Testing the components of your IT environment is an ongoing challenge. Staying ahead requires understanding the latest attack techniques and evaluating your defences against evolving threats. This proactive approach is crucial for enhancing your cybersecurity posture.
Explore NSP’s Penetration Testing to simulate real cyberattacks and identify vulnerabilities in your people, processes, and technology.
Not just a scan of known vulnerabilities – a real attempt to get in, move through your environment, and reach your most sensitive systems. The way an attacker would.
External network, internal network, web applications, cloud configuration, email security, and social engineering. We test the things attackers actually target, not just the things that are easy to check.
Every finding explained in business terms. What was found, what an attacker could do with it, how likely exploitation is, and what to fix first. Written for the person running the business as well as the IT team.
Internal teams often miss vulnerabilities because they’re too close to the environment. An independent pen test gives you an objective view of what’s actually exploitable – not just what looks secure from the inside.
ISO 27001, PCI DSS, and NZISM all reference regular penetration testing as a control requirement. NSP’s pen test produces a report formatted to support your compliance programme and your cyber insurance application.
Not every vulnerability is equal. Our report tells you which findings are critical, which are medium risk, and which can wait – so you’re fixing the right things first, not just the most visible ones.
A pen test tells you whether the security tools you’ve invested in are actually working – whether your EDR would catch a real attack, whether your monitoring would detect lateral movement, and whether your incident response would kick in fast enough.
Every NSP pen test delivers a full written report covering every vulnerability found, how it was identified, what an attacker could realistically do with it, and the evidence from our testing. Findings are rated by severity – critical, high, medium, low – so you know immediately where to focus.
The report has two sections: an executive summary written for leadership and boards, and a technical detail section written for your IT team. Both sections include specific remediation guidance, not just a list of problems.
Most importantly – it’s written in plain English. If you need to present findings to a board, a client, or a cyber insurance underwriter, this report is designed to be shown.
Before anything starts, we agree exactly what is in scope. Which systems, which environments, which attack scenarios. You decide what we test. We tell you what to expect, what access we need, and how we will work around your operational requirements. Nothing happens until scope is agreed and signed off.
Our testers use the same tools and techniques that real attackers use – manual exploitation, not just automated scans. We attempt to get in, move through your environment, escalate privileges, and reach your most sensitive systems. Everything we do is documented so you know exactly what was tested, what was found, and how.
Every finding is documented with evidence, rated by severity – Critical, High, Medium, Low – and explained in plain English. What was found, how it was exploited, what an attacker could realistically do with it, and what to fix first. The report has an executive summary for leadership and a technical section for your IT team.
We walk you through every finding. What it means for your business, how likely exploitation is, and what to prioritise. You leave with a sequenced remediation roadmap – what to fix this week, what to schedule, what to monitor. If you need help fixing what we found, NSP’s team can support that too. For compliance purposes, we can arrange a retest once remediation is complete.
Testing your internet-facing perimeter – firewalls, VPNs, remote access tools, public-facing servers, and any system exposed to the internet. This is the view an attacker has before they get inside your network. Most NZ businesses start here.
Testing what an attacker can do once they are already inside your network – whether from a compromised device, a phishing attack, or a malicious insider. We simulate lateral movement, privilege escalation, and access to your most sensitive systems and data.
Testing the security of your web applications, customer portals, APIs, and online services. We check for OWASP Top 10 vulnerabilities including injection flaws, broken authentication, and data exposure – the most commonly exploited weaknesses in business web applications.
Testing your cloud environments – Microsoft Azure, Microsoft 365, and cloud-hosted services – for misconfigurations, excessive permissions, insecure storage, and identity control weaknesses. Cloud misconfiguration is one of the leading causes of data breaches in NZ.
Testing your people, not just your systems. We conduct simulated phishing campaigns and, where agreed, physical security tests to find out how your staff respond to real-world manipulation attempts. Your people are your biggest attack surface and the hardest one to patch.
A full-scope, adversarial simulation that combines external, internal, social engineering, and physical security testing into one coordinated attack scenario. Red team exercises are designed for businesses that want to test their detection and response capability – not just their preventive controls.
A plain-English summary of what we found, what the realistic risk is to your business, and what to do first. Written to be shown to your board, your leadership team, or your cyber insurer – not just your IT team.
Every finding documented with the evidence from our testing, the method used to exploit it, and the severity rating – Critical, High, Medium, Low. Your IT team gets a precise, actionable record of what we found and how we found it.
A sequenced fix list ordered by severity and practical impact. What to address this week, what to schedule over the coming months, and what to monitor ongoing. Not just a list of problems – a plan for fixing the right ones first.
We walk you through every finding in a live debrief. What it means, how exploitable it is, and what a real attacker could do with it. Questions answered, context provided. If you are presenting findings to a board or an insurer, we can help you frame that conversation too.
Some businesses need a pen test because they are required to have one. Others need one because something happened or because they want to know what would happen if it did.
Compliance requirements. ISO 27001, PCI DSS, and NZISM all reference regular penetration testing as a control requirement. If you are pursuing certification or maintaining compliance, a documented annual pen test from a professional provider is typically mandatory.
Cyber insurance. NZ insurers are increasingly asking for evidence of recent security testing at application and renewal. A pen test report from NSP is formatted to support your insurance application directly.
Significant environment changes. A new application, a cloud migration, a major infrastructure change, or a new integration with a third party. Each of these introduces new attack surface. A pen test after a significant change confirms your new environment is as secure as the old one.
After a security incident. Something happened – a breach, a phishing attack, suspicious activity. A pen test after an incident confirms what was actually compromised, identifies what else is exposed, and gives you confidence that the gaps have been closed.
Proactive risk management. You want to know what an attacker would find before they do. An annual pen test is the most direct way to answer that question.
A vulnerability scan is an automated tool that checks your environment against a database of known weaknesses. It is fast, repeatable, and useful but it tells you what might be exploitable, not what actually is.
A penetration test goes further. A skilled tester actively attempts to exploit the weaknesses a scan identifies and others that automated tools miss entirely. They simulate what a real attacker would do: chain vulnerabilities together, escalate privileges, move laterally through your environment, and reach your most sensitive systems.
The difference in output is significant. A vulnerability scan gives you a list. A pen test tells you what is actually dangerous, what an attacker could realistically do with it, and what to fix first.
Most compliance frameworks – ISO 27001, PCI DSS, NZISM – specifically require a penetration test, not just a vulnerability scan. Most cyber insurers do too.
NSP offers both. If you are not sure which is right for your situation, our team will help you scope the most effective engagement for your environment and objectives.
NSP pen tests are conducted using established, recognised methodologies – not proprietary checklists.
Frameworks we test against and reference:
– OWASP Testing Guide – the standard for web application security testing, covering the OWASP Top 10 and beyond
– NIST SP 800-115 – the technical guide to information security testing and assessment
– PTES (Penetration Testing Execution Standard) – a comprehensive framework for the full pen test lifecycle
– MITRE ATT&CK – the adversarial tactics and techniques matrix used to map findings to real-world attack patterns
Who does the work:
NSP pen tests are led by senior security practitioners with hands-on experience across a range of NZ and international environments. Our team is led by Geordie Stewart – CISO, MSc, CISSP – with more than 20 years of cybersecurity experience. You are not getting a junior analyst working through a checklist. You are getting someone who understands how real attacks unfold and knows where to look.
For businesses with specific compliance requirements, we can tailor our methodology and report format to match what your auditor or insurer needs.
F&B Distributor
We were pleased that NSP could conduct an independent review, assess our environment, understand security trends and weaknesses, and provide a comprehensive cybersecurity roadmap.
Charity Organisation
NSP played a crucial role in resolving significant technological challenges linked to our legacy system. As a charitable organization, operational efficiency with limited resources is critical. A resilient infrastructure and a reliable technology partner are essential for our success, and NSP proved to be the perfect match for our needs.
Commercial Leasing Company
NSP delivered and continues to deliver inspired solutions for our customers tailored to their needs.
Government Housing
NSP vCISO understood our requirements and his practical approach helped us build a strong security system.
Penetration testing – also called a pen test or ethical hacking – is an authorised simulated attack on your systems, carried out by security professionals to find vulnerabilities before real attackers do. NSP’s pen testers use the same techniques and tools that attackers use, but under a controlled scope agreed with you before testing starts. The goal is to find what’s actually exploitable – not just what shows up on an automated scan.
NSP offers penetration testing across external networks, internal networks, web applications, cloud environments, and social engineering. Every engagement includes a scoping phase to agree what’s being tested, active testing using manual and automated techniques, and a full written report with severity-rated findings and a prioritised remediation roadmap. We also provide a debrief walkthrough of the findings for your team.
A vulnerability scan is an automated check for known weaknesses – it tells you what might be exploitable. A penetration test goes further: a skilled tester actively attempts to exploit those weaknesses and others, simulating what a real attacker would do. A scan gives you a list. A pen test tells you what’s actually dangerous. Most compliance frameworks and cyber insurers require a pen test, not just a scan.
At minimum, annually and whenever there’s a significant change to your environment such as a new application, cloud migration, or major infrastructure update. ISO 27001, PCI DSS, and NZISM all reference regular penetration testing as a requirement. If you’re applying for or renewing cyber insurance, your insurer may ask for evidence of recent testing. NSP can help you build a testing programme that fits your risk profile and compliance obligations.
Increasingly, yes. NZ cyber insurers are asking for evidence of regular security testing before underwriting or renewing policies. A documented pen test from a professional provider is one of the strongest signals you can provide. If you also need a broader cyber insurance readiness assessment, NSP’s cyber insurance assessment service covers the full picture.
It depends on scope. A focused external network test or web application test typically takes 3–5 days of active testing. Larger environments or more complex engagements – internal network, cloud, social engineering combined – can take 1–2 weeks. We agree the scope and timeline with you before anything starts, and we work around your operational requirements.
Cost depends on scope, environment complexity, and the type of testing required. As a general guide, focused engagements for SMEs typically start from a few thousand dollars, while more comprehensive tests covering multiple environments are priced accordingly. NSP provides a clear, fixed-price quote based on the agreed scope before testing starts – no surprises. Get in touch for a scoping conversation.
NSP offers external network penetration testing, internal network penetration testing, web application penetration testing, cloud security testing, and social engineering assessments. If you’re not sure which type is right for your business, our team will help you scope the most effective engagement for your environment and objectives.
These terms describe how much information the tester is given before testing starts. Black box testing means the tester starts with no prior knowledge of your environment – simulating an external attacker with no inside information. White box testing means the tester is given full access to documentation, source code, and network diagrams – useful for deep technical reviews of specific systems. Grey box is the most common approach: the tester is given some context (for example, valid credentials or network diagrams) to focus testing on the areas that matter most. NSP will recommend the most appropriate approach for your objectives during scoping.
A penetration test has a defined scope, a known timeframe, and is focused on finding as many vulnerabilities as possible within that scope. A red team exercise is broader and more adversarial – the red team is given an objective (for example, “access the finance system”) and uses any means necessary to achieve it, including social engineering, physical access, and extended dwell time. Red team exercises test your detection and response capability, not just your preventive controls. Most businesses start with a pen test. Red team exercises are suited to organisations that already have a mature security programme and want to test it under realistic conditions.
This is one of the most common concerns and it is a legitimate one. NSP takes precautions to avoid causing disruption during testing. Before testing starts, we agree on what is in scope, what is out of scope, and what to do if something unexpected happens. We avoid destructive tests unless specifically agreed, and we work around your operational hours where required. In rare cases, vulnerability exploitation can cause unexpected behaviour in legacy systems – this is discussed during scoping so you can make an informed decision about what to test and when. The short answer: disruption during a well-scoped, professionally conducted pen test is uncommon and manageable.
It depends on your goal. If you want to know your actual current security posture – what an attacker could exploit right now – do not patch first. The test results are more useful when they reflect your real environment. If you have already fixed known critical vulnerabilities and want to confirm the fixes are effective, tell us during scoping and we will focus accordingly. For compliance-driven tests, your auditor or insurer typically wants the test to reflect your live environment at the time of testing.
Start with the Critical and High severity findings. These are the vulnerabilities that represent real, exploitable risk to your business right now. Your remediation roadmap from NSP sequences the fixes for you – you do not need to decide the order yourself. Once critical findings are addressed, work through the Medium and Low items on a schedule that fits your resources. For businesses with compliance obligations, NSP can conduct a retest after remediation to confirm findings have been resolved and to produce updated documentation for your auditor or insurer. If your pen test reveals structural security gaps rather than just individual vulnerabilities, a vCISO engagement can help you address the underlying programme issues.
Stay up to date with our resources on Modern Workplace, AI, Cloud, Managed services and Cybersecurity.

Cybersecurity
Shadow AI in Real Estate: What Your Team Is Using - And What You Don't Know About It
July 30, 2026

Cybersecurity
Shadow AI in Healthcare: What Your Clinical and Administrative Staff Are Using - And What You Don't Know About It
July 28, 2026

Cybersecurity
Shadow AI in Construction: What Your Team Is Using - And What You Don't Know About It
July 27, 2026

Managed services
9 Signs Your NZ SMB Needs a Managed Security Partner
July 24, 2026

Cybersecurity
Shadow AI in Accounting Firms: What Your Staff Are Using - And What You Don't Know About It
July 23, 2026
This eBook provides business leaders with a practical, concise, and informative guide to taking the most important step towards your digital security. The goal is to gain a good understanding of all you need to know about Pentesting to evaluate your network infrastructure and identify cybersecurity vulnerabilities.