phew phew is a boutique, Auckland-based pen testing company, providing accessible and understandable advice and services.

Our specialist pen testing and cyber security consulting team are experienced, knowledgeable and well respected. We are cyber security specialists providing a range of services and advice to SMEs across NZ and Australia.

We're proud to announce that phew is now a CREST ANZ Approved Company Member!CREST ANZ recognised our work ethics, manag...
17/06/2026

We're proud to announce that phew is now a CREST ANZ Approved Company Member!

CREST ANZ recognised our work ethics, management discipline and commitment to technical excellence as meeting the highest standards for cybersecurity service providers.

For the organisations we work with, this adds a further layer of confidence that we deliver with the rigour and integrity they deserve.

Learn more about what this accreditation means for you on our website:

Independent accreditation We’re CREST accredited phew is recognised for its integrity, technical excellence, and practices that meet the highest standards […]

Since Claude or Codex Security can scan your codebase, find vulnerabilities, and generate a report, do you really need a...
09/06/2026

Since Claude or Codex Security can scan your codebase, find vulnerabilities, and generate a report, do you really need a pen tester?

This is a fair question, and one we are hearing more often. An honest answer is that AI security tooling is genuinely useful, and the capabilities are advancing fast, but there is a meaningful gap between what is being marketed and what is happening in practice.

In our latest piece, we look at where AI adds real value, where it produces noise, and why the assurance gap matters more than most teams realise, particularly for SaaS businesses facing an increasingly loud and complex threat environment.

Read in full on our blog:

One question is starting to come up more frequently in conversations about pe*******on testing, and it is an entirely reasonable […]

19/05/2026

Many buyers commission a pe*******on test without a clear way to evaluate or understand the quality of what they've signed up for.

Price and delivery timing provide signals that are easiest to read, but these metrics alone are also fairly unhelpful in terms of being a predictor of quality. The difference between a test that builds genuine confidence and assurance, and one that just produces findings, often comes down to buyers asking questions upfront which most aren't sure how to ask. So we wrote a guide to help with that.

It covers what separates good providers from the rest, what the scoping conversation should actually feel like and include, why source code access matters more than most buyers realise, and what confidence in your security posture looks like when it's backed by proper evidence rather than assumption.

If you're a technical leader evaluating your options for the first time, or searching for a useful framework to help you shortlist providers, we'd love you to take a look.

📖 Read in full on our blog:

Most teams commission their first web application pen test without really knowing what's about to happen.The process can...
22/04/2026

Most teams commission their first web application pen test without really knowing what's about to happen.

The process can feel like a black box, which is ironic, given that black-box testing isn't where you should be heading. We wrote this guide because we believe an informed buyer makes better decisions and gets more from the experience.

In it, we walk through the full lifecycle of a web application pen test in plain English: from scoping conversations and methodology selection, through the testing itself, to the initial report, remediation, re-testing, and the final assurance output your board and auditors can actually use.

We cover what source code-supported testing unlocks, why your test environment matters more than most people realise, how findings are rated and why honest ratings matter, and what separates a one-off compliance exercise from a genuine step forward in your security posture.

No jargon. No fear-mongering. Just a clear picture of what good looks like.

Full article ⏩

It’s not uncommon for teams to commission a pen test (particularly their first one) without really knowing what’s about to […]

Since phew was founded, our focus has been on building a business grounded in quality. That meant investing heavily in h...
01/04/2026

Since phew was founded, our focus has been on building a business grounded in quality. That meant investing heavily in how we work, developing rigorous methodologies, and holding ourselves (and our pen testing) to high standards. By delivering work we could genuinely stand behind, we prioritised substance over presentation, and outcomes over optics.

Along the way, we didn’t really pause to spend time fully articulating who we are, what we stand for, and why it matters, but recently we decided it was time to address that. By undertaking a brand story exercise with the team at Flux B2B, we've been able to articulate and define our identity more clearly, whilst building a consistent way to communicate it.

At phew's core is a simple idea - that confidence in security should be backed by evidence, not assumption. Too often, tech teams are asked to accept results they can’t fully interrogate, delivered through processes that feel unclear or inaccessible. That has become the norm across the industry, but it’s not something we’re comfortable with.

We believe that trust should be earned through clarity. That means showing the reasoning behind outcomes, not just presenting them. It means helping customers understand not only what we’ve found, but why it matters and how to act on it. And in particular, by grounding our pe*******on testing in industry recognised standards, not just using a rule of thumb or unclear testing methodologies.

This thinking shapes how we frame our story at phew. We recognise that consumers are sometimes forced to make decisions based on limited signals (perhaps comparing providers on time, price, or surface-level outputs, without a clear way to judge depth or quality) and as a result, meaningful differences in approach often go unnoticed.

Our response has been to lean further into what we already value: clear communication, appropriately scoped engagements, and outputs grounded in real evidence. Because we combine structured testing with experienced judgment, we place a strong emphasis on helping our customers build their own understanding (not just handing over a report). For us, this is about more than just delivering a service, it’s about contributing to a higher standard.

Alongside this process with Flux, we revisited how we present ourselves through our branding by working with the fabulous team at Smith & Peach. Our refreshed visual identity (most notably our proposals and reporting) is designed to reflect the same principles that underpin our work: clarity, consistency, and focus. Every detail is intended to make information easier to absorb and navigate, while maintaining a professional and composed tone.

In an industry that often feels loud or overly complex, we’ve deliberately taken a different approach. We aim to be clear without being simplistic, and professional without being distant. The goal is to make our work (and its implications) easier to engage with, because ultimately, that’s what matters.

Our feeling is that when our customers have a clear understanding of their security posture, supported by evidence they can rely on, they’re better equipped to make decisions and have meaningful conversations. They can approach challenges with confidence, rather than uncertainty. That’s the outcome we’re working towards.

This process has been heaps of fun, but also marks an important step for us. Not because it changes what we do, but because it helps us express it more effectively. Having spent years building the foundations, we’re ready to communicate them clearly.

This article first appeared on phew's blog at:

Since phew was founded, our focus has been on building a business grounded in quality. That meant investing heavily in […]

We’ve got the keys, and our name is over the door!phew has officially moved into its new office space in downtown Auckla...
01/03/2026

We’ve got the keys, and our name is over the door!

phew has officially moved into its new office space in downtown Auckland.

Whilst we're growing, we remain firmly boutique and quality-focussed, committed to doing cybersecurity properly for our customers across NZ and Australia.

Thank you to our team, clients and industry partners for their support. We’re excited for what’s ahead.

If you’re nearby, come and say hello, the coffee is good ☕

Address

17 Dockside Lane
Auckland
1010

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+6498840969

Alerts

Be the first to know and let us send you an email when phew posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to phew:

Shortcuts

Share