Independent expert commentary on PCI, ISO, SOC and AI governance
Cianaa is an independent cybersecurity certification and assessment body headquartered in Auckland, working across New Zealand, Australia, Asia Pacific, Europe, the United States and Canada. Our assessors give journalists clear, credible, conflict-free commentary, backed by original published research.
Dr Rizwan Ahmad
PhD-credentialed founder of Cianaa Technologies. PCI Qualified Security Assessor (QSA) and PCI 3DS Assessor, ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor. Led the audit behind New Zealand’s first ISO/IEC 42001 certification. Available for interview or written comment, including on deadline.
What our assessors can speak to
Practitioner commentary from people who perform these assessments, not vendors selling a product.
Payment security and card fraud
PCI DSS v4.0.1, QSA assessments, card-not-present fraud, client-side skimming and payment-page security. We are a practising QSA firm.
ISO certification and SOC 2
ISO/IEC 27001, ISO/IEC 27701 and SOC 2. What certification actually proves, how assessments work, and where organisations go wrong.
AI governance and ISO 42001
AI management systems, responsible AI, the EU AI Act and emerging regulation. We audited New Zealand’s first ISO/IEC 42001 certification.
Data protection and privacy
GDPR, Japan’s APPI, the NZ Privacy Act and cross-border transfer. Published cross-framework research on privacy alignment.
Threat landscape and AI risk
AI-enabled phishing, social engineering, digital forensics and the shifting economics of cybercrime, grounded in our own research.
The ANZ regulatory landscape
Cyber assurance across New Zealand and Australia, including submissions to government consultation on critical infrastructure reform.
Recognition and milestones
Independent markers of our work that journalists are welcome to reference and verify.
★ New Zealand’s first ISO/IEC 42001 certification
Cianaa’s auditors conducted the certification audit for Datacom’s Datascape, the first New Zealand-based recipient of ISO/IEC 42001:2023 for AI management systems. Read the announcement →
MSECB Auditor of the Year 2024, Asia-Pacific
Awarded to Dr Rizwan Ahmad, founder and principal assessor at Cianaa Technologies.
Listed on Mastercard’s global SDP compliance list
Cianaa is named as a QSA assessor on Mastercard’s Site Data Protection compliance listing.
New Zealand Government independent evaluator
Listed as an independent Security and Privacy evaluator under the Digital Identity Services Trust Framework.
PCI QSA since 2014, and PCI 3DS Assessor
Registered with the PCI Security Standards Council and listed on the Council’s official register, licensed across Asia-Pacific, Europe and Canada.
Open-access research with DOIs
Nine peer-citable research papers on AI governance, ISO/IEC 42001, payment fraud and cross-border privacy, free to cite. Browse the research →
Cianaa at a glance
About Cianaa · boilerplate for publication
Cianaa Technologies is an independent cybersecurity certification and assessment body headquartered in Auckland, working across New Zealand, Australia, Asia Pacific, Europe, the United States and Canada, with an Australian entity, Cianaa Assurance Pty Ltd. Cianaa provides PCI DSS QSA and PCI 3DS assessments, ISO/IEC 27001, 27701 and 42001 certification audits, SOC assessments and government-aligned assurance. A PCI Qualified Security Assessor Company since 2014, Cianaa combines academic depth with practical, conflict-free assurance for organisations that need trusted, independent verification.
Need a comment, data or an interview?
Journalists can reach our assessors directly. We aim to respond quickly, including on deadline, and we are happy to provide figures, background or a named quote.
Contact our team →