Revolution InfoSec launches SecurityCentral in New Zealand
Thu, 17th Sep 2026 (Today)
Revolution InfoSec has launched SecurityCentral in New Zealand, targeting business leaders who manage cyber security risk.
The platform was developed for a "forgotten middle" of organisations that have outgrown spreadsheets and informal processes but lack dedicated cyber security teams and the budget for more complex governance systems.
According to the Wellington-based consultancy, that segment faces growing pressure as cyber security oversight shifts from an IT issue to a boardroom responsibility. Medium-sized organisations are increasingly expected to meet many of the same governance and assurance requirements as larger companies, despite having fewer internal resources.

Revolution InfoSec said proposed legal changes in New Zealand could intensify that pressure. Under the scenario it outlined, directors could face personal criminal liability of up to $500,000 for a critical breach.
SecurityCentral combines governance, risk and compliance functions with vulnerability management in a single platform. The approach is designed to give executives and owners visibility over both governance activity and technical weaknesses without relying on separate systems.
Many governance, risk and compliance products are designed for technical specialists, the consultancy said. By contrast, SecurityCentral is positioned as a tool for decision-makers seeking clearer reporting on cyber risk and evidence that controls are in place.
The platform supports ISO/IEC 27001 and New Zealand-specific frameworks, including the New Zealand Minimum Cyber Security Standards and Te Whatu Ora's Health Information Security Framework. For organisations operating in or supplying to the public sector, those frameworks can play an important role in procurement and customer assurance processes.
Market gap
The launch reflects a broader shift in demand as more organisations look for ways to document their cyber posture for boards, insurers, customers and regulators. That need is spreading beyond large enterprises to businesses big enough to face scrutiny but not large enough to maintain specialist teams.
Founded in 2023, Revolution InfoSec said it created the platform after repeated consulting work with businesses that struggled to translate technical cyber issues into management decisions. Many clients, it said, were caught between basic administrative tools and software designed for specialist users.
"Businesses aren't looking for another complex IT platform. They're looking for confidence that the right things are being done. They need risks identified, and meaningful information that they can use to make decisions and provide assurance to their board, customers and stakeholders," said Alistair Ross, founder of Revolution InfoSec.
The company said that demand has been shaped by customer trust requirements, cyber insurance expectations and governance obligations. Together, those pressures are bringing a wider group of New Zealand organisations into the cyber governance market.
Single view
The company highlighted the integration of vulnerability management with governance oversight as a point of difference. In many organisations, technical scanning and remediation data sits in separate tools from policy records, control assessments and board reporting, making it harder for non-technical leaders to form a complete picture.
By bringing those elements together, the platform is intended to show both whether security controls are documented and whether technical weaknesses are being identified and tracked. That could matter for organisations trying to demonstrate not only that they have policies in place, but also that they monitor operational risks.
Organisations in regulated sectors and public sector supply chains in New Zealand are likely to be among those watching the market closely. Support for local frameworks may be important for buyers that need systems aligned with domestic compliance expectations rather than products shaped mainly around overseas standards.
Ross said the company's client work had revealed a consistent gap in the software available to this part of the market.
"We built SecurityCentral because we kept seeing the same problem. Growing New Zealand businesses were expected to manage cyber risk like large enterprises, but the tools available were either too basic or designed for organisations with dedicated cyber security teams. We wanted to build something that gave business leaders a complete picture of cyber risk in one place, while speaking the language of business rather than IT," Ross said.