citadel-cyber --assess your-network
Your perimeter is only
as strong as your people.
Citadel Cyber is a Takapuna-based cybersecurity consultancy for New Zealand SMEs. We run penetration tests, staff phishing simulations and NZISM-aligned compliance audits — so you find the gaps before someone else does.
cat services.md
What we test, break and fix.
-
External penetration test
We probe your public-facing systems — web apps, APIs, mail servers, VPNs — using the same tools and techniques as real attackers. You get a prioritised findings report within five business days.
From $4,500 + GST
-
Internal network assessment
An analyst on-site or via VPN maps your internal network, tests Active Directory, privilege escalation paths and lateral movement. Covers up to 250 hosts.
From $6,800 + GST
-
Phishing simulation
Realistic phishing emails sent to your staff over four weeks. We measure open rates, click-through and credential submission, then deliver awareness training to the teams that need it most.
From $2,200 + GST (up to 100 mailboxes)
-
NZISM compliance audit
We map your current controls against the New Zealand Information Security Manual and produce a gap analysis with a remediation roadmap. Accepted by government procurement panels.
From $7,500 + GST
-
Cloud configuration review
Azure, AWS or Google Cloud — we review IAM policies, network security groups, storage permissions and logging. Includes a Terraform/Bicep hardening checklist.
From $3,800 + GST
-
Incident response retainer
Four-hour SLA for breach response, forensics triage and comms support. Retainer includes an annual tabletop exercise for your leadership team.
$1,200/month + GST
cat why-citadel.md
SME-grade security without enterprise overhead.
Most NZ cybersecurity firms target corporates with 500+ staff and six-figure budgets. We built Citadel for the 20-to-200 seat businesses that are too big to ignore security and too small for a full-time CISO. Every engagement is scoped and priced so that the cost of the audit is less than the cost of one breach.
We are CREST-accredited, all analysts hold current OSCP or OSCE certifications, and we carry professional indemnity insurance with a $2M limit. Our phishing simulation platform is hosted in New Zealand on NZ-domiciled infrastructure — your staff data never leaves the country.
- CRESTAccredited penetration testing provider — renewed 2026
- OSCP / OSCEAll senior analysts hold Offensive Security certifications
- NZISMApproved assessor for NZ Information Security Manual audits
- ISO 27001Our own operations are ISO 27001 certified
- NZ Privacy ActCompliant data handling — all test data destroyed at engagement close
- PI Insurance$2M professional indemnity cover, Aon NZ
cat case-studies.md
Real outcomes, anonymised clients.
Professional services firm · 85 staff · Wellington
Phishing simulation exposed 42% click rate — down to 6% after training.
A law firm assumed their staff were savvy because they handled sensitive client data daily. Our first simulation sent a fake courier-delivery email and 42% of staff clicked through to a credential-harvesting page. After two rounds of targeted awareness training over eight weeks, the click rate dropped to 6% and credential submissions fell to zero.
42% → 6%
Manufacturing company · 140 staff · Hamilton
External pen test found an unpatched VPN appliance with domain-admin credentials cached in memory.
The client's VPN concentrator was running firmware two years out of date. We demonstrated full Active Directory compromise within four hours of the engagement start. The remediation — a firmware update, credential rotation and MFA enforcement — took one weekend and cost the client nothing beyond the audit fee.
4-hour compromise path → closed
diff packages.csv
Compare assessment packages.
| Feature | Essentials | Professional | Enterprise |
|---|---|---|---|
| External pen test | 1 IP range | Up to 5 IP ranges | Unlimited |
| Internal assessment | Not included | Up to 250 hosts | Up to 1,000 hosts |
| Phishing simulation | Up to 100 mailboxes | Up to 100 mailboxes | Up to 100 mailboxes |
| NZISM gap analysis | Not included | Not included | Full audit + roadmap |
| Cloud review | Not included | 1 cloud tenant | Multi-cloud |
| Executive summary | Yes | Yes | Yes |
| Board presentation | Not included | Not included | 1-hour board briefing |
| Retest | Not included | Free 30-day retest | Free 90-day retest |
| IR retainer | Not included | Not included | 12-month retainer |
| Price (+ GST) | $4,500 | $9,800 | $18,500 |
cat team.md
Three analysts, one focus.
Founder & lead consultant
Hamish Caulfield
Fifteen years in offensive security, from GCSB through to consulting. Hamish leads all NZISM audits and the incident-response retainer. OSCP, OSCE, CREST CRT, CISSP.
Senior analyst
Mei Lin Chen
Mei Lin runs the phishing-simulation programme and the internal network assessments. Background in SOC analysis at a Big Four firm in Sydney before moving to Auckland. OSCP, GPEN, GCIH.
Analyst
Jordan Ngata
Jordan handles external pen tests and cloud configuration reviews. Computer Science graduate from AUT, CTF competitor and NZ CyberCon speaker. OSCP, AWS Security Specialty.
Frequently asked questions
Will a pen test break our systems?
How long does an engagement take?
Do you work outside Auckland?
What happens to our data after the engagement?
ping contact
Request a security assessment.
Get in touch directly
Citadel Cyber Ltd
Level 2, 40 Hurstmere Road
Takapuna, Auckland 0622
PGP key fingerprint: 8A3F 12D4 E7B9 6C01 5AF2