CitadelCyber

Takapuna, Auckland
09 488 2201

6 results

citadel-cyber --assess your-network

Your perimeter is only
as strong as your people.

Citadel Cyber is a Takapuna-based cybersecurity consultancy for New Zealand SMEs. We run penetration tests, staff phishing simulations and NZISM-aligned compliance audits — so you find the gaps before someone else does.

cat services.md

What we test, break and fix.

cat why-citadel.md

SME-grade security without enterprise overhead.

Most NZ cybersecurity firms target corporates with 500+ staff and six-figure budgets. We built Citadel for the 20-to-200 seat businesses that are too big to ignore security and too small for a full-time CISO. Every engagement is scoped and priced so that the cost of the audit is less than the cost of one breach.

We are CREST-accredited, all analysts hold current OSCP or OSCE certifications, and we carry professional indemnity insurance with a $2M limit. Our phishing simulation platform is hosted in New Zealand on NZ-domiciled infrastructure — your staff data never leaves the country.

  • CRESTAccredited penetration testing provider — renewed 2026
  • OSCP / OSCEAll senior analysts hold Offensive Security certifications
  • NZISMApproved assessor for NZ Information Security Manual audits
  • ISO 27001Our own operations are ISO 27001 certified
  • NZ Privacy ActCompliant data handling — all test data destroyed at engagement close
  • PI Insurance$2M professional indemnity cover, Aon NZ

cat case-studies.md

Real outcomes, anonymised clients.

Professional services firm · 85 staff · Wellington

Phishing simulation exposed 42% click rate — down to 6% after training.

A law firm assumed their staff were savvy because they handled sensitive client data daily. Our first simulation sent a fake courier-delivery email and 42% of staff clicked through to a credential-harvesting page. After two rounds of targeted awareness training over eight weeks, the click rate dropped to 6% and credential submissions fell to zero.

42% → 6%

Manufacturing company · 140 staff · Hamilton

External pen test found an unpatched VPN appliance with domain-admin credentials cached in memory.

The client's VPN concentrator was running firmware two years out of date. We demonstrated full Active Directory compromise within four hours of the engagement start. The remediation — a firmware update, credential rotation and MFA enforcement — took one weekend and cost the client nothing beyond the audit fee.

4-hour compromise path → closed

diff packages.csv

Compare assessment packages.

Show differences only
Feature Essentials Professional Enterprise
External pen test1 IP rangeUp to 5 IP rangesUnlimited
Internal assessmentNot includedUp to 250 hostsUp to 1,000 hosts
Phishing simulationUp to 100 mailboxesUp to 100 mailboxesUp to 100 mailboxes
NZISM gap analysisNot includedNot includedFull audit + roadmap
Cloud reviewNot included1 cloud tenantMulti-cloud
Executive summaryYesYesYes
Board presentationNot includedNot included1-hour board briefing
RetestNot includedFree 30-day retestFree 90-day retest
IR retainerNot includedNot included12-month retainer
Price (+ GST)$4,500$9,800$18,500

cat team.md

Three analysts, one focus.

Founder & lead consultant

Hamish Caulfield

Fifteen years in offensive security, from GCSB through to consulting. Hamish leads all NZISM audits and the incident-response retainer. OSCP, OSCE, CREST CRT, CISSP.

Senior analyst

Mei Lin Chen

Mei Lin runs the phishing-simulation programme and the internal network assessments. Background in SOC analysis at a Big Four firm in Sydney before moving to Auckland. OSCP, GPEN, GCIH.

Analyst

Jordan Ngata

Jordan handles external pen tests and cloud configuration reviews. Computer Science graduate from AUT, CTF competitor and NZ CyberCon speaker. OSCP, AWS Security Specialty.

Frequently asked questions

Will a pen test break our systems?
No. We agree a scope and rules of engagement before we start. Testing is non-destructive — we demonstrate access, not damage. If we find a critical vulnerability mid-test we notify you immediately rather than waiting for the report.
How long does an engagement take?
An external pen test typically takes 3–5 business days of active testing. The report is delivered within five business days after that. Internal assessments add 2–3 days depending on network size. A full NZISM audit runs 3–4 weeks including interviews.
Do you work outside Auckland?
Yes. Most testing is remote. For on-site internal assessments we travel nationwide — past clients include firms in Wellington, Hamilton, Christchurch and Dunedin. Travel is at cost with no mark-up.
What happens to our data after the engagement?
All test data, credentials captured and screenshots are stored in an encrypted vault during the engagement and securely destroyed 30 days after report delivery. We never retain client data beyond that window.

ping contact

Request a security assessment.

Your organisation
Your details

Get in touch directly

Citadel Cyber Ltd

Level 2, 40 Hurstmere Road
Takapuna, Auckland 0622

09 488 2201

secure@citadelcyber.co.nz

PGP key fingerprint: 8A3F 12D4 E7B9 6C01 5AF2