Wellington Serving New Zealand and Australia
Intelligence Group is a Wellington security practice. We attack your networks, applications and people the way a real adversary would, then hand you the evidence, the impact and the fix for every finding, at a fixed price against a written scope.
01 Services
These are the assessments organisations come to us for most often. Anything that falls outside them can be scoped as a bespoke engagement.
Starting from a compromised workstation or an unauthorised device on your LAN, we find out how far an intruder could escalate and what they could seize.
Everything you publish to the internet, from VPN gateways and mail to remote access and forgotten hosts, assessed from an outsider's vantage point.
Login and session weaknesses, broken authorisation, injection and logic flaws in the web applications you develop or procure.
Android and iOS apps together with their backend services: data left on the device, weak transport protection and missing platform safeguards.
REST, GraphQL and internal service interfaces checked for authorisation gaps, over-generous responses and abusable workflows.
Staff and guest Wi-Fi reviewed for rogue access points, weak authentication and whether wireless clients can reach systems they should not.
An objective-led simulated intrusion that runs for weeks and measures whether your people and tooling notice and respond, not merely whether controls are switched on.
Controlled, ethically run phishing exercises against your workforce, reported as trends and learning outcomes rather than a list of names.
02 Process
Systems in scope, exclusions and rules of engagement are documented and signed off before a single packet is sent, keeping the work lawful, safe and focused on what counts.
Certified consultants work through the agreed scope using established methodologies, purpose-built tooling and careful manual analysis, confirming each issue by hand.
Findings arrive with supporting evidence, an assessment of impact to your organisation and a concrete remediation, ordered by the risk each one represents.
After your team remediates, we re-examine every fix and reissue the report, giving you proof that the exposure has actually been removed.
03 Essential Eight
Beyond penetration testing, Intelligence Group delivers evidence-based Essential Eight maturity assessments through a platform we designed and operate ourselves. Uploaded artefacts, reviewer decisions and maturity roll-ups sit together, and every report is dated and exportable. See how Essential Eight assessments work →
Artefacts are uploaded against each numbered test, so nothing lives in email threads or shared drives.
Every artefact is judged against a written methodology by an assessor, with the evidence sitting beside the decision.
Progress history, roll-ups by strategy and dated reports you can export for any engagement.
04 Deliverables
Established methodologies and tooling are paired with hands-on manual testing, so nothing is skipped and every issue has been confirmed by a consultant rather than assumed from a scanner.
Each issue states the impact to your organisation, a severity you can defend and the exact remediation, written so both technical staff and executives can act on it.
We do not mark a finding resolved because someone says it is. Remediated issues are retested and the report is reissued with the outcome.
Whether it is one API or a month-long red team operation, each engagement is scoped, priced and written up for the systems you actually operate. There are no pre-packaged bundles.
Get in touch to talk through what you need. We agree the scope in writing and give you a fixed price before any testing starts.
Request a quote