Assess compliance with the PSR framework

Review your organisation’s alignment to the NZ Protective Security Requirements. Understand where you stand and what’s needed to meet government expectations.
Talk to an expert
PSR Assessment

Protective security requirements assessment

The Protective Security Requirements (PSR) is a framework developed by the New Zealand Government to guide organisations in managing physical, personnel, information and governance security. It’s essential for any organisation handling government information - including private sector providers - to align with PSR standards. A formal assessment shows your government clients that your security posture meets their expectations.

Our PSR Maturity Assessment starts with a structured gap analysis across one or all PSR domains. We identify your current strengths and risks across governance, physical, information and personnel security.

We then work with you to build a prioritised programme that strengthens security maturity. This includes tailored advice, implementation support and establishing clear governance and reporting frameworks. It’s especially valuable for organisations needing to uplift security across the board, with a focus on long-term resilience and defensible reporting.
The PSR Maturity Assessment will begin with a gap assessment to understand your current strengths and weaknesses across the areas of security governance, physical security, personnel security and information security. We can assess against one or all of these domains.

Following this we will work with you to develop a work programme to support you to achieve your desired state and provide ongoing advice and guidance to help your teams implement the programme. As part of this we will also help you to establish appropriate governance and reporting of the programme. This is recommended for all organisations looking to uplift their security across the board to better protect their people, information and assets.

  • Identify gaps across the PSR domains
  • Build a tailored roadmap to improve PSR maturity
  • Get guidance to support implementation and ongoing reporting
Service detail

PSR Four Core Policy Areas

The PSR framework defines four critical policy areas: Security Governance (GOV), Personnel Security (PERSEC), Information Security (INFOSEC), and Physical Security (PHYSEC). All organisations handling government information should align with these standards to meet compliance expectations and build a strong security foundation.

The Four Pillars of Protection

These four policy areas help identify, manage, and reduce risk. They serve as a practical framework for protecting people, information, and assets.

Security Governance
GOV 1 — Establish and maintain the right governance
GOV 2 — Take a risk-based approach
GOV 3 — Prepare for business continuity
GOV 4 — Build security awareness
GOV 5 — Manage risks when working with others
GOV 6 — Manage security incidents
GOV 7 — Be able to respond to increased threat levels
GOV 8 — Assess your capability
Information Security
INFOSEC 1 — Understand what you need to protect
INFOSEC 2 — Design your information security
INFOSEC 3 — Validate your security measures
INFOSEC 4 — Keep your security up to date

Personnel Security
PERSEC 1 — Recruit the right person
PERSEC 2 — Ensure their ongoing suitability
PERSEC 3 — Manage their departure
PERSEC 4 — Manage national security clearances

Physical Security
PHYSEC 1 — Understand what you need to protect
PHYSEC 2 — Design your physical security
PHYSEC 3 — Validate your security measures
PHYSEC 4 — Keep your security up to date
Our delivery process

High level approach

Depending on your needs, we’ll either assess your maturity across all four PSR domains or focus on specific areas. For government agencies, we can also support completion of your PSR self-assessment for formal submission.
Roadmap
After the assessment, we’ll work with you and your leadership team to define appropriate target.
Maturity implementation support
We provide practical support to implement agreed recommendations and aligning resources
Track and reassess
We help you embed regular progress reviews to ensure momentum is maintained. Our team can assist with status updates, performance tracking, and repeat assessments to keep your PSR posture current.
Benefits

Why work with us

Our team includes consultants with direct experience in government security roles. We understand the compliance environment, the expectations of senior public sector stakeholders, and how to navigate
Trusted by government agencies
We’ve worked with agencies across central and local government. Our experience gives us insight into both operational needs and strategic expectations
Practical, risk-based guidance
We don’t just deliver reports. We help you understand your risk exposure, prioritise actions, and make informed decisions based on what’s most importa
Clear, actionable reporting
Our reporting is designed for decision-makers. We keep it clear, concise, and focused on what your leadership team needs to take confident action.
What comes next

Expand your security coverage

A PSR programme helps you gain and maintain a strong compliance position across all four PSR domains. We support you beyond the initial assessment with practical steps to embed improvements and meet evolving expectations.

  • Ongoing maturity assessments across governance, personnel, physical and information security
  • Guidance to maintain alignment with NZISM, PSR and sector-specific requirements
  • Support with reporting, validation and board-level updates
Talk to an expert
Executive and Board Security Governance Training
We train executives and boards on their cybersecurity oversight role — focusing on risk framing, accountability, and key governance responsibilities.
Instructor Led ISO27001 Training
This instructor-led course equips participants with the knowledge and skills needed to become certified to lead, plan, and conduct ISO 27001 audits.
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

Am I obligated to follow the PSR?

If you are a government organisation (including Crown entities), the PSR is either mandated or encouraged. If you are a private sector organisation (especially if you handle government information or provide services to agencies) then it is also encouraged. The principles are sound and Bastion recommends anyone providing services to government organisations to consider adopting them

Will following the PSR keep me safe?

At a high level, if you maintain good maturity against each of the PSR requirements then you will be a lot safer than those who don't. It's all about minimising risk.

Can you help me improve in all the areas, or just information security?

We can help across all areas of the PSR. We have deep experience and expertise in all areas of the PSR.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.