Bastion Security

Hacking for Heroes

We think that organisations who are working hard to help the community and vulnerable groups are Heroes!
Apply Now

Hacking for Heroes Programme

Our goal is to strengthen the security posture of community-focused groups, ensuring they can protect the sensitive information they handle and continue their vital work without disruption.

What is the Hacking for Heroes programme?

Bastion Security Group’s Hacking for Heroes programme donates $80,000 worth of cybersecurity consultancy annually to New Zealand not-for-profit organisations. Our goal is to strengthen the security posture of community-focused groups, ensuring they can protect the sensitive information they handle and continue their vital work without disruption.

Why are we doing this?

Often not a week goes by without a data breach or ransomware attack popping up in the news. Bastion Security would like to help not-for-profit organisations identify and provide guidance on how to fix security issues, so they are less likely to be involved in a security event that could negatively impact what they do. We think that this is particularly important as community organisations often hold information on behalf of vulnerable people.

Who should apply?

We welcome applications from not-for-profit organisations that handle sensitive information or operate in high-trust environments. If your organisation provides essential services and could benefit from enhanced cybersecurity but lacks the internal resources, this programme is for you.

Application process

The application process is simple and focused on impact. We want to understand what you do, how you help, and how better security could support your mission.

  1. Complete our short expression of interest form
  2. If shortlisted, we’ll follow up with a call to learn more
  3. Final applicants will be selected based on need, alignment and impact potential.

Key dates

Expressions of interest for the 2026 programme are now open.

  • Applications open: 12th August - 28th August 2026
  • Short listing of applicants: 31st August - 4th September 2026
  • Final interviews: 7th - 11th September 2026
  • Successful applicants contacted: 11th September 2026
  • Engagements underway: September - February 2027


Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server - (CVE-2026-12620)
During a security engagement, Leo Diamat discovered that the GridTime 3000 GNSS Time Server web application transmitted session access tokens via URL query string parameters on multiple endpoints.
Cross-Site Scripting (XSS) Vulnerability on Several Endpoints by Utilising Cross-Site Request Forgery (CSRF) in GridTime™ 3000 GNSS Time Server - (CVE-2026-12619)
During a security engagement, Leo Diamat discovered that multiple endpoints in the GridTime 3000 GNSS Time Server web application were vulnerable to reflected Cross-Site Scripting (XSS) via an unsanitised token parameter.
PHP-FPM (PHP Source) - Stored Cross-Site Scripting (XSS) (CVE-2026-6735)
During a security engagement, Conrad Draper discovered a stored XSS vulnerability in the PHP-FPM status endpoint which was due to a lack of input sanitisation of the request URI. This affects the request URI when displaying stored content.