Corporate Security
Secure. Protect. Respond.
Your team’s devices are constantly transmitting data, even when turned off. Our Certified Military-grade Faraday products shield devices from all signals – keep confidential data, intellectual property, and travel activity secure.
The Threat Landscape
Firewalls, encryption, MDM.
Then the digital device leaves the office.
A boardroom meeting. A business trip. A staff breach and subsequent exit. There are various scenarios where digital devices pose corporate security risks in terms of data leaks or theft.
Phones, tablets and laptops are constantly transmitting signals, whether on or off, revealing locations, habits, and sensitive activity to outside systems outside of your control. Devices may be charged using public ports, or exposed to unknown WiFi networks.
Most cybersecurity tools focus on software (Firewalls, VPNs, and other MDM), but ignore the threats at the hardware level. Your devices are still vulnerable, and physical signal isolation is the only solution.
Boardroom & Meetings
Digital Devices in Meetings Create Two Problems
Digital devices in sensitive meetings pose serious data risks - corporate espionage, eavesdropping, unauthorized recordings, GPS tracking, and active remote hacking. Turned-off devices still transmit signals and are vulnerable. University of Florida researchers reconstructed a spoken conversation from behind a 25cm concrete wall by picking up electromagnetic leakage from a laptop microphone. Furthermore, device usage destroys participant focus. UC Irvine research puts the average focus recovery time after a single interruption at 23 minutes. Military-grade Faraday bags effectively mitigate these risks.
Focus recovery after a single interruption (Mark, UC Irvine). Speech recognition accuracy reconstructed through 25cm concrete from laptop microphone EM leakage. UC Irvine; Genkin, Bhupathiraju et al., USENIX Security 2025.
Executive Travel
Untrusted networks, untrusted ports, border security scanners
The devices your executives take on business trips are vulnerable to cyber criminals and unauthorised data extraction. The FBI and FCC have issued public warnings about juice jacking: compromised USB ports at airports, hotels and public places that extract data or push malware through the device charging cable. A USB data blocker or cable solves this risk. Devices that pass through airport scanners and other security checkpoints can be wirelessly interrogated. An "Evil Twin" WiFi can route everything to a rogue server. Your MDM is ineffective. A Military-grade Faraday bag will render your devices digitally invisible.
Travellers report being hacked while using public Wi-Fi abroad. Airports, hotels, and conference lounges are the highest-density attack environments. NordVPN travel cybersecurity research, 2025.
Incident Response
Compromised devices that keep transmitting
The National Cyber Security Centre recorded 5,995 incidents in 2024/25, with 331 classified as nationally significant. If one of those is yours, the Privacy Act 2020 gives you 72 hours to notify the Privacy Commissioner. The investigation cannot start until the compromised device is digitally contained. And you cannot contain a device that is still transmitting.
Incidents recorded by NCSC in 2024/25; OPC notification window for notifiable privacy breaches. NCSC Cyber Threat Report 2025; Privacy Act 2020.
Insider Risk
The departing-employee window
The average organisation loses USD 19.5 million a year to insider incidents across 13.5 separate events. Fortinet's 2025 survey found 77% of organisations faced insider-driven data loss in the past 18 months. In the case of a suspected data breach or a disgruntled employee leaves, there are risks that the employee may tamper with data on the company device. That device poses a data risk and also contains evidence of misdemeanour. Digitally securing the device is essential.
Annual insider-risk cost per organisation; share of organisations reporting insider-driven data loss in the past 18 months. Ponemon Institute Cost of Insider Risks 2025; Fortinet Insider Risk Report 2025.
Our Solutions
Five solution pathways, one for every scenario where security software fails.
Sensitive meetings, executive travel, data protection at the device layer, incident response, and investigation handling.
Boardroom Attention
Sensitive Meetings
Stop the phone ping, stop the data leak. Isolate devices during important meetings to prevent data compromise and eavesdropping. Prevent phones from disturbing the meeting.
Airport · Hotel · Lounge
Executive Travel
Public USB ports, unknown WiFi networks, airport scanners - your devices are exposed, and your MDM software cannot protect them. Hardware-level protection is essential.
USB · RFID · Card Skimming
Data Protection at the Device Layer
Juice jacking at public USB charging ports, contactless card and passport skimming, device signal interception. Threats your device firewall cannot prevent because these are not software but hardware threats.
72-Hour Duty
Incident Response
Isolate the compromised device. Preserve the chain of custody. Report incident within 72 hours without losing device evidence while the fraud investigation or forensic team assembles. Set up an internal forensic team to analyse devices in the case of employee fraud or misdemeanor.
Departing Employee · Insider Risk
Investigation Handling
Immediately recover the device to reduce the risk of data breaches and preserve the evidence. HR, legal, compliance, and IT all need the same controlled handover. One procurement workflow covers triage, isolation, and analysis.
Regulatory Context
Your legal duty is specific, documented, and regulated.
Corporate device security is no longer a best-practice conversation, it’s essential.
Privacy Act 2020
Notifiable breach duty to the Office of the Privacy Commissioner.
Notification Window
As soon as practicable, with OPC guidance of 72 hours from awareness of a notifiable breach.
Timing (2024/25)
OPC Annual Report records a 41% rise in serious privacy breach notifications year on year.
Physical Implication
You cannot investigate, contain, or document a breach on a device that keeps transmitting. Isolation is step one.
National Cyber Security Centre
Lead operational cyber security agency for Aotearoa New Zealand.
Incidents · 2024/25
5,995 incident reports · 1,521 from organisations · 331 of national significance.
Policy Horizon
Cyber Security Strategy 2025-2030 is now published. Action Plan 2026-2027 includes Ministry of Justice advice on a civil pecuniary penalty regime under the Privacy Act.
Physical Implication
If your incident response does not immediately isolate the compromised device within seconds of becoming aware of the incident, it fails the moment the incident becomes notifiable.
Intelligence and Security Act 2017
Classified contexts, defence, and Five Eyes-adjacent work.
Scope
The handling of classified material, protective security requirements, and cleared-personnel device controls.
Custodi Fit
NZDF-procured Mission Darkness portfolio, tested to IEEE 299-2006 and MIL-STD-188-125 for classified register environments.
Physical Implication
Where classified context applies, software controls alone are insufficient. Faraday isolation is the physical control.
Principle & Process
Signal blocking products are tools. Expertise in device security adds value.
In this modern technological world, incorporating hardware such as Faraday shielding technology as part of your business’s overall digital device security strategy is important. Faraday shielding technology strengthens a business’s overall security posture by acting as a physical backstop to digital security measures. Policies that outline why, when and how such hardware is used are essential to all businesses, large and small. Providing training to your employees to understand the risks of data and privacy breaches when using digital devices should be part of your overall security process.
Custodi offers Consultancy Services and training to assist with your business strategy and policies around digital device security.
Policy Review
We can assist with reviewing your policy around digital device security in relation to data and privacy threats and regulatory requirements. The starting point before any hardware requirements are assessed.
SOP Development
We can assist with recommendations for your standard operating procedures in relation to safeguarding data and privacy on digital devices under different scenarios, such as sensitive meetings, staff travel, how to handle employee incident responses.
Training
We can provide training in line with your SOP, for employees to understand how their digital devices can be compromised, how to mitigate the risks, and how to use the Faraday products.
Common Questions
Frequently Asked Questions.
Engagement, procurement, and operational questions corporate buyers tend to ask.
Our engagements start with a 30-minute scoping call to understand where your risks lie in relation to data and privacy breaches (such as meetings, staff travel exposure, incident response readiness, or insider-risk handling). We can then recommend what Faraday products you might need and whether a policy review is required.
Yes. We can assist with preparing your SOP, along with supplying Faraday hardware, and training. We make recommendations based on your operating context: meeting frequency, staff travel, incident reporting structure, and the policy framework your legal and compliance teams already use. Auditable, version-controlled, and reviewable when your situation changes.
To preserve the data and prevent remote tampering, the device must be isolated from all wireless signals as soon as possible, if not immediately. Therefore, having forensic-grade Faraday bags on site is essential. If you don’t have any, we ship by courier within New Zealand in 24-48 hours. Once the device is digitally isolated, your response team needs to understand the next steps: how to triage, how to preserve chain of custody for an OPC notification, how to coordinate the device handover between IT, legal, and the investigative/forensic teams. We offer advice during an active incident, or can assist with preparing your SOP for such incidences.
For companies with over 20 staff we usually run a phased deployment: SOP and Faraday travel gear specifications first, pilot with a small group, then full rollout with training for the entire group. The Faraday hardware budget is an important but small component. The procurement, training, and ongoing policy maintenance is where most of the value lies.
It depends on what is discussed in your boardroom. If your meetings discuss sensitive non-public information, regulatory discussions, M&A activity, classified material, or anything you would not want recorded by an attacker, then yes. The data leak threat is real: University of Florida researchers reconstructed spoken conversation through a 25cm concrete wall in 2025 using only electromagnetic leakage from a laptop microphone. You may have meetings where attendees may not want to be tracked to your location. Digital devices such as phones, tablets and laptops are trackable, regardless of whether they are turned off or the GPS location is diabled.
Secure. Protect. Respond.
If you do not have a digital device policy, you're not alone. We can provide advice based on your requirements and current procedures, and can make recommendations on the hardware you might need.
