Security advisory, Security by Design, governance, risk, and assurance for complex projects across New Zealand government environments. Delivered by senior security professionals to get it right the first time.
Working with
Many security issues arise not from a lack of controls, but from late involvement, fragmented delivery, and outputs that require rework. We address this directly.
We engage early in projects to influence architecture and delivery decisions — avoiding late-stage rework, redesign, and control gaps that arise when security is added after the fact.
All work is performed by experienced security professionals. There is no delegation to junior staff after scoping. The person you engage is the person doing the assessment.
Every finding traces to a risk, every risk to a recommendation, every recommendation to evidence. Outputs are structured so executives and technical reviewers can act on them without going back for clarification.
Result: Security is built correctly from the beginning, reducing rework, delivery risk, and costly remediation later. Outputs are complete and correct from the first delivery.
Structured security services for government agencies and regulated organisations operating under NZISM, NIST, ISO 27001, and agency-specific assurance requirements.
Risk assessments, threat modelling, remediation planning, and tracking — structured for decision-making and aligned to your framework obligations.
Security frameworks, policies, operating models, and maturity uplift. Designed for agencies building or improving their security posture at an organisational level.
Independent control validation, audit support, and evidence-based assurance reporting. From informal gap analysis through to full certification and accreditation.
Security assessment of AI systems and Large Language Model deployments against OWASP LLM Top 10. We help organisations understand their AI risk profile and governance gaps before systems reach production.
We offer two structured engagement models depending on your project type, duration, and internal capability needs.
For projects requiring high-level security expertise, where security and risk must be actively managed throughout delivery. Scoped, structured, and senior-led from the outset.
A dedicated senior security expert operating as part of your delivery team, while maintaining independent security accountability. Suited to complex or multi-phase programmes and ongoing advisory needs.
Commercial model — Flexible engagement structures available: Time & Materials, work packages with defined scope, or embedded advisory. Get in touch to discuss your requirements.
A structured, quality-gated process designed to minimise delivery risk and ensure outputs hold up under scrutiny from the first time they are reviewed.
Define scope, stakeholders, project boundaries, and acceptance criteria. Align on what good delivery looks like before work begins.
Run workshops, review artefacts, and perform evidence-based analysis. The same senior professional who scoped the work does the assessment.
Share draft outputs early for fast correction and stakeholder alignment. Issues are resolved before finalisation, not after.
Issue structured artefacts after quality review and client sign-off. Clear and complete for both executive and technical audiences.
AIS is the platform Andean Security Consulting uses for risk assessment, control validation, findings management, and accreditation documentation. It supports NZISM, NIST SP 800-53, ISO 27002, the Privacy Act IPPs, and custom control frameworks — all in one structured project record.
Built for the same regulated environments we work in. Available to other organisations that run formal security assessments.
Explore AIS ↗One project record. Every assurance output.
Andean Security Consulting is a specialist firm. We keep the team tight so the people doing the assessments are the people with the experience.
20+ years in information security, with deep specialisation in certification and accreditation, security risk assessment, and control validation for New Zealand government and regulated sectors. Sebastian leads all assessments and accreditation engagements at Andean Security Consulting, and is the principal architect of AIS.
Specialist Network
For engagements that require additional specialist depth, Andean draws on a curated pod of senior security practitioners who join the delivery team as needed. All work is carried out under principal oversight and subject to the same quality standards as any Andean engagement.
Tell us about your project or assessment requirements and we'll get back to you within one business day.