Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Separate background IP from project deliverables
- 2. Use the right ownership model for the deal
- 3. Get written IP assignments from founders, employees and contractors
- 4. Check licences before reusing tools or content
- 5. Protect confidential information separately from ownership
- 6. Register important brand assets early
- Common mistakes New Zealand cyber businesses make
FAQs
- Does a client automatically own a cybersecurity report it paid for?
- Do contractors automatically assign IP to the consultancy?
- Can we reuse parts of one client project for another client?
- Should a cybersecurity consultancy register a trade mark?
- What if a founder created the core tool before the company existed?
- Key Takeaways
Cybersecurity consultancies create valuable intellectual property every day, but many New Zealand businesses only realise there is an ownership problem once a client relationship sours, a contractor leaves, or a new product launch is on hold. Common mistakes include assuming the client automatically owns everything it paid for, reusing third party tools without checking licence terms, and letting staff or contractors build assessment templates and scripts without a clear assignment of rights.
For cyber businesses, this matters because your real value often sits in the material behind the service, not just the service itself. That can include methodologies, detection rules, scripts, reports, training materials, internal playbooks, software tools and brand assets. If ownership is unclear, you can end up unable to reuse your own work, unable to commercialise a product, or exposed to a claim that you copied someone else's material.
This guide explains how IP ownership works for New Zealand cybersecurity consultancies, when the issue usually comes up, what your contracts should say, and the practical steps to take before you sign a contract, hire a contractor, or invest in branding and product development.
Overview
IP ownership for a cybersecurity consultancy usually turns on who created the material, under what contract, and whether the parties agreed to assign, license or retain rights. In New Zealand, assumptions are risky because the default legal position may not match the commercial deal you thought you had.
- Identify what IP your consultancy creates, including reports, templates, scripts, software, playbooks, training content and branding.
- Separate your pre-existing materials from client-specific deliverables before you sign a contract.
- Use clear terms on ownership, licences, reuse rights, confidentiality and moral rights.
- Check whether employees, founders and contractors have properly assigned IP to the business.
- Review third party software, open source tools and threat intel sources for licence restrictions.
- Protect branding, domain names and product names early, especially before you invest in marketing.
What IP Ownership Cybersecurity Consultancies Means For New Zealand Businesses
For most New Zealand cyber consultancies, IP ownership is not just a legal technicality, it is a revenue and risk issue. If you cannot prove who owns your core materials, your margins, client relationships and future product plans can all be affected.
A cybersecurity consultancy may create several different types of intellectual property at once. A single engagement could involve a scoping document, a penetration testing methodology, bespoke scripts, a report format, training slides, remediation recommendations, a client portal and internal workflow tools. Each item may have a different ownership position depending on how it was developed and what your contract says.
What counts as IP in a cyber consultancy
Your IP is often broader than founders first expect. It commonly includes:
- Business name, logo, tagline and other brand assets.
- Website copy, diagrams, sales material and case study formats.
- Assessment frameworks, audit checklists and testing methodologies.
- Scripts, code libraries, automations and internal software tools.
- Threat models, risk matrices, templates and playbooks.
- Client reports, remediation plans and training content.
- Productised services, managed detection processes and SaaS style tools.
- Confidential know-how, pricing models and internal processes.
Some of these rights may be protected by copyright. Some may be confidential information or trade secrets. Your branding may be protectable through a trade mark registration. In practice, cyber businesses often rely on a mix of these protections rather than a single right.
Why the default position can surprise businesses
The main trap is assuming payment equals ownership. A client may pay for a penetration test, but that does not automatically mean it owns every underlying template, script or methodology your consultancy used to deliver the work.
The reverse mistake also happens. A consultancy may assume it owns everything because it created the deliverable, but the contract may say all work product is assigned to the client on creation or on payment. If the contract is broad enough, you may have accidentally signed away rights in reusable material you rely on across multiple engagements.
Another point founders often miss is that individuals do not always create IP for the company automatically. Work created by employees in the course of employment is generally treated differently from work created by independent contractors. If a freelance security engineer, virtual CISO consultant or software developer builds something important and your contractor agreement is silent, your company may not own it outright.
Why ownership matters commercially
Clear IP ownership supports how you price, scale and sell your services. It affects whether you can:
- Reuse methodologies and templates across clients.
- Turn consulting know-how into a subscription product or platform.
- License internal tools without asking past clients for consent.
- Sell the business or raise investment with a clean IP story.
- Defend claims that your reports or code copied third party material.
- Stop ex-team members from taking key materials to a competitor.
If your consultancy wants to move from pure services to mixed services and software, this becomes even more important. Investors, buyers and larger enterprise customers often ask who owns the platform, the codebase, the rulesets and the content. If the answer is messy, deals slow down.
When This Issue Comes Up
IP ownership questions usually surface at predictable moments, and the best time to resolve them is before you sign a contract or spend money building around an uncertain asset. Once a dispute starts, the commercial leverage tends to drop quickly.
When signing client contracts
This is the most common pressure point. Enterprise procurement teams often insert broad clauses saying the client owns all deliverables, all related materials and all intellectual property created in connection with the services.
That wording can be a problem if your service depends on pre-existing frameworks, report structures or software modules. If you accept the clause as drafted, you may lose rights you need for future work. A better structure often separates:
- Your pre-existing IP, which you keep.
- Client data and client confidential information, which remain the client's.
- Project-specific deliverables, which may be assigned or licensed depending on the deal.
- A licence back to you to use de-identified know-how, templates and general learnings.
When hiring contractors or specialist consultants
Cyber businesses often use contractors for incident response, cloud reviews, red teaming, software development and technical writing. This is where founders often get caught. A contractor may produce key material, invoice the company and move on, while the paperwork says nothing about ownership.
If that person later disputes your use of the material, or reuses it elsewhere, the business can be left arguing over rights after the fact. Contractor agreements should deal clearly with assignment, future assistance, confidentiality, use of third party materials and whether the contractor can reuse generic know-how.
When employees build tools internally
Internal side projects often become core products. A staff member might create a dashboard, script library or detection workflow to help with client delivery, then the business later wants to commercialise it.
That usually works better where employment contracts clearly address IP ownership, confidentiality and post-employment handling of company property. Without that, disputes can arise about whether the tool was built within the employee's role, on company time, using company resources, or as a personal side project.
When using third party software and open source components
Many cyber consultancies rely on scanning tools, SIEM connectors, open source libraries, public frameworks and threat intelligence feeds. The legal issue is not just whether you can use them, but how that use affects your ownership and licensing position.
For example, some third party tools may restrict commercial redistribution, modification or white labelling. Some open source licences may require source code disclosure in certain use cases. If you embed external components into a client-facing product without checking the licence, you can create a mismatch between what you promise clients and what you are actually allowed to provide.
When launching a branded product or managed service
Consultancies often evolve into managed security services or productised offerings. Before you register a domain or print packaging for a new tool, training package or managed platform, check whether the name is available and whether your business owns the underlying IP.
Brand disputes and ownership gaps often appear late, when money has already been spent on design, website build and customer acquisition. Early checks are usually cheaper than rebranding after launch.
Practical Steps And Common Mistakes
The practical answer is to map your IP, document ownership early and make your contracts match how your consultancy actually works. Most problems come from informal growth, reused templates and rushed procurement sign-off.
1. Separate background IP from project deliverables
Your contracts should distinguish between material your consultancy already owned before the engagement and material created specifically for the client. That distinction protects your reusable know-how without stopping the client from getting what it paid for.
Background IP often includes:
- Testing methodologies and frameworks.
- Standard report formats and templates.
- Internal scripts and automations.
- Training content developed before the project.
- Pre-existing software modules and connectors.
Project deliverables might include the final report, a client-specific remediation roadmap, custom configuration documentation or a tailored workshop pack. Even then, the contract should state what rights the client receives and what rights your business keeps.
2. Use the right ownership model for the deal
Not every engagement needs a full assignment of IP. In many cyber consulting matters, a licence is commercially enough. The client needs to use the report and internal recommendations, but does not need to own your methodology, scripts or know-how.
Depending on the project, you may use one of these models:
- Your business owns the deliverables and gives the client a broad internal use licence.
- Your business assigns specific client-facing deliverables, but keeps all background IP and improvements.
- The client owns custom-built software developed solely for it, while your consultancy keeps generic modules, tools and knowledge.
- The parties share limited rights in defined materials, with strict confidentiality and field-of-use restrictions.
The right model depends on bargaining power, pricing and the nature of the work. A low-fee consulting engagement rarely supports handing over a consultancy's whole toolkit.
3. Get written IP assignments from founders, employees and contractors
If the company is the trading vehicle, the company should own the core IP. Founders sometimes forget this when they start a business in New Zealand and begin operating quickly through a newly incorporated company. Early materials may sit with an individual founder, a developer friend or a contractor who helped before proper paperwork was in place.
Here's what to sort out first:
- Founder assignment documents for pre-company or pre-contract work.
- Employment contracts with clear IP and confidentiality clauses.
- Contractor agreements with present assignment wording, not vague promises to transfer later.
- Procedures for collecting source files, repositories, working papers and passwords when someone leaves.
This is especially relevant where your business structure changed over time, such as moving from sole trader to company, or from one entity to a new operating company.
4. Check licences before reusing tools or content
Cyber consultancies often build quickly by adapting open source code, vendor templates or community materials. The common mistake is assuming that because something is publicly available, it can be repackaged into a paid service or proprietary platform.
Before you embed or reuse third party material, check:
- Whether commercial use is allowed.
- Whether modification is allowed.
- Whether attribution is required.
- Whether sublicensing or client distribution is restricted.
- Whether source code disclosure obligations may apply.
- Whether the terms conflict with your client contract.
Keep a basic register of key third party components and licence terms. It does not need to be fancy, but it should exist.
5. Protect confidential information separately from ownership
Not every valuable asset should be assigned or registered. Some of the most useful material in a cyber consultancy is confidential know-how, such as internal playbooks, detection logic, pricing methods, workflow documents and operational lessons.
Ownership helps, but confidentiality terms are what stop unauthorised use and disclosure. Make sure your client contracts, employment contracts and contractor agreements all deal with confidential information properly. Also think about practical controls, such as restricted access, internal policies and clean offboarding.
6. Register important brand assets early
Copyright may protect certain content automatically, but brand protection is different. If your consultancy is investing in a product name, platform name or service brand, a trade mark check should happen before you invest in branding, collateral and sales rollout.
That is particularly relevant if you are selling online or marketing nationally. A Companies Office registration does not give the same protection as a trade mark, and owning a domain name does not mean you own the brand legally.
Common mistakes New Zealand cyber businesses make
The recurring errors are usually commercial, not just legal. They often look like this:
- Signing a client MSA without carving out pre-existing IP.
- Letting contractors create code or templates before a contract is signed.
- Promising ownership rights to a client that third party licences do not allow.
- Failing to transfer founder-created materials into the company.
- Using old employment or contractor templates that do not cover cyber-specific work product.
- Assuming a business name registration or domain registration protects a product brand.
- Reusing client-specific confidential material in later engagements.
Privacy is another point to watch. Cyber consultancies often handle sensitive datasets, logs, user access information and incident details. IP ownership does not override privacy obligations or confidentiality commitments. If your services involve personal information, your documents and practices should also line up with the Privacy Act 2020, a privacy policy, and any client security requirements.
Marketing claims matter too. If you promote a proprietary platform, exclusive methodology or unique threat intelligence capability, those statements should be accurate. The Fair Trading Act 1986 can be relevant if advertising overstates what you own or what your service can do.
FAQs
Does a client automatically own a cybersecurity report it paid for?
Not necessarily. Ownership depends on the contract and the legal position applying to the work. Many clients at least need strong rights to use the report, but that does not always mean they own the underlying templates, methodology or supporting tools.
Do contractors automatically assign IP to the consultancy?
No. That assumption is risky. A written contractor agreement should clearly state what IP is assigned to the business, when the assignment takes effect, and what limited reuse rights, if any, the contractor keeps.
Can we reuse parts of one client project for another client?
Usually only if you have the contractual right to do so and you are not reusing client confidential information or personal information. Generic know-how, pre-existing templates and de-identified learning are often treated differently from client-specific deliverables.
Should a cybersecurity consultancy register a trade mark?
If you are investing in a consultancy name, product name or managed service brand, trade mark registration is often worth considering. It can be especially useful before you scale marketing, launch online, or expand into a productised service.
What if a founder created the core tool before the company existed?
The company should usually receive a formal assignment of that IP. This becomes important during investment, sale, procurement and internal ownership reviews, because buyers and clients usually expect the operating entity to own the key assets.
Key Takeaways
- IP ownership in a New Zealand cybersecurity consultancy should be documented, not assumed.
- Separate background IP, client data and project-specific deliverables in every client contract.
- Make sure founders, employees and contractors have properly assigned relevant IP to the business.
- Check third party and open source licence terms before embedding tools or content into client work or products.
- Use confidentiality clauses and practical controls to protect know-how that is not being registered or assigned.
- Consider trade mark protection before you invest in branding, register a domain or launch a new managed service or product.
- Keep privacy obligations, marketing accuracy and commercial reuse rights aligned with your IP position.
If your business is dealing with IP ownership cybersecurity consultancies and wants help with client contract terms, contractor IP assignments, trade mark protection, confidentiality clauses, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Protect your brand
Protecting the commercial value
If the name, logo or brand is central to the business, a trade mark strategy can reduce the risk of rebrands, disputes and copycats.







