Protective Security Consulting
We understand New Zealand Government’s Protective Security Requirements. We can help you to deliver your projects – from stocktaking your operations to presenting you your current and future risk management plan, through to process design and documentation, certification and accreditation, policy development and digital implementations.
Our Professional Services offerings enable you to free up resources by letting us solve challenges and deliver your security projects. There is no challenge to big or small – move on to the next problem and let us finish it.
Virtual CISO, ITSM and Security Delivery Team
Governance
Establishing effective cyber security governance can be tough. You need an appropriate strategy, work programme, operating model, policies, risk management plan and underlying processes to deliver security outcomes within a tight budget.
We can help you structure your team and activities, confirm and build the coverage of your function, identify and document funding requirements and develop detailed processes based on our experience working with NZ Government and private clients.
Personnel Security
We have responded to countless incidents involving internal staff members. We have seen the challenges faced when fronting up to regulators and shareholders when proper checks would have identified these risks.
We can help you to confirm your vetting processes are appropriate, manage staff on-boarding and ongoing security training, and are experienced in assisting businesses with the management and monitoring of departing staff.
Physical Security
We specialise in social engineering and testing physical security controls. Like a penetration test for IT systems, we have seen that these tests identify real weaknesses in physical security design. More importantly, they gamify physical security responsibilities for your staff.
As an example, we like to make staff aware that social engineers will attempt to tailgate them, which makes them more comfortable in appropriately challenging others who they do not recognise. More broadly, we have assisted some of New Zealand’s largest organisations to assess and develop their physical security risk management plan and implement physical security processes and technical controls.
Information Security
“Information Security is never-ending” – It truly is.
A challenge faced by many businesses in New Zealand is that they are instructed to spread their information security resource across a generic set of controls and activities. Our point of difference is two-fold.
Firstly, we work actively within businesses as IT Security Managers, and have felt the pain of a generic list of recommendations. Secondly, we monitor and respond to incidents, meaning we understand what really causes businesses and IT professionals pain. We can help you to reduce your “todo” list, focus on the projects which reduce your real exposure (and are defendable if you are breached).
Delivery Options:
Virtual ITSM / CISO
Diode currently supports NZ Government by providing experienced virtual IT Security Managers.
A vITSM is a specific, highly experienced cyber security professional who provides you with the time you need each week (or as you need it) to plan, manage, deliver, and respond to security challenges for your organisation.
This enables you to right-size and execute your security capability investment (and adjust it over time) and benefit from the learnings of other organisations across New Zealand.
Contractor Support
Sometimes you need an experienced, self-managed, and flexible resource to support your IT, Security or Risk function.
Typically (especially in the current climate), you will need this resource yesterday.
Diode does not offer junior contractor support. Any Diode Contractor who supports you will bring a minimum of 5 years dedicated cyber security experience.
Vendor Project Delivery
Our Vendor Project Delivery philosophy is simple – you expect us to deliver a high quality output at a low time/engagement cost to you.
This is typically a fixed cost engagement to deliver a specific outcome.
If we have done our job right, you should get exactly what you need – while barely noticing we were there.
Become a partner to receive 24/7/365 immediate response support, tailored threat warnings for your environment, analysis on whether you are impacted by new vulnerabilities, security operations support and security monitoring services.
Not sure if you need it? Get in touch now to organise a cyber incident simulation – tailored to your business. These exercises are fun and will identify gaps in your ability to respond. Simulations also build real muscle memory, and our clients have repeatedly told us that they have improved their ability to respond.
In case of an incident or a suspected breach, please get in touch with us immediately at one of the contact details below.