Overcyte’s cover photo
Overcyte

Overcyte

Technology, Information and Internet

New Plymouth, Taranaki 447 followers

Continuous cyber resilience for critical infrastructure & essential services operators

About us

Cyber Risk Intelligence for Critical Infrastructure and Essential Services. Overcyte helps organisations understand cyber risk, measure resilience, and prioritise actions that deliver meaningful security outcomes. Built for the organisations that communities, governments, and economies depend upon every day.

Website
www.overcyte.com
Industry
Technology, Information and Internet
Company size
11-50 employees
Headquarters
New Plymouth, Taranaki
Type
Privately Held
Founded
2025

Employees at Overcyte

View 6 employees at Overcyte

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • We’re proud to share that Overcyte has been named a finalist in two categories at the 2026 Reseller News Innovation Awards!   🏆 Product 🏆 Software / SaaS   It’s fantastic recognition for what our team has been building here in New Zealand, and for our mission to help organisations move beyond point-in-time compliance towards continuous cyber resilience.   A big thank you to our team, customers, partners and everyone who has supported Overcyte on the journey so far.   We’re looking forward to celebrating alongside New Zealand’s technology and channel community in Auckland in October.   #Overcyte #InnovationAwards #CyberSecurity #SaaS #CyberResilience

    • No alternative text description for this image
  • View organization page for Overcyte

    447 followers

    "at no point was there a risk to the wider energy system... We work closely with the energy sector to protect infrastructure and ensure the highest security standards" The ongoing Middle Eastern conflict has seen Iranian hackers blamed for a recent four day shutdown at a 'small-scale energy generator' in the UK as retaliation for the country allowing US airplanes to strike the country from British bases. Whilst NCSC-UK has not received any reported outages from regulated operators of power stations, it's a reminder of the need for the energy sector to adequately secure power generation. Politicians have described the incident as a "new kind of warfare" with plans to focus on energy security published in the Energy Sector Cyber Security Strategy just 3 months ago. Review the UK Government approach at https://lnkd.in/eT48trXP

    • No alternative text description for this image
  • "recent events in NZ would suggest that one sector which is well and truly facing some cyber security challenges, is the health sector" Privacy Commissioner Michael Webster, March 2026 New Zealand's health sector has suffered multiple adverse security incidents in the last five years - the 2021 Waikato DHB ransomware attack kicked off local concerns and recent events at MediMap and Manage My Health have led to new action. The National Cyber Security Centre's Minimum Cyber Security Standards (MCSS) are now being promoted as a baseline standard to measure where security gaps exist in health providers aiming to meet NCSC-MCSS CMM2. Read our latest blog to learn about the new Health NZ approach and how the Overcyte platform can support your assurance activities: https://lnkd.in/e8q-WDVM

    • No alternative text description for this image
  • "You can’t offer a bribe to a bot, so there is less chance of corruption.” Recent events in Australia and New Zealand have demonstrated how critical infrastructure organisations face attacks from a broad spectrum of threat actors. NZ's Security Intelligence Service have published their latest threat assessment and named China as doing espionage "at scale." Meanwhile, in Australia, a security breach at Origin Energy has been linked to an offshore employee who stole customer data to try and extort the power company for profit. The solution? AI and automation according to one commentator - remove the humans and you remove the risk. Read more in our latest blog: "A tale of two threats" at https://lnkd.in/eBQ3PdeX

    • No alternative text description for this image
  • View organization page for Overcyte

    447 followers

    "As an operator of essential services (OES) within the water sector, ACW has a responsibility to prevent any release of water that does not meet quality standards and to ensure the consistent provision of water in accordance with regulatory obligations" NCSC UK has now provided a worked example of the steps to implement the agency's 8 secure connectivity principles, the reasoning behind key decisions, and how the company addressed the differing needs of modern and legacy environments. Admin Corp Water (ACW) is a fictional regional water utility that treats and distributes potable water to millions of homes and businesses. It faces the challenge of balancing security and efficiency whilst meeting standards such as the UK Cyber Assessment Framework (CAF) and ISA/IEC 62443. Have a read of the approach at https://lnkd.in/eZbbzcmU

    • No alternative text description for this image
  • The 2023-2030 Australian Cyber Security Strategy set out a bold vision for protecting the country from digital threats. A seven year roadmap, six cyber shields and a commitment to invest more than half a billion dollars in protecting the country from digital threats. Three years on and Federal and State regulators continue to find significant cyber security failings in both private and public sector organisations. A recent NSW audit found that less than half of Government agencies complied with mandatory cyber security requirements. It seems that having a vision and achieving it, may take more money, time and effort than originally planned for. Have a read of our assessment in the latest Overcyte blog: https://lnkd.in/ea8vRWAZ

    • No alternative text description for this image
  • A new Presidential Memoranda has been issued by the Trump White House setting up a programme that would let private cybersecurity companies conduct government-authorised operations against foreign cybercriminal groups, including surveillance and disruption of their own infrastructure. There's concern about escalation of offensive activities by non-state actors, talk of 'cyber mercenaries' as proactive guns for hire, striking out at threat actors and putting them on the defensive. "Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs)" will be under the control and oversight of the Federal Government and will establish minimum standards that these companies must meet, including: - appropriate levels of technical proficiency - proven performance of cyber operations - facility security and personnel vetting And most importantly "competence and reliability." Just what we need more of in the cyber domain! Does this have echoes of the infamous Blackwater private security firm that made headlines during the Iraq war? Or is it time companies start actively 'hacking back' at attackers? Have a read of the Order at https://lnkd.in/eJ59TJZq and let us know what you think.

    • No alternative text description for this image
  • "The threat is geopolitical, while the defense is municipal. We are asking small towns - many with no dedicated cybersecurity staff members and little money to spare - to protect essential infrastructure against hackers linked to other nations." Jen Easterly, former director of the US Cybersecurity and Infrastructure Security Agency, provides analysis of recent Iranian attacks on American water companies and details how despite substantial investment, many operators lack the budget and skills to protect clean water supplies. The US must now "commit at least $3 billion in new multiyear funding... dedicated to replacing aging controls in water facilities and strengthening their ability to operate safely when digital systems fail." She states that many small firms still rely on aging equipment that was engineered to operate reliably for decades, long before system designers contemplated internet connectivity, ransomware or attacks by foreign intelligence services. An interesting read: https://lnkd.in/eEccZeuy

    • No alternative text description for this image
  • "the incident described in this report, which involved gaining access to an OT network through a private APN, was the first observed instance of this attack vector being used in a real‑world cyberattack" CERT Polska has released an updated report on the December 2025 cyberattack against Poland's energy sector - "the first in which the objective was purely destructive." A misconfiguration that allowed devices within the private APN network to communicate with one another has been found as the cause of a second, smaller CHP plant being impacted with the attack path shown in the image below. Read the full in depth report for the attack timeline and guidance on securing OT communications at https://lnkd.in/eBu6RzVN Recommendations include standard network hardening practices including monitoring and logging traffic between an OT network and a private APN and minimising ports and services exposed. Plus: 1. Auditing private APN configuration and enabling client isolation between end devices connected to the APN 2. Treat a private APN as an untrusted network with a trust level equivalent to that of the Internet 3. Strictly limit communications between the OT network and the device acting as the gateway to the private APN 4. Change default credentials for all services available 5. Include private APNs and the devices providing access to them within the scope of penetration tests Marcin Dudek's talk at DEFCON 34 will be available on YouTube soon: https://lnkd.in/dV_de9W

    • No alternative text description for this image
  • Are you working in securing transport systems? The NIST National Cybersecurity Center of Excellence has an upcoming webinar on using their Transit CSF Community Profile to strengthen cybersecurity preparedness and resilience against evolving threats. This 'tailored wrapper' over the standard CSF security controls provides a voluntary, risk-based resource for sector operators looking to protect complex digital services used for operating transport systems and securing payment mechanisms. An industry panel will share their insights on improving transport cybersecurity and the event is free to attend. Sign up now at https://lnkd.in/e_vpy_Ux

    • No alternative text description for this image

Similar pages