Security insights that drive better decisions
Explore services designed to uncover risks, strengthen your posture and support ongoing security improvement.
- Practical, expert-led guidance tailored to your systems and goals
- Clear insights you can act on
- Support across penetration testing, compliance and cyber risk governance
Find the right path to strengthen your security
Assess risk and improve resilience
Latest advisories
Frequently asked questions
Is this a one-time service or ongoing?
It can be both. We offer one-time evaluations or ongoing security improvement programs to help you evolve alongside changing threats and regulations.
Can you align assessments with specific frameworks or regulations?
Yes. We tailor assessments to ISO 27001, NZISM, PSR, NIST, PCI-DSS, and industry-specific compliance requirements.
What if we’ve never done a formal security assessment before?
That’s perfectly fine. We specialise in helping organisations get started, understand the gaps, and prioritise actions without overwhelming your team.
What services are included in your assessment offerings?
We conduct comprehensive security audits, gap analyses, threat risk assessments, maturity benchmarking, and compliance reviews aligned with ISO, NZISM, and other standards.
What does 'Assess & Improve' mean in the context of security?
It’s about understanding where your security stands today and how to make it stronger. We identify gaps, evaluate risks, and help you build a smarter, safer security strategy.
How do I book a penetration test or get a quote?
Complete the form on this page and our team will be in touch within one business day to discuss your requirements and provide a scoped proposal.
How long does a penetration test take?
A penetration test typically takes around 5 days, although the exact duration depends heavily on the agreed scope and the specific objectives of the engagement. Penetration testing is tailored to your environment, risk profile and goals, so timelines can vary accordingly.
What's the difference between a vulnerability scan and a penetration test?
A vulnerability scan uses automated tools to identify known weaknesses. A penetration test goes further - our testers simulate real attacker behaviour to validate those risks and uncover more complex issues that tools alone miss.
Do you test cloud environments, web applications and APIs?
Yes. We cover external and internal networks, web and mobile applications, cloud environments, APIs, SaaS platforms and specialist areas including OT/SCADA, wireless and hardware.
How often should we run a penetration test?
Most organisations benefit from annual testing as a baseline, with additional tests following significant changes to systems, applications or infrastructure - or when required for compliance.
Do you offer independent or CREST-certified testing?
Yes. Bastion is a CREST-certified penetration testing provider, meaning our testing meets globally recognised standards for quality, ethics and technical rigour.
Talk to an expert
51 Shortland Street,
Auckland 1010 New Zealand
10 Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia








