Bastion Security

Hacking for Heroes

We think that organisations who are working hard to help the community and vulnerable groups are Heroes!
Talk to an expert

Hacking for Heroes Programme

Our goal is to strengthen the security posture of community-focused groups, ensuring they can protect the sensitive information they handle and continue their vital work without disruption.

What is the Hacking for Heroes programme?

Bastion Security Group’s Hacking for Heroes programme donates $80,000 worth of cybersecurity consultancy annually to New Zealand not-for-profit organisations. Our goal is to strengthen the security posture of community-focused groups, ensuring they can protect the sensitive information they handle and continue their vital work without disruption.

Why are we doing this?

Often not a week goes by without a data breach or ransomware attack popping up in the news. Bastion Security would like to help not-for-profit organisations identify and provide guidance on how to fix security issues, so they are less likely to be involved in a security event that could negatively impact what they do. We think that this is particularly important as community organisations often hold information on behalf of vulnerable people.

Who should apply?

We welcome applications from not-for-profit organisations that handle sensitive information or operate in high-trust environments. If your organisation provides essential services and could benefit from enhanced cybersecurity but lacks the internal resources, this programme is for you.

Application process

The application process is simple and focused on impact. We want to understand what you do, how you help, and how better security could support your mission.

  1. Complete our short expression of interest form
  2. If shortlisted, we’ll follow up with a call to learn more
  3. Final applicants will be selected based on need, alignment and impact potential.

Key dates

Expressions of interest for the 2025 programme are now open.

  • Applications open: 17th June - 17th July 2025
  • Short listing of applicants: 18th - 19th July 2025
  • Final interviews: 21st - 24th July 2025
  • Successful applicants contacted: 30th July 2025
  • Engagements underway: August 2025 - January 2026


Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Silverstripe - Cross-Site Scripting (XSS) Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in the administrator panel of Silverstripe CMS, specifically in the handling of the user input within the form messages module.
Silverstripe - Host Header Injection
A Host header injection vulnerability in Silverstripe has been identified that allows an attacker to poison the password rese
Statamic CMS
Sam Schroder found a local file inclusion (write only) vulnerability inside of the upload functionality of Statamic CMS. This affects front end components like forms with `assets` fields.