Security & Intelligence — Papua New Guinea

See the threat
before it arrives.

Ruach Info-Sec delivers cyber security, threat intelligence, and protective services built for government, financial, and development sector clients operating across Papua New Guinea.

24 / 7
Monitoring & Incident Response
PNG-Based
Local Team, Regional Reach
Multi-Sector
Govt · Finance · Development · Resources
What We Do

Capabilities

Nine disciplines, one operating standard: understand the risk, close the gap, and stay watching.

01

Cyber Security & Managed SOC

Continuous monitoring, threat detection, and hardened infrastructure for networks that can't afford downtime.

02

Threat Intelligence & Risk Analysis

Contextual intelligence on the actors, methods, and vulnerabilities relevant to your sector and region.

03

Incident Response & Forensics

Rapid containment, root-cause investigation, and recovery support when an incident is already underway.

04

Governance, Risk & Compliance

Policy, audit, and compliance frameworks aligned to donor, regulatory, and industry requirements.

05

Physical & Protective Security

Site risk assessments, access control design, and protective advisory for facilities and personnel.

06

Security Awareness Training

Practical, role-based training that turns staff into the first line of defence, not the weakest link.

07

Penetration Testing

Authorized network, web application, and infrastructure penetration tests that surface exploitable gaps before an adversary does.

08

Database Development

Secure database design, performance tuning, backup/recovery hardening, and reporting pipelines built for reliability at scale.

09

ERP Advanced Setup & Configuration

End-to-end ERP implementation — business process mapping, module configuration, data migration, and integration with existing systems.

How We Engage

A four-stage approach

Every engagement follows the same sequence, from first assessment to sustained monitoring.

01

Assess

We audit your current security posture — systems, sites, and processes — to establish a clear risk baseline.

02

Design

We build a tailored security architecture and response plan matched to your sector, budget, and threat profile.

03

Deploy

We implement controls, harden systems, and stand up monitoring — with minimal disruption to operations.

04

Sustain

We monitor, respond, and review on an ongoing basis, so your posture improves as the threat landscape shifts.

Who We Serve

Sectors

Institutional clients whose operations can't tolerate an unmanaged security gap.

Government & Public Sector Financial Services Development & NGOs Mining & Resources Telecommunications Critical Infrastructure
About Ruach Info-Sec

Built on the ground, for the ground.

Ruach Info-Sec is a Papua New Guinea-based security and intelligence firm. We work alongside government agencies, financial institutions, and development organisations to close real gaps — not sell generic playbooks.

Our team combines technical security expertise with an understanding of the operating conditions unique to PNG: dispersed sites, variable connectivity, and a threat landscape that doesn't match a textbook. That's the gap we close.

01
Local Presence,
National Coverage
02
Cross-Sector
Experience
03
Assessment to
Sustained Monitoring
04
Plain-Language
Reporting
What We Offer

Explore Our Services & Solutions

Five integrated practice areas, delivered by one accountable team.

🔐

Cybersecurity Solutions

Managed SOC, threat intelligence, incident response, and penetration testing — internal, external, and web application — to find and close exploitable gaps before an attacker does.

💼

ERP Solutions

Microsoft Dynamics 365 Business Central implementation, advanced setup, database development, custom reporting, and Power Platform integration.

🌐

IT Infrastructure & Networks

Network design and hardening, cloud & hybrid infrastructure (AWS, Azure), structured cabling, and CCTV deployment for dispersed sites.

🎓

Training & Awareness

Role-based security awareness training that turns staff into a first line of defence, plus technical upskilling for internal IT teams.

🤝

Consulting & Support

ISO 27001 advisory, governance and risk consulting, vendor coordination, and ongoing managed support across every engagement.

How We're Organised

Technical Team Structure

A single line of accountability from executive oversight down to delivery — across every practice area.

Managing Director / Chief Technology Officer

Max Asher Puksy — Executive Sponsor & Senior Oversight
Core Delivery Team

Project Manager

Delivery Lead
  • Network & Infrastructure Engineers
  • Cloud & DevOps Engineers
  • CCTV & Structured Cabling Technicians
  • Schedule, budget & on-site delivery

Senior Technical Architect

Enterprise & Advisory
  • Enterprise Architecture Advisors
  • Software & Application Developers
  • Vendor & Stakeholder Coordinators
  • Solution design & technical assurance

ISO 27001 / Compliance Lead

Governance & Risk
  • Risk & Audit Consultants
  • Cybersecurity Analysts (SOC / CTI)
  • Policy & Governance Specialists
  • ISMS compliance & reporting
Specialist Technical Functions

ERP Solutions Lead

Advanced Setup & Configuration
  • Advanced ERP setup & configuration
  • Business process mapping
  • Module customization (Finance, Supply Chain, HR)
  • Data migration & system integration

Penetration Testing Lead

Offensive Security
  • Network & web application penetration testing
  • Vulnerability assessments
  • Red team exercises
  • Remediation planning & reporting

Database Development Lead

Data Engineering
  • Database design & architecture
  • Performance tuning & optimization
  • Backup, recovery & security hardening
  • Reporting & BI data pipelines
Accreditations

Certifications & Partnerships

Standards and platforms our team is certified to deliver against.

ISO/IEC 27001 ISMS logo ISO/IEC 27001 ISMS
CompTIA Security+ logo CompTIA Security+
Microsoft Azure DevOps logo Microsoft Azure DevOps
Dynamics 365 Business Central logo Dynamics 365 Business Central
Microsoft Power BI logo Microsoft Power BI
Microsoft Power Apps logo Microsoft Power Apps
Amazon Web Services logo Amazon Web Services

Risk Assessment Matrix

The likelihood / impact framework we use to score and prioritise findings across every engagement.

Negligible
Minor
Moderate
Major
Severe
Almost Certain
Medium
High
High
Severe
Severe
Likely
Low
Medium
High
High
Severe
Possible
Low
Medium
Medium
High
High
Unlikely
Low
Low
Medium
Medium
High
Rare
Low
Low
Low
Medium
Medium
ERP Solutions

ERP Advanced Setup Notes

Our Microsoft Dynamics 365 Business Central deployments follow a structured, auditable setup path — not a default install.

01

Company & Financial Setup

Chart of accounts, dimensions, number series, fiscal periods, currencies, and posting groups configured to match existing finance controls before go-live.

02

Data Migration & Validation

Legacy data extraction, cleansing, and staged import (customers, vendors, items, open transactions) with reconciliation against source systems.

03

Workflow & Approval Configuration

Purchase, sales, and approval workflows mapped to organisational sign-off levels, with role-based Business Central permission sets.

04

Integration & Extensions

Power Platform (Power BI, Power Apps, Power Automate) connections, third-party API integrations, and custom AL extensions where standard modules fall short.

05

Database Development

Custom table and field development, SQL-level performance tuning, report layouts, and secure data access design across the underlying Business Central database.

06

Training & Hypercare

Role-based user training, documented SOPs, and a post-go-live hypercare period to resolve issues before handover to steady-state support.

Get Started

Ready to strengthen your security posture?

Schedule a Consultation