NZCAT
Independent security architecture advisory for Aotearoa New Zealand's mid-market.
NZCAT delivers senior-level security architecture review, incident readiness, and technology advisory to organisations that cannot justify Big Four engagement minimums. Advice is grounded in real incident response and adversarial behaviour.
Contact NZCAT
Personal analytical writing, published through CyberMillennial. Security architecture and incident analysis, alongside a record of building a career in Aotearoa New Zealand.
Visit cybermillennial.com →Strategic Signals
Recent, dated incidents across Aotearoa New Zealand and Australia, described by sector and scale. Organisations are not named.
- Mar 2024
A dealer network was breached, exposing driver licence and tax documents for more than 100,000 individuals.
100,000+ individuals
- Oct 2025
An airline loyalty programme was breached, exposing contact and membership details for customers including individuals in New Zealand.
5.7 million records
- Dec 2025
A patient records platform disclosed unauthorised access, exposing personal health information for patients across dozens of general practices.
~120,000 individuals
- Jan 2026
A regional law firm was hit by ransomware. The firm sought a High Court injunction restraining further use or disclosure of the stolen data.
Firm-wide client files
- Jan 2026
A manufacturing operator was listed by an extortion group after unauthorised device-level access was obtained through a contractor.
- Feb 2026
A medication management platform disclosed a data integrity incident in which medication records and demographic data were tampered with.
- May 2026
A breach of a widely used learning management platform affected approximately 9,000 educational institutions worldwide, including universities in New Zealand.
~9,000 institutions
- May 2026
A food processing and logistics operator was listed on a darknet leak site, disrupting supply logistics.
Operating Principles
Operational risk is business risk.
Senior Architectural Authority
Technical risk translated directly into business impact for boards and SMEs across Aotearoa New Zealand.
AI-Augmented Risk Compounding
Rapid GenAI adoption is compounding unaddressed legacy risk. Strengthening data governance is no longer optional.
Pragmatic Gap Analysis
STAR and PROBE surface operational gaps beyond checkbox compliance.
“Direct financial losses reported to the NCSC totalled $12.4 million in Q3 2025: a 118% increase from the previous quarter.”
NCSC, Q3 2025 Cyber Security Insights
“The gap between how quickly leaders believe they can recover and how long recovery actually takes is a preparedness problem.”
Collin Penman, CISO, Datacom (April 2026)
“Cyber incidents now carry direct consequences for real-world activities, not just data.”
NZ Cyber Security Strategy 2026-2030
Services
Security Architecture Review
STAR
One roadmap connecting technical reality, business risk, and leadership priorities, revisited as the architecture changes.
M&A Security Due Diligence
PROBE
Profiles the other party in an acquisition, partnership, or major vendor commitment, on either side of the deal, before signing or after.
Executive Incident Exercise
ECLIPSE
A scenario-driven exercise testing executive decision-making during a major cyber incident.
Executive Personal Security
HALO
Assesses the digital footprint, device security, and physical exposure of senior leaders, frequently targeted as an initial access vector.
OT Security Assessment
MISSION
Assesses operational technology environments for network segmentation, legacy equipment risk, and vendor connectivity gaps.
AI Security Review
ATLAS
Reviews AI adoption against its security integration, scoped to the organisation's current stage of AI use.
Post-Pentest Roadmap
PAYLOAD
Turns penetration test findings into a prioritised architectural roadmap for leadership and security teams.
Why NZCAT
Senior oversight, without enterprise pricing.
Mid-market organisations across Aotearoa New Zealand face a widening threat landscape without the budget to access senior-level expertise from major consultancies. Established firms operate on minimum daily rates and multi-year programmes, sized for clients with dedicated procurement functions. Architectural weaknesses and visibility gaps go unaddressed by standard compliance audits and remain out of reach of full enterprise engagements.
NZCAT works directly against an organisation's existing security stack: existing diagrams, plus either read-only access to systems in production or configuration already exported from them, whichever the client prefers, without requiring new tooling. Statements of work are scoped to the complexity of each engagement, giving senior oversight to organisations that need it for a specific decision, such as an acquisition or an AI rollout, without committing to a retainer.