Services
Private AI AI Services Security Strategy
Company
Resources / Blog About Contact us
Cyber Security

Security that makes sense for your business.

Most organisations do not have a security problem. They have a decision problem. We find out where your real risks are, explain what they mean in plain language, and help you fix what actually matters.

  1. Perimeter
  2. Applications
  3. Identity
  4. Data
  5. Your people
A diagram of an organisation drawn as five nested layers named from the outside in: perimeter, applications, identity, data, and your people at the core. Threats arrive from outside and are held at each layer.

How we help

Five ways we strengthen your security.

Each service is designed to give your leadership team a clear picture and a practical path forward, without unnecessary spend or complexity.

M365 Health Check

Microsoft 365 is where most NZ organisations do their work and carry most of their risk. We review your configuration against best practice and tell you what to change, in order of priority.

Learn more →

Pen Testing

We attempt to breach your systems using the same methods real attackers use. You get a clear, plain-English report on what we found, what it means, and exactly how to fix it.

Learn more →

Security Assessments

A thorough review of your security posture against recognised frameworks. Where you stand today, where your gaps are, and a prioritised roadmap for closing them.

Learn more →

Cyber Security Training

Your people are both your biggest vulnerability and your strongest defence. We run phishing simulations and practical training that sticks, without making staff feel blamed or talked down to.

Learn more →

Why it matters now

The threat environment has changed. Most organisations have not caught up.

In 2022, the average time between an attacker gaining access and achieving full control was 8 hours. By 2025, that dropped to 22 seconds.

Smaller organisations are not safer because they are small. They are easier to attack because they typically have fewer controls and less capacity to respond. That makes them efficient targets.

The good news: the most effective defences are not expensive or complicated. They just require someone willing to ask the right questions before something goes wrong.

22s
Average time for an attacker to achieve full control once inside a system (2025)
35%
Of all breaches in 2024 originated through a third-party vendor or outsourced system
$5M+
Average cost of a third-party breach, higher than breaches caused internally

How we work

Plain speaking. Practical outcomes.

Every engagement follows the same approach, regardless of scope.

01

Understand your world

We start by understanding your business, not just your systems. What do you hold, who has access, what would hurt most if it failed.

02

Find the real risks

We look for the vulnerabilities that actually matter for your situation, not a generic checklist applied to every client.

03

Explain clearly

Every finding gets explained in plain language. No jargon. No fear-mongering. Just a clear picture of what is happening and why it matters.

04

Fix what matters

A prioritised list of what to do, in what order, with what outcome. We can help you implement it or hand it to your team.

Board Ready Cyber

The security conversation your board needs to have.

Most boards ask "are we secure?" and hear "yes." That is not good enough, and most boards know it. Board Ready Cyber gives your leadership team the evidence they need to answer that question properly.

Find out more
  • A clear view of your current security posture
  • Risks explained in language your board can act on
  • A prioritised plan for closing your most critical gaps
  • A written report your board can rely on
  • No jargon. No scaremongering. No unnecessary spend.

Our approach

Ethical. Pragmatic. No unnecessary complexity.

Security work carries a responsibility. We have access to sensitive systems, sensitive data, and sensitive findings. Everything we do is governed by a clear ethical framework: we report what we find, we protect what we access, and we never overstate a risk to justify a larger engagement.

We are also pragmatic. Many organisations spend money on security tools and frameworks they do not need, while leaving basic gaps unfixed. Our job is to tell you honestly what matters for your specific situation, not to recommend the most impressive-sounding solution.

Security does not have to be complicated. The organisations that are best protected are usually the ones that have done the basics well, consistently, over time.

Independently owned
No vendor commissions. No monitoring contracts. No incentive to recommend anything other than what is right for you.
Right-sized for your organisation
We do not apply enterprise frameworks to SMBs. The recommendation fits your actual risk profile, not a generic template.
People, not just systems
Your people are the main target and the main asset. Security that ignores the human factor is incomplete.

What our clients say

"Secure23 conducted Pen Tests and a Security Assessment on some of our most critical business systems. Their work helped us understand our security landscape and provided clear, understandable reports on areas we could improve."

Dan Wood, Chief Information Officer, NZ Police Association

"Horizons Regional Council engaged Secure23 for a simulated phishing test. They were reliable with delivery, managed to budget, and produced a quality output."

William Gordon, IT Team Leader, Horizons Regional Council

Not sure where to start?

A 30-minute conversation is usually enough to work out what you need. No commitment required.

Get in touch