Case Studies & Expert Insights
Explore expert insights and case studies from Liverton Security.

Complexity of Security (Part 1)
All Case Studies & Expert Insights
Deep dive into solutions and cybersecurity topics with our experts

Beyond the Firewall: Why Real Pen Testing Must Cover the Whole Business
Most penetration tests focus on firewalls and systems—but attackers don’t. They look for the easiest way in, whether that’s a forgotten network device, an unlocked door, or a convincing phishing email.

From Open Ports to Organisational Maturity: Why Pen Testing Is the Foundation of a Healthy Security Posture
“No issues detected” can create a dangerous sense of false confidence. Compliance may satisfy an audit, but it does not prove security controls will withstand real-world threats. Penetration testing and security maturity assessments help uncover hidden vulnerabilities, validate defences, and expose the risks attackers are looking for.

Vibe Coding: The Hidden Security Risks of AI-Generated Software
Artificial intelligence is making software development more accessible than ever, allowing users to generate code simply by describing what they want. This emerging practice, often called “vibe coding,” promises faster development and greater accessibility. However, without proper requirements, testing, and security awareness, AI-generated software can introduce serious vulnerabilities. Understanding the risks behind AI-assisted development is essential before deploying code into production environments.

AI Prompt Poisoning: Understanding the Threat – And Why You Need to Pay Attention
Artificial intelligence is rapidly changing the way we work, and with that change comes a new set of security challenges. One of the most concerning is ‘AI prompt poisoning’ – a technique where someone intentionally manipulates the instructions given to an AI model to generate unwanted or harmful results.

When NZ organisations get breached, the same question keeps coming up—"How did this happen when we were compliant?"
Compliance frameworks like NZISM, PSR, and the Privacy Act were never intended to be treated as annual checklists. Their underlying assumption is that controls operate continuously, risks are reviewed as environments change, and people actively protect information. When organisations treat compliance as a finish line, security drifts — and that gap between audits is where breaches occur. Real security maturity comes from ongoing assurance, not point-in-time compliance.

Bridging Directly To Continuous Maturity Assessments
As organisations change, security often drifts out of alignment. Continuous maturity assessment helps identify weakening controls, workarounds, and emerging risks early—before they turn into incidents. It provides a practical way to keep security relevant, effective, and aligned with how a business operates as it evolves.