Careline Trust Talk to us

Find out how protected
you really are.
Then get stronger.

Northline Security is an independently owned New Zealand cyber security consultancy. We test what would actually hold, get your people ready for the day it matters, and write the whole thing up in language anyone can act on.

  1. Perimeter
  2. Applications
  3. Identity
  4. Data
  5. Your people
A diagram of an organisation drawn as five nested, slowly shifting layers, named from the outside in: perimeter, applications, identity, data, and your people at the core. Threats arrive from outside one at a time and each is held at a layer, which flares as it holds.
1,180devices protected
340people trained
5standards we test against
100%independently owned

How we help

Three ways in, depending on where you are.

Indicative durations. We scope against your organisation rather than a price list, and we will tell you if you do not need us yet.

013 to 5 weeks

Find out where you stand

A cyber risk assessment against the standard you are held to, a penetration test of the systems that matter, or a review of the platform you are about to launch.

  • Cyber risk assessmentMeasured against NZISM, MCSS, ISO 27001, NIST CSF or CIS
  • Penetration testingWhat a real intruder reaches, with proof
  • New system assessmentBefore you put it in front of your people

You end up with A ranked risk register, evidence for each finding, and a one page summary your board will actually read.

022 to 4 weeks

Prepare your people

A realistic phishing campaign so you know exactly who clicks, training built on your own results rather than a generic deck, and a workshop that rehearses the bad morning before it arrives.

  • Simulated phishingMeasured per person, per team, with analysis
  • Awareness trainingBuilt on your results, then retested
  • Incident simulationTechnical, legal, comms and privacy in one room

You end up with A number you can move, a trained team, and a response plan somebody has actually rehearsed.

03Ongoing

Fix what needs fixing

We stay on to do the work. Hardening the configuration, cutting access back to what is needed, writing the policy that was missing and standing up tooling the team you actually have will use.

  • Configuration hardeningServers, network, desktop, GPO and Intune
  • Policy and control upliftThe documents an auditor asks for
  • ToolingSelected for your team, not for our margin

You end up with Fewer findings next time, and a team that can hold the line without us.

The reports

Every report we write, you can actually read.

Security is full of language built to end a conversation rather than start one. Here is the same finding written both ways. Ours is the second one.

How most reports put it

Enforce MFA across all privileged accounts.

How we put it

A second lock on the doors that matter most, so a stolen password on its own is not enough to get in.

How most reports put it

Reduce the externally exposed attack surface.

How we put it

There is less of you facing the internet for a stranger to find and try.

How most reports put it

A privilege escalation path exists from the user tier to domain administrator.

How we put it

Somebody could start with an ordinary staff login and end up owning everything, in a few quiet steps.

How most reports put it

Controls assessed as non-compliant with NZISM 17.1.53.

How we put it

The government's security rulebook says do this. Right now you do not, and here is what it would take.

How most reports put it

An authorised black box engagement was conducted against the perimeter.

How we put it

We tried to break in, with your written permission, and wrote down exactly how far we got.

How most reports put it

Residual risk remains above appetite post-remediation.

How we put it

After the fixing, some risk is still there. Somebody has to decide it is acceptable, and that somebody is you.

Evidence

The work, and what the people who bought it said about it.

Every organisation on this page is a client. These four agreed to be quoted.

  • Careline Trust Frontline Staff Association

    They mapped where we were actually exposed, then wrote it up so the whole leadership team could follow it, not just IT.

    Peter NashIT Manager
    • Penetration testing
    • Security assessment
  • Riverlands Regional Council

    Delivered on time and to the budget we agreed, and the output was genuinely usable. Straightforward people to deal with.

    Sarah EllisIT Team Leader
    • Simulated phishing
  • Careline Trust

    The training actually landed with our staff, and we have had noticeably fewer near misses since.

    Mark HalloranCorporate Services Manager
    • Awareness training
    • Simulated phishing
  • Southgate Advisory

    It showed us exactly where our knowledge gaps were, and gave us something concrete to do about each one.

    Claire DentonFounder and CIO
    • Simulated phishing
  • Ravensbourne District Council
  • Halcyon Trust Services
  • Emergency Care Council
  • Allied Health Registration Board

Who turns up

The names on the report are the people in the room.

Four consultants, and you will meet all of them. Independently owned, so we sell no software, take no vendor commission and run no monitoring service. There is nothing attached to the advice.

  1. Michael Trent

    Michael Trent

    Director

    Twenty years in IT security and strategy across the financial and not-for-profit sectors. The reason the reports read the way they do.

    20+ years·Strategy and assessment·Certified Ethical Hacker

  2. Rachel Speight

    Rachel Speight

    Principal Security Consultant

    Eighteen years across public, private and local government assurance, including a period as chief information security officer at a large public sector agency.

    18 years·Assurance and governance·NZISM, PSR, ISO 27001, NIST CSF, CIS

  3. Joseph Okafor

    Joseph Okafor

    Cyber Security Consultant

    Penetration testing and network hardening. Finds the door left open behind the door you were worried about.

    BSc Computer Science·Offensive testing and hardening·NSE4

  4. Anita Kaur

    Anita Kaur

    Cyber Security Consultant

    Penetration testing plus governance, risk and compliance. The half of the job that decides whether a finding ever gets fixed.

    Master of Information Governance, in progress·Testing and compliance·CEH, Certified Tenable Engineer

Start anywhere

Start with a
conversation.

You do not need a brief, a budget, or the vocabulary. Tell us where you have got to in your own words and we will tell you what would genuinely help.

  • A consultant replies, usually the same day
  • No sales sequence, and nothing to buy from us
  • We will say so if you do not need us yet
help@northlinesecurity.co.nz
Send a note

A few lines is plenty.

Where are you up to?