Assurance, Strategy & Secure AI · ANZ

See your risk clearly. Defend it deliberately.

Independent cyber assurance and strategy for New Zealand and Australian business. We make you cyber-secure and cyber-safe, ready for the standards your customers and insurers expect, and safe to adopt AI.

A no-obligation conversation about where you stand and where to start.

IndependentAdvice, not product sales
Strategy-ledRisk before tooling
ANZ-basedLocal frameworks & context
25+
Years at CISO & CIO level
100%
Independent, no product sales
NZ+AU
SMB specialists
CISM·MSc
Qualified & credentialled
What we do today

Know where you stand. Act on what matters.

Strong security starts with clarity: knowing where you stand, what matters most, and what to do next. These are the services Mosaic delivers now, independent of any product we might sell you.

Security Strategy & vCISO

Board-ready direction and a prioritised roadmap, delivered as fractional CISO leadership that turns cyber risk into clear, costed decisions.

Risk & Maturity Assessment

A clear, evidence-based view of your cyber risk, security maturity and architecture, measured against the Essential Eight, NIST CSF, NZISM and ISO 27001 across cloud and on-premise, so investment goes where it counts.

Governance, Risk & Compliance

Policies, frameworks and audit-readiness that fit how you work, covering ISO 27001, SOC 2, Essential Eight and SMB1001, plus third-party and supply-chain risk and secure SDLC review against OWASP SAMM.

Certification & Accreditation (NZISM)

We take your systems through NZISM Certification and Accreditation: assembling the control evidence, supporting the independent certification assessment, and preparing the residual-risk case your accreditation authority needs to sign off.

Privacy Impact Assessments

Structured assessment of privacy risk for new projects, systems and data flows, aligned to the Privacy Act 2020 and Office of the Privacy Commissioner guidance, with clear, defensible findings.

Secure AI Adoption

Adopt AI with confidence, not exposure. We help you govern AI use, assess model and data risk, and put practical guardrails in place, aligned to the NIST AI RMF, ISO/IEC 42001 and the CSA AI Controls Matrix.

Secure AI Adoption

Your team is already using AI. Are you covered?

Staff are pasting sensitive data into AI tools, and your customers and insurers are starting to ask how you govern it. We help you move fast on AI without the exposure: clear policy, practical guardrails, and a risk assessment that holds up to scrutiny.

  • An acceptable-use policy and governance your board can sign off
  • Assessment of model, data and shadow-AI risk across your business
  • Guardrails mapped to the NIST AI RMF, ISO/IEC 42001 and CSA AI Controls Matrix
Get AI-ready Ask us about it in your first conversation.
Expanding

Growing into full-spectrum defence

Our assurance and strategy work is live today. Next, we're adding a 24/7 managed capability and offensive testing, delivered with carefully chosen partners and ANZ data residency, so Mosaic covers you end to end. Register your interest and we'll tell you the moment they launch.

Launching soon

Managed Detection & Response

Continuous, expert-led detection and response across your endpoints, identity and cloud, without you building a team.

Launching soon

24/7 Security Operations (SOC)

Round-the-clock monitoring with local business-hours analysts and follow-the-sun overnight cover, data kept in-region.

Launching soon

Penetration Testing

Hands-on testing of your applications, networks and cloud to prove what an attacker could really do, and how to stop them.

Our approach

From uncertainty to assurance

Every engagement follows the same disciplined path, so your security becomes deliberate, measurable and something you can prove.

01

Assess

We map your assets, risks and current maturity against the frameworks that matter to your business and your customers.

02

Strategise

We turn findings into a prioritised, board-ready roadmap of pragmatic actions matched to your risk appetite and budget.

03

Strengthen

We help you close the gaps: controls, governance, architecture and maturity uplift against your chosen framework, with hands-on support.

04

Assure

We validate the result independently and keep measuring it, so you can demonstrate your posture with confidence.

Why Mosaic

Independent by design

We don't resell products, so our only agenda is your security. We start with your business risk, turn it into decisions your board can act on, and build protection in layers, like a mosaic, so nothing rests on a single control.

Independent and vendor-agnostic

We take no product commissions and have nothing to sell but our expertise, so every recommendation is made in your interest, not ours.

Strategy before tooling

Tools can't rescue a weak strategy. We get the thinking, governance and priorities right first, then let the technology follow.

Pragmatic and right-sized

We translate the frameworks that matter, from the Essential Eight and SMB1001 to ISO 27001 and the Privacy Act, into plain, affordable actions sized for a small or medium business, so you become genuinely cyber-secure and cyber-safe, not just compliant on paper.

Clear and accountable

Plain-English reporting, prioritised actions and measurable outcomes, so you always know where you stand and what to do next.

Cyber-secure and cyber-safe, proven with evidence you can put in front of your board, your customers and your insurers.The Mosaic Cyber Defence promise

Who's behind Mosaic

Senior expertise. Direct access.

Mosaic is led by a practitioner with more than 25 years in senior security and technology roles, spanning CISO, CIO, CTO and COO. You work directly with that seniority, not a junior learning on your account. And because we sell no products and earn no vendor commissions, our advice answers to you, not a supplier.

MSc Cyber Security CISM TOGAF CSA TAISE (in progress) 25+ years in security leadership
Start the conversation

Know where you stand.

Book a no-obligation conversation. We'll get to grips with your situation, show you where the real risk sits, and scope the work that gets you cyber-secure and cyber-safe.

  • A straight read on where you're most exposed
  • The priorities that matter most for your business
  • A clear, costed plan for what comes next
New Zealand · Australia

No obligation. We reply within one business day.