service
Penetration Testing
Authorised, manual simulated attacks across your apps, networks and cloud.
A penetration test, or pentest, is a simulated cyber attack carried out by ethical hackers to identify vulnerabilities in your systems, networks, or applications. It’s like hiring someone to break into your business digitally, with your permission, so they can find the gaps before a real attacker does. For small to medium businesses in New Zealand, this means uncovering weak spots like misconfigured settings, outdated software, or insecure websites that could put customer data or operations at risk.
By running a pentest, Kiwi businesses can get a clear, expert view of where their security stands and what needs to be fixed. It helps protect sensitive information, supports compliance with data protection standards, and shows customers you take cyber security seriously. For many SMBs, a pentest is a practical step to building trust, reducing risk, and ensuring their systems can stand up to real-world threats, without waiting for something to go wrong first.
Based in Auckland? See our Auckland penetration testing page. To understand what a test costs, read our penetration testing cost guide for NZ.
What we offer
Drill into a specific test for the full detail, or talk to us about the right mix.
Web Application Penetration Test
A manual assessment of a browser-based application, following the OWASP Web Security Testing Guide to find the logic flaws, broken access controls and injection issues that scanners miss.
API Penetration Test
Testing against the OWASP API Security Top 10: broken object-level authorisation, broken authentication, excessive data exposure, rate limiting and injection, across REST and SOAP.
Internal Network Penetration Test
Simulates an attacker who already has a foothold inside your network, testing privilege escalation, lateral movement, Active Directory and segmentation.
External Network Penetration Test
Examines your internet-facing infrastructure the way a remote attacker would: exposed services, vulnerabilities, remote access, email and DNS, and breached credentials.
AI and LLM Penetration Test
Testing for AI features like chatbots, copilots and RAG systems: prompt injection and jailbreaks, data leakage, access control gaps, tool and plugin abuse, and model endpoint security.
Mobile Application Penetration Test
iOS and Android assessment following the OWASP MASTG: architecture review, static and dynamic analysis, network communication and local data storage.
Hardware Penetration Test
Assessment of physical and embedded devices such as IoT, medical and industrial equipment: device and firmware analysis, communication protocols and physical security.
Other services
CyberSafe Essentials
A fixed-price assessment built for small organisations with fewer than 20 users, covering the three areas attackers target most.
Secure Configuration Reviews
Your cloud and SaaS environments measured against security baselines.
Technical Controls Validation
A check that your defences are configured correctly and would stop an attacker.
Vulnerability Scanning
Automated assessment of your networks and web apps, validated by a human.
Bespoke Testing
Testing shaped around your requirements when your needs do not fit a standard engagement.