law. No new statutory cyber security obligations for critical infrastructure operators are in force in New Zealand today, and any consultancy telling you otherwise is overstating the position.
The direction of travel is nonetheless unambiguous, and it mirrors what Australia did through the Security of Critical Infrastructure Act and the CIRMP rules. Operators who begin building a defensible risk management programme now will be positioned to meet obligations when they arrive, rather than compressing the work into whatever transition period is granted. We help operators assess their current position against the likely shape of reform, with particular attention to operational technology and third-party dependency risk — the two areas that consistently prove hardest to evidence.
For background on our practice, see our profile as a cyber security company in New Zealand. For city-specific pages, see Auckland and Wellington.
Tell us where you are and what you are being asked to demonstrate, and we will set out a realistic path — including where you may need less work than you expect. Get in touch.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.