About Secure23
I started Secure23 because I kept seeing the same problem: organisations spending money on security without understanding what they were actually protecting against, or why. The tools were there. The decisions were not.
My background spans technology leadership and delivery across the UK and New Zealand, including roles at Hitachi Europe, KPMG, and the UK Ministry of Defence, and engagements with organisations including ACC, AMP, and Morgan Stanley. That means I have seen security done well and done badly across some of the most complex and regulated environments in the world.
What I brought to Secure23 is what was missing from most of those experiences: a plain-speaking approach that treats security as a business problem, not a technical one. No jargon. No unnecessary spend. No scaremongering. Just a clear picture of where your risks are and what to do about them.
AI has changed the landscape significantly. The same approach applies: understand what you are actually trying to achieve, work out what the risks are, and make practical decisions based on your specific situation, not a generic framework.
Secure23 works with a network of specialist associates who bring additional depth when engagements require it. Every client relationship is managed directly by me.
Experience across some of the world's most demanding organisations
How we work
Every report, every briefing, every recommendation is written for the person making the decision, not the person reading technical documentation. If you need a glossary to understand our advice, we have not done our job.
We scope engagements clearly, deliver what we agreed, and tell you early if something changes. You will never receive an invoice that surprises you or a report that raises more questions than it answers.
We are not here to produce reports that sit in a drawer. Every engagement ends with a clear, prioritised list of actions. We can help you implement them or hand them to your team, whichever makes more sense.
We do not sell enterprise solutions to organisations that do not need them. The right answer for a 50-person NFP is different from the right answer for a law firm with 200 staff. We start with your situation.
Secure23 is independently owned. We are not tied to specific vendors or reseller arrangements that influence what we recommend. Our advice is based on what is right for your situation, nothing else.
Based on the Kapiti Coast and working across the Wellington region and beyond. We know the NZ regulatory environment, the organisations operating in it, and the specific challenges facing NZ SMBs and professional services firms.
The team
Our model
Secure23 operates as a lean consultancy. Tom leads every client engagement directly, supported by a network of specialist associates who bring additional depth in areas including penetration testing, AI architecture, and compliance frameworks.
This model means you get experienced, senior-level advice on every engagement, without the overhead of a large consultancy or the account management layers that often sit between you and the person actually doing the work.
Most engagements follow a fixed-price scoping model: a defined piece of work, a clear deliverable, and a known cost. No open-ended retainers or scope creep. If ongoing advisory makes sense after that, we can discuss it.
A 30-minute conversation is usually enough to find out. No commitment required.
Get in touch