PrivSec Consulting
  • Home
  • About
  • Services
    • Governance, Risk & Compliance
    • Penetration Testing >
      • AI Security
    • Configuration Reviews
    • Code Review
    • Privacy
    • Security Resilience Improvement Exercises
    • Security Awareness and Training
    • Alignment and Uplift Activities >
      • PCI DSS
    • Consultancy and Advice
  • Releases
  • Contact

About us

Established in 2021, PrivSec Consulting is committed to helping organisations do what they do best in the most secure manner possible. PrivSec aim to provide concise, accurate, and right-sized cyber security and privacy advice to your organisation.

Who are We?

We differentiate ourselves from the pack by our focus on working with you to meet your needs and ensuring our services are tailored to deliver the right security outcome for your business.

Our consultants hold qualifications such as CISSP, CCSP, CISA, CISM, CRISC, CCSK, PCIP, OSWE, OSEP, CA and OSCP.

PrivSec Consulting are Approved Suppliers within the AoG Consultancy and Professional Services Marketplace panel for the for the following services:
  •  Information Security Risk Management and Assessment
  • Information Security Governance and Strategy
  • Information Security Assurance
  • Source Code, Application Review and Technical Testing

Our Principles

We are here to help you. Our key principles include:
  • Pragmatism - If there is an easier way to get to an outcome we will suggest that.
  • Simplicity - We want you to understand the work we are doing. We keep away from technical jargon in our deliverables when it doesn't need to be there, to make your life easier.
  • Honesty - We call a spade a spade. If there are issues you need to be aware of, we will highlight these to you as soon as possible.
  • Being the Experts - We are easily approachable, eager to share knowledge, and up skill regularly to ensure we are at the forefront of our field.

Our Team



Picture

Peter Jakowetz
Managing Director and Principal Consultant

With experience in risk, audit, privacy and technical testing, Peter brings professionalism and pragmatism to all engagements, with an in depth technical knowledge. Peter demonstrates experience in a wide range of technologies and systems and has worked in both government and commercial organisations through New Zealand in a range of roles.
Before starting a new adventure with PrivSec, he was involved in building and managing a security function within a large NZ Government agency. Prior to this he worked as a principal security consultant providing assistance to a large number of Government agencies and private organisations.
During this time he had a particular focus on assisting organisations to meet All of Government security requirements for services including IaaS and TaaS.
He has also held roles as a penetration tester and security architect, rounding out his skill set.
Picture

Julius Staufenberg
Senior Consultant

Julius has several years of industry experience, and has conducted a wide range of security and privacy engagements. He has a keen interest in technology, and enjoys the challenge of the fast-paced cyber security environment.

Julius has a particular interest in AI systems, especially in their security and privacy implications. 

Julius graduated with a BSc(Hons) in Computer Science, and holds numerous industry certifications including the Artificial Intelligence Governance Professional (AIGP) and several cloud certifications. He has also passed the respective Certified Information Systems Security Professional (CISSP) and Certified Information Systems Auditor (CISA) exams.
In his spare time, he enjoys getting out into the outdoors, keeping fit, and learning new skills.
Picture

Bo Wood
Consultant

Bo is a Penetration Tester at PrivSec Consulting. Bo has 2 years of experience working within security consultancies, strengthening their technical skillset through intern roles. On top of upskilling in these roles, they have worked on small development projects such as a Proof-of-Concept Windows ransomware in Rust. Bo enjoys tackling the challenges that come along with Penetration Testing and is interested in learning more about the field of offensive security, as well as gaining more industry experience. In their spare time, Bo likes to play Tabletop RPGs like Pathfinder and narrative video games.
Picture
Jack Moran
Senior Consultant

Jack is a offensive security consultant, with a background in a wide array of offerings aimed at identifying and exploiting vulnerabilities. These include penetration testing (internal and external assets), security configuration reviews, and code reviews. 

Jack is also an avid member of the security community, volunteering his time across well known security events. His contributions include organising Hack The Box NZ meetups, and speaking and volunteering at conferences like New Zealand Internet Task Force (NZITF) and Christchurch Hacker Conference
Picture

Dom Rapp
Senior Consultant 

Dom Rapp is a Senior Security Consultant in the Technical Testing team at PrivSec Consulting.

Dom has a diverse and extensive background in the tech industry, with experience spanning both private and public sectors. He has held a wide range of roles, from highly technical positions to management. Before his time at PrivSec, he has run security teams at a global SaaS company, led the penetration testing division of a leading security consultancy and guided the development of a large SaaS company as a security architect.

Dom's experience bridges the gap between technical and non-technical audiences, which has given him a people-centric approach, ensuring that key context is always kept front of mind and voices from all contributors are included, ensuring that security improvements provide the most impact possible.
Picture

Yannick Devos
Principal Consultant & Practice Lead

While his academic background was initially in telecommunications, Yannick quickly shifted to network security and then information security, being part of the core team at the first information security dedicated consultancy in France in 2002. Over the last seven years, Yannick held a variety of roles in New Zealand Government agencies and security consultancies, focusing on risk management, assurance and security governance. His most recent position in the Government Chief Digital Officer’s security team allowed him to demonstrate a delivery mindset, ensuring the right outcomes for customers were delivered while respecting the service provider’s constraints. His key achievements being the successful implementation of security assurance processes over the Marketplace and annual audit assurance for TaaS suppliers.
When he wants to reset and refocus, Yan is either transmitting morse code with his HAM radio peers over the world, or enjoying shifting winds and tight lies on a golf course around Wellington.
Picture

Aaron Sanson
Principal Consultant

Aaron Sanson is a Principal Consultant at PrivSec Consulting. His is an experienced and passionate security practitioner with 30 years of experience in the IT security industry.
Aaron has provided services to a range of NZ organisations in his previous roles through the private and public sector, with a strong understanding of the security requirements in both of these domains.
He likes to understand the underlying issues and requirements of clients and offer pragmatic, fit for purpose, security advice. His approach is to work to identify alternative and pragmatic solutions when confronted with issues or problems.
Picture

Sriram Jayaraman
Consultant

Sriram is an offensive security consultant with experience in performing penetration testing and security reviews for a wide range of NZ businesses in both public and private sectors. He is an avid learner and enjoys the satisfaction of finding a good bug while helping clients achieve better security outcomes. Prior to his security journey, he had been a web application developer providing him with a solid understanding of best practices from the other side of the fence. Sriram holds a Master's degree in Cyber Security and is currently pursuing his OSCP. Outside of work, Sriram is always down for a game of football. He also likes being active whether it be a walk, a run or a session at the gym.
Picture

Tom Williams
Operations Manager

Tom joins PrivSec Consulting after 15 years in the hospitality industry, across a range of roles including project management, business optimisation, people management, and IT. Tom enjoys broadening his knowledge, especially by getting to see "behind the scenes" and is excited by the opportunity to gain deeper understanding of the world through working in Cyber Security and its related fields.
Outside of work Tom enjoys music, gardening, games, and travel
Picture

Richard Whiteside
Senior Consultant

Richard is a Senior Consultant with ten years of experience in the information security and privacy sector, primarily in risk assessment and management, compliance, audits, and strategy.

He enjoys collaboration within teams and with external stakeholders, and his experience as both an external security consultant and a security leader within an organisation has given him valuable insight on how the two perspectives can best work together.

In his spare time, Richard is keen to learn new skills and experiment with new technology, including home automation.
Picture

Matt Dekker
Principal Consultant & Technical Testing Lead

Matt is a security consultant with a background in penetration testing, code review, host and configuration reviews. Prior to his time working as a consultant he worked as a software developer which has shaped his focus on application and mobile security. Matt has a Masters in Cyber Security, and also holds OSCP, OSEP and OSWE certifications.

Picture

Kent Wolstenholme
Senior Consultant

After completing two years at Victoria University working towards his BE in Cyber Security, Kent has joined the team to gain some real-world work experience. He is passionate about the industry and is looking forward to new experiences. By thinking out of the box, Kent has proven to be a real asset in all the engagements he has been involved in.
Outside of work, he spends his time building, tuning and racing cars and motorcycles.
Picture

Jake Dalton
Associate Consultant

Jake is an Associate Consultant at PrivSec Consulting. He is currently working towards a BE in Software Engineering at the University of Canterbury, specialising in Cyber Security. Jake loves to solve puzzles and to understand how things work, so he is in his element when hunting through a client's application for vulnerabilities. In his free time, he loves hiking out to the high places of New Zealand.
Picture

Nina Pugh
Admin Assistant

Nina is the administrative assistant at PrivSec consulting. She works with people across the team to help with office management and operations. Within this capacity Nina helps provide a backbone of organisation and support for everyone at PrivSec. In turn, Nina has found this position to be a great way to expand her knowledge base in various fields of operation. Outside of work Nina enjoys the Wellington arts and cultural scene and getting outdoors whenever the sun is shining.
Picture

Quinn Simmons
Consultant

Graduating with a BSc in Computer Science with a specialisation in Cyber Security, Quinn has taken his passion for the industry into the role of Associate Consultant at PrivSec. His interest in technology and passion for problem solving has led him to pursue a career in Cyber Security, where he is looking to apply his skills and grow professionally. Outside of work, Quinn enjoys trips around Aotearoa with friends and spending rare sunny afternoons on the golf course.
Picture

David Watson
Consultant

David is a consultant in the GRC team at PrivSec Consulting. He holds a Bachelors degree in Accounting and Information Systems.

With over three years experience in both the Public and Private sector, he brings a range of skills and expertise to the role and looks forward to supporting our clients in their security journeys.

David's interest in security stems from building PC's in his spare time, and a desire to understand how complex technology works. Outside of work David enjoys skiing, four-wheel-driving and board games.

Picture

Aum Patel
Associate Consultant

Aum is currently working towards a Bachelor of Engineering in Cybersecurity at Victoria University of Wellington and has joined the team to apply his knowledge to real-word scenarios.

He is a driven, perpetual learner and combined with his passion for security and technology, wants to contribute to the GRC team to keep organisations safe.

Outside of work, Aum enjoys playing card games, and the rare ski days New Zealand has to offer.

Sponsorships and Events

PrivSec proudly support a number of security events throughout New Zealand. We have recently sponsored:
  • Christchurch Hacker Conference 2023/ 2024/ 2025
  • Kawaiicon 2022/ 2025
  • New Zealand Tech Rally 2025/ 2026
  • Code Camp Wellington 2024
  • ISANZ 2023/ 2024/ 2025
  • Canterbury Hacker Camp
We welcome expressions of interest from organisers of security events that aim to uplift New Zealand’s maturity in privacy and cyber security.

We have recently exhibited at the following events:
  • Lawfest 2024/2025
  • Canterbury Tech 2024/2025

Advisories and Presentations

Advisories:
  • Unquoted Service Path Disclosure - OpenSSH Portable versions 9.1.0.0v - 9.4.0.0
Recent Articles:
  • The Ease of Deepfakes in 2025
  • Artificial Intelligence In New Zealand's Public Sector
  • Digital Identity in New Zealand: What You Need to Know
  • Supply Chain Security
  • Vroom vroom... Security
  • How to Create a WPA2 Enterprise PEAP-MSCHAPv2 Home Lab
  • PCI DSS 4.0 & Penetration Testing
  • Security Considerations of AI
Presentations we've done:
  • OWASP Day 2025 - Computer Says No - Peter Jakowetz
  • Project Wednesday - Authentication Principles and Practices - Julius Staufenberg
  • Christchurch Hacker Conference 2024 - NTLM the last ride - Jim Rush & Tomais Williamson
  • ISACA Wellington Education Day 2024 - Eating your own dogfood - Peter Jakowetz
  • DEFCON 2024 - NTLM the last ride - Jim Rush & Tomais Williamson
  • OWASP Day 2024 - Keeping the Bank Happy - Peter Jakowetz
  • OWASP Day 2024 - SSRF and You - Jim Rush
  • A Hacker's View of Privacy Breaches - Jim Rush
  • Code Camp Wellington 2024 - Collaboration not Confrontation - Peter Jakowetz
  • Code Camp Wellignton 2024 - The OWASP Top Ten - A crash course for developers - Jim Rush
  • OWASP Day 2023 - What Happens When a Meteor Takes Out My Data Centre - Peter Jakowetz
  • CHCon NZ 2021 - Homebrew Hacking - Peter Jakowetz
  • OWAP Day 2020 - PCI-DSS-WTF - Peter Jakowetz
  • CHCon NZ 2019 - Deleted Memories - Peter Jakowetz
  • OWASP Day 2019 - That Vulnerability Looks Quite Risky - Peter Jakowetz
  • BSidesWLG 2017 - The Internet of Pancakes - Peter Jakowetz
  • CHCon NZ 2017 - The Internet of Pancakes - Peter Jakowetz


Picture
PrivSec are proudly a New Zealand owned and operated organisation, supporting other organisations around New Zealand and Globally. 

Want to know more? Contact us now.

[email protected] | 0800 150 805
  • Home
  • About
  • Services
    • Governance, Risk & Compliance
    • Penetration Testing >
      • AI Security
    • Configuration Reviews
    • Code Review
    • Privacy
    • Security Resilience Improvement Exercises
    • Security Awareness and Training
    • Alignment and Uplift Activities >
      • PCI DSS
    • Consultancy and Advice
  • Releases
  • Contact