Bastion Security

Assess your systems and improve security

Know where your security stands and how to make it stronger. Our Assess & Improve services identify gaps, measure maturity and help plan your next steps.
Talk to an expert
Strategy meets security

Security insights that drive better decisions

Explore services designed to uncover risks, strengthen your posture and support ongoing security improvement.

  • Practical, expert-led guidance tailored to your systems and goals
  • Clear insights you can act on
  • Support across penetration testing, compliance and cyber risk governance
Uncover security risks

Find the right path to strengthen your security

From audits to testing, we help you uncover risks, understand your posture and take the right steps.
Discover our services

Assess risk and improve resilience

Our services cover every aspect of your security, from initial assessment to ongoing protection.
Certification & Accreditation
We help organisations simplify the security certification and accreditation process with expert advice that actually fits your systems, goals, and timelines.
Certification & Accreditation
We help organisations simplify the security certification and accreditation process with expert advice that actually fits your systems, goals, and timelines.
Audit & Assurance
Strong security starts with visibility. Our audit and assurance services review your controls, highlight gaps, and help you build more resilient systems.
Audit & Assurance
Strong security starts with visibility. Our audit and assurance services review your controls, highlight gaps, and help you build more resilient systems.
Governance, Risk & Compliance
Strengthen governance, manage risks and ensure compliance with ease. We simplify cyber security to fit seamlessly into your operations.
Governance, Risk & Compliance
Strengthen governance, manage risks and ensure compliance with ease. We simplify cyber security to fit seamlessly into your operations.
Cyber Maturity Assessments
We assess your controls, map your security maturity, and recommend a clear path to strengthen it. A well-executed digital maturity assessment sets the foundation for your security roadmap.
Cyber Maturity Assessments
We assess your controls, map your security maturity, and recommend a clear path to strengthen it. A well-executed digital maturity assessment sets the foundation for your security roadmap.
Penetration Testing
Attackers don’t wait. Our penetration testing finds your weak spots first, across apps, systems, and networks so you can fix them fast.
Penetration Testing
Attackers don’t wait. Our penetration testing finds your weak spots first, across apps, systems, and networks so you can fix them fast.
Service Development Manager
Government Agency
"Great service, clear, detailed and precise information on what our vulnerabilities were and what needs addressing. Couldn't have been easier to deal with and very professional."
What comes next

Expand your
security coverage

Assessment is just the beginning. We’ll guide you from insight to action, so you’re not only aware of the risks but ready to take them on.

  • Tailored recommendations based on your environment and risk profile
  • Follow-up services including remediation planning and continuous monitoring
  • Ongoing support to strengthen your cyber security posture over time
Talk to an expert
Employee Cyber Training & Awareness
Your people are your first line of defence. Our cyber training builds awareness and sharpens their instincts.
Advisory
When clarity is critical and stakes are high, our advisory services deliver strategic, executive-level security expertise that empowers decision-making.
Why choose us

Meet the people who power your protection

Our team isn’t just experienced, they’re invested. Their technical expertise, breach response skills and certifications make Bastion’s cyber security services trusted and effective.
Meet your team
Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
TimePictra (Microchip) – Stored Cross-Site Scripting (XSS) (CVE-2026-3010)
During a security engagement, Steve Nyan Lin discovered a stored XSS vulnerability in the TimePictra web application which was due to a lack of input filtering. This affects the neName parameter when creating new network elements.
TimePictra (Microchip) – Lack of Authentication (CVE-2026-2844)
During a security engagement, Steve Nyan Lin discovered a lack of authentication within numerous functionaliy within the TimePictra web application which allowed viewing of sensitive information and making changes to network elements.
Silverstripe - Cross-Site Scripting (XSS) Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in the administrator panel of Silverstripe CMS, specifically in the handling of the user input within the form messages module.
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

Is this a one-time service or ongoing?

It can be both. We offer one-time evaluations or ongoing security improvement programs to help you evolve alongside changing threats and regulations.

Can you align assessments with specific frameworks or regulations?

Yes. We tailor assessments to ISO 27001, NZISM, PSR, NIST, PCI-DSS, and industry-specific compliance requirements.

What if we’ve never done a formal security assessment before?

That’s perfectly fine. We specialise in helping organisations get started, understand the gaps, and prioritise actions without overwhelming your team.

What services are included in your assessment offerings?

We conduct comprehensive security audits, gap analyses, threat risk assessments, maturity benchmarking, and compliance reviews aligned with ISO, NZISM, and other standards.

What does 'Assess & Improve' mean in the context of security?

It’s about understanding where your security stands today and how to make it stronger. We identify gaps, evaluate risks, and help you build a smarter, safer security strategy.

How do I book a penetration test or get a quote?

Complete the form on this page and our team will be in touch within one business day to discuss your requirements and provide a scoped proposal.

How long does a penetration test take?

A penetration test typically takes around 5 days, although the exact duration depends heavily on the agreed scope and the specific objectives of the engagement. Penetration testing is tailored to your environment, risk profile and goals, so timelines can vary accordingly.

What's the difference between a vulnerability scan and a penetration test?

A vulnerability scan uses automated tools to identify known weaknesses. A penetration test goes further - our testers simulate real attacker behaviour to validate those risks and uncover more complex issues that tools alone miss.

Do you test cloud environments, web applications and APIs?

Yes. We cover external and internal networks, web and mobile applications, cloud environments, APIs, SaaS platforms and specialist areas including OT/SCADA, wireless and hardware.

How often should we run a penetration test?

Most organisations benefit from annual testing as a baseline, with additional tests following significant changes to systems, applications or infrastructure - or when required for compliance.

Do you offer independent or CREST-certified testing?

Yes. Bastion is a CREST-certified penetration testing provider, meaning our testing meets globally recognised standards for quality, ethics and technical rigour.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.