New Zealand Information Security Manual
We architect authentication, privileged access and auditability to meet NZISM guidelines, specifically Chapter 16 identity controls, multi-factor authentication requirements and cryptographic protection.
Aotearoa New Zealand · Core Market
MAITS provides independent identity architecture, cyber security and access governance advisory for New Zealand government agencies, crown entities, local authorities and commercial enterprises. Headquartered in Wellington, we help organisations modernize access, eliminate standing privilege and achieve robust compliance with New Zealand cyber security standards.
New Zealand organisations face distinct sovereign identity challenges: navigating the New Zealand Information Security Manual (NZISM), adhering to Protective Security Requirements (PSR), respecting the Privacy Act 2020, and moving away from legacy on-premises Active Directory environments toward modern cloud trust architectures.
MAITS provides hands-on senior architects who understand public sector machinery, crown procurement and local operating realities.
Regulatory & security alignment
We translate government standards and statutory privacy obligations into concrete architecture decisions and enforceable system controls.
We architect authentication, privileged access and auditability to meet NZISM guidelines, specifically Chapter 16 identity controls, multi-factor authentication requirements and cryptographic protection.
Governance, personnel security lifecycle alignment, and segregation of duties configured to support Mandatory Requirements under the NZ Protective Security Requirements framework.
Architecting identity and credential exchange around IPP 5 (storage and security of personal information), IPP 10 (limits on use) and strict data minimisation principles across all identity flows.
Strategic guidance on the Digital Identity Services Trust Framework (DISTF), privacy-preserving digital credentials, and interoperability between public registers and commercial relying parties.
Enterprise Microsoft Entra
The vast majority of New Zealand enterprises and government agencies run Microsoft Entra ID (formerly Azure AD). However, many tenants still rely on legacy MFA methods (telephony, basic push notifications), unmanaged hybrid sync from aging Active Directory domain controllers, and unreviewed standing administrative access.
MAITS designs and executes end-to-end Entra modernisations:
Capabilities in NZ
Engage MAITS for targeted technical assessments, architecture reviews or embedded engineering capability.
Structured 9-area diagnostic of your identity architecture, authentication strengths, PIM, Conditional Access and governance controls.
Explore IAM Health CheckStrategy and rollout roadmap for hardware security keys, device-bound passkeys and synced passkeys across enterprise fleets.
Explore Passkey & PasswordlessTiered administration models, break-glass runbooks, session controls and privileged workstation architectures.
Explore Privileged Access (PAM)Role-based and attribute-based access control, entitlement lifecycles and auditable access review certification workflows.
Explore Identity Governance (IGA)Modern customer journeys, migration from Azure AD B2C to native Entra External ID, and high-assurance customer verification.
Explore Customer Identity (CIAM)Fractional Chief Identity Architect or lead security advisory for major digital transformations and public sector programmes.
Explore Technical LeadershipStart a conversation
Whether preparing for an audit, planning an Entra modernization, or rolling out phishing-resistant passkeys, our Wellington team is ready to assist.