SAARA NZ

SAARA NZ SAARA helps you get from where you are to where you need to be

ISO/IEC 27001:2022 isn't just a cyber checklist!It's an information security management system standard.That means it is...
04/09/2026

ISO/IEC 27001:2022 isn't just a cyber checklist!

It's an information security management system standard.

That means it is about how an organisation identifies risk, sets controls, manages responsibilities, reviews evidence and improves over time.

Technology matters, but it is only one part of the system.
Depending on the organisation’s scope and risk, people, policy, process, physical security and governance can all influence how information is protected.

This is why certification readiness should not be treated as a last-minute paperwork exercise.
The evidence needs to show that the system is defined, used and maintained.

SAARA supports organisations at the point where physical security, cyber security, governance and operational assurance need to work together.

Information security works best when it is managed as a system, not treated as a technical task list.

TEC has been direct about the 2027 funding environment: demand is expected to exceed available funding.The 2027 Plan Gui...
26/08/2026

TEC has been direct about the 2027 funding environment: demand is expected to exceed available funding.

The 2027 Plan Guidance, published by the Tertiary Education Commission in March 2026, states clearly that total funding is not expected to meet the increase in demand in 2027.

TEC has also signalled that it will actively reduce investment where outcomes are poor or where provision does not align with its priorities.

For organisations with TEC investment, this makes the Investment Plan submission more critical than usual.

A strong 2027 plan needs to show:
- Organisational capability to deliver on the Tertiary Education Strategy 2025–2030
- Evidence of your specific value in the tertiary network
- How you measure performance and how you will improve it
- A credible learner success approach integrated into your Strategic Intent
- Commitment to improving achievement outcomes and closing achievement gaps
TEC has also noted that micro-credentials should be funded from your existing allocation (they are not a route to additional investment).

The message is a practical one: providers that cannot demonstrate strong performance, clear strategic alignment and genuine learner success are at higher risk of reduced investment.

SAARA supports organisations to understand the TEC planning expectations and build Investment Plans that reflect both strategic intent and evidence of practical delivery.

If your current plan is due for review, the 2027 guidance is worth working through carefully.

Security should start with risk, not equipment.A new system might look impressive, but the first question should not be ...
18/08/2026

Security should start with risk, not equipment.

A new system might look impressive, but the first question should not be which product to buy.

The better question is what needs protecting, what could harm it and what level of control is proportionate.

Risk-based security helps teams make clearer decisions about access, surveillance, intrusion detection, procedures and response.

It also helps procurement teams avoid buying features that do not match the actual security need.
Installers play an important role in delivery.

Independent client-side advice helps keep the design aligned to risk, operational need and client requirements.

SAARA supports risk-based assessments, independent design and project oversight so security decisions stay aligned to client requirements.

Start with the risk, then choose the controls.

Security governance is a leadership responsibility.Protective security cannot sit only with the people managing doors, c...
11/08/2026

Security governance is a leadership responsibility.

Protective security cannot sit only with the people managing doors, cards, cameras or IT settings.

Good governance makes security visible.
It sets accountability, reporting lines, resourcing, decision-making and improvement priorities.

Without that structure, security activity can become reactive, fragmented or dependent on individual effort.

The practical questions are worth asking.

Who owns security risk?
Who reports on it?
Who checks whether controls are working?
Who decides what needs to improve next?

SAARA supports governance reviews, responsibility mapping, assurance reporting and practical security improvement planning.

When leadership can see the evidence, security becomes easier to manage.

Policy is not the same as practice.A policy shows intent, but assurance needs evidence that the process is owned, curren...
03/08/2026

Policy is not the same as practice.

A policy shows intent, but assurance needs evidence that the process is owned, current and actually used.
For PSR self-assessment, this distinction matters.

Teams should be able to show the documents that define the process, and the evidence that people are following it.

That might include ownership, review cycles, version history, records, checks, reporting and examples of the process in use.

The practical question is simple: does your evidence support the maturity level you are assessing?

SAARA can independently review evidence, assess whether it supports the self-assessment position and identify practical gaps before formal reporting.

Strong assurance is built on evidence of practice, not just evidence of paperwork.

Good people are not the same as mature systems.Many organisations have capable people doing good security work every day...
29/07/2026

Good people are not the same as mature systems.

Many organisations have capable people doing good security work every day.
The risk is that the process lives in their heads, not in the organisation.

The PSR Capability Maturity Model helps show the difference between informal practice and repeatable organisational capability.

Level 1 is Informal.
Level 2 is Planned and Tracked, and is described as the minimum PSR baseline.

That means security responsibilities, policies, processes and core protective measures should be defined, repeatable and able to be checked.

The goal is not to chase the highest maturity level for every situation.
The goal is to match maturity to the organisation’s risk.

SAARA supports organisations to move from informal practice to planned, tracked and evidence-supported protective security.
Security should not depend on one person remembering how things are done.

PSR is bigger than a government acronym.It's New Zealand’s protective security framework across governance, personnel, i...
20/07/2026

PSR is bigger than a government acronym.

It's New Zealand’s protective security framework across governance, personnel, information and physical security.

That means it is not just an IT issue, and it is not just about doors, cameras or visitor passes.

It asks a practical question: how does your organisation protect its people, information and assets in a joined-up way?

For mandated government organisations, PSR is a formal requirement.
For other organisations, it can also be a useful good-practice framework.

The value is in using it to understand risk, identify gaps and build stronger evidence of what is actually working.

SAARA supports organisations to assess current protective security practice, identify practical gaps and build evidence-led improvement plans.

Good security starts when governance, people, information and physical controls are working together.

Physical security isn't just hardware!Locks, cameras, gates and access cards matter, but they are only part of the pictu...
16/07/2026

Physical security isn't just hardware!

Locks, cameras, gates and access cards matter, but they are only part of the picture.

Physical security also includes procedures, site security plans, validation, maintenance and ongoing review.

It protects people, information and assets, and it connects closely with governance, personnel security and information security.

A control that is installed but not tested may create false confidence.
A procedure that is written but not used may leave a real gap.

The practical question is whether your physical security measures are designed, validated and kept up to date.

SAARA supports physical security audits, site security plans, system assurance and independent commissioning.

Physical security works best when the hardware, procedures and evidence all line up.

Under iQAF, your Quality Management System has to work every day.For many organisations, the QMS was built for periodic ...
13/07/2026

Under iQAF, your Quality Management System has to work every day.

For many organisations, the QMS was built for periodic review events. Under the new annual quality assurance cycle, it needs to support everyday practice.

The Quality Assurance of Tertiary Education Providers Rules 2026 require providers to:

• Maintain an up-to-date Quality Management System
• Complete an annual organisational self-review
• Submit a self-review summary to NZQA each year
• Participate in the annual NZQA discussion

A functional QMS is more than a set of documents. It should include:

• Policies and procedures that staff actively use
• Evidence from moderation and assessment throughout the year
• Current financial and operational oversight
• A live Quality Improvement Plan
• Integration of the Code of Practice self-review

This poses the question; Is your current QMS supportive of continuous quality improvement in practice?

SAARA supports providers to review, strengthen and operationalise their Quality Management Systems so they support real compliance, not just documentation.

Mānawatia a Matariki.Today is a time to pause, reflect and look ahead.Matariki invites us to remember those who have pas...
09/07/2026

Mānawatia a Matariki.

Today is a time to pause, reflect and look ahead.

Matariki invites us to remember those who have passed, give thanks for the present and prepare for the year ahead.

For SAARA, that message connects closely with the way we work.

Strong organisations are built through care, planning, trust and responsibility.

Whether supporting education, project delivery or security, we believe good outcomes start with people and clear purpose.

We wish our clients, partners, whānau and communities a meaningful Matariki.

May the year ahead bring clarity, connection and steady progress.

Address

(L10 Unit B) 43 High Street, City Centre
Auckland
1010

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

+6493020899

Alerts

Be the first to know and let us send you an email when SAARA NZ posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share