Security Defects Are Silent Until They're Not.
The three security testing gaps that leave NZ programmes exposed — and how independent verification prevents them.
Automated Scanners Miss Business-Logic Flaws
SAST and DAST tools find known CVEs and injection patterns — but they can't reason about broken authentication flows, insecure direct object references, or business-logic bypasses specific to your application. Independent security testers combine tool-assisted scanning with manual analysis of how your system actually behaves under adversarial conditions.
Cloud Misconfiguration Is the Leading NZ Breach Vector
Overly permissive S3 buckets, unencrypted secrets in environment variables, and unrestricted security groups are consistently the entry point for breaches in NZ public and private sector systems. Cloud configuration review requires a different lens from application testing — one that looks at the infrastructure as an attacker would, not as a developer would.
API Security Is Tested Last, If At All
As applications move to API-first architectures, the attack surface shifts to the API layer — yet most security testing is still focused on the UI. Authentication bypass, excessive data exposure, and broken object-level authorisation in APIs are among the most exploited vulnerabilities in NZ enterprise systems. Dedicated API security testing is non-negotiable.
How Resync Approaches Security Testing
Security testing that only runs automated scans misses the vulnerabilities that matter most. Resync combines SAST, DAST, and manual application security testing in a structured methodology based on OWASP Testing Guide v4 and NZ Government security requirements. We test how your system behaves under adversarial conditions — not just whether it passes a compliance checklist.
Every security testing engagement starts with threat modelling specific to your application's architecture, data classification, and user base. We prioritise testing coverage based on risk — authentication and session management, injection surfaces, access control, API endpoints, and cloud configuration — rather than running the same scan template against every client.
Findings are reported in business-impact terms so programme leadership and developers both understand what needs fixing, and in what order.

What We Test
Full application security coverage from OWASP Top 10 through API security, cloud configuration, and authentication testing.
OWASP Top 10
Systematic coverage of the OWASP Top 10 web application security risks — injection, broken auth, sensitive data exposure, security misconfiguration, XSS, and more — using manual testing combined with automated scanning.
API Security Testing
Test REST and GraphQL API endpoints for broken object-level authorisation, excessive data exposure, mass assignment, injection, and rate-limiting bypass. Critical for microservices and API-first architectures.
Cloud Configuration Review
Assess AWS and Azure configuration for overly permissive IAM roles, exposed storage, unencrypted secrets, unrestricted security groups, and logging gaps — the most common entry point for production breaches.
Authentication & Authorisation
Test authentication flows, session management, multi-factor authentication implementation, OAuth and OIDC configurations, and role-based access control for bypass vulnerabilities and privilege escalation paths.
Penetration Testing
Manual adversarial testing of your application's attack surface — combining OSINT, enumeration, exploitation, and post-exploitation analysis to simulate what a real attacker would do with your system.
Compliance Verification
Map security testing results to NZ Government security requirements, NZISM controls, PCI DSS obligations, and ISO 27001 control objectives — so your programme has documented, independent evidence of security assurance.
Tool Independence
No Scanner to Sell.
No Vendor Relationship to Protect.
Most security testing firms are affiliated with a tool vendor or carry reseller agreements that bias their methodology. Resync has no relationship with any security tool vendor. We select tooling — OWASP ZAP, Burp Suite Professional, Nessus, or cloud-native scanners — based entirely on what best covers your attack surface.
Why Resync for Security Testing?
Independent. Methodology-first. Results that go to programme leadership, not just your dev team.
Truly Independent
No vendor relationships. No tool sales targets. We're accountable only to you — which means our findings are always honest.
NZ-Based Specialists
Our QA teams are embedded in New Zealand. That means faster mobilisation, no timezone friction, and specialists who understand the local regulatory and technology landscape.
Capability Transfer Included
Every engagement includes documentation, training, and hands-on knowledge transfer. When we leave, your team is stronger — that's the point.
Frequently Asked Questions
What programme directors and security leads ask before engaging Resync for application security testing.
Q.What's the difference between a vulnerability scan and a penetration test?
A vulnerability scan uses automated tools to identify known weaknesses — missing patches, known CVEs, misconfigured headers. A penetration test goes further: a tester manually exploits vulnerabilities to demonstrate real-world impact, chains weaknesses together, and identifies business-logic flaws that scanners can't find. Resync provides both, scoped to your risk profile and timeline.
Q.Does Resync cover NZ Government security requirements?
Yes. Resync's security testing methodology maps to the NZ Information Security Manual (NZISM), the Government's Protective Security Requirements (PSR), and CERT NZ guidance. For classified systems, we work within the appropriate clearance and engagement frameworks. Our findings documentation supports GCISO reporting and AoG supplier requirements.
Q.How long does a security testing engagement take?
A focused web application assessment covering OWASP Top 10 and authentication testing typically takes 5-10 business days. A full penetration test including cloud configuration, API security, and manual adversarial testing runs 2-4 weeks depending on application complexity. We scope engagements based on your attack surface and timeline.
Q.Can you retest after our developers fix the findings?
Yes — and we recommend it. Resync provides a retest as part of every security testing engagement to verify that findings have been correctly remediated rather than just closed. A vulnerability that's partially fixed is still a vulnerability. Retest scope is focused on the specific findings rather than a full assessment repeat.
