Guide

Cyber Security for Small Business in NZ

Practical cyber security steps for small NZ businesses—MFA, backups, phishing defence, device hygiene, and where to start without enterprise complexity.

Do the basics consistently before buying enterprise complexity

Small businesses do not need a miniature version of an enterprise security department. They need a handful of controls done every day: multi-factor authentication, backups that restore, current devices, sensible patching, and people who pause when a payment request changes. Those foundations prevent more real-world pain than a complicated platform nobody has time to operate.

Most attacks do not care how famous your business is

You do not need to follow every headline. You do need a plan for the patterns that repeatedly hit SMEs:

  • Phishing and business email compromise
  • Ransomware and destructive malware
  • Stolen or reused passwords
  • Lost or unpatched laptops
  • Unsafe sharing of client or staff data

Build protection in a sensible order

If security has been ad hoc, implement in this order:

  • MFA on email and admin accounts
  • Known-good backups with a restore test
  • Turn off or replace unsupported operating systems
  • Endpoint protection and patching rhythm
  • Short staff guidance on phishing and payment changes

Insurance helps after the event; controls reduce the event

Cyber insurance can help with response costs, but insurers increasingly expect MFA, backups, and basic hygiene. Policies also have exclusions. Treat insurance as a backstop, not the plan.

Bring in help when ownership is the missing control

Get external help if you lack time to maintain controls, you handle sensitive client data, you have multiple sites, or you have already had a scare. A preliminary IT Health Check can highlight gaps; incident response support matters if you suspect an active breach.

Make security part of normal IT work

We embed security into managed IT—identity, endpoints, backups, Microsoft 365 hygiene, and vulnerability awareness—then escalate to focused projects when hardening or incident work needs a deeper push.

Frequently asked questions

Is cyber insurance enough?

No. Insurance can help financially after an event, but strong controls are essential to reduce the chance and blast radius of incidents—and to meet many policy expectations.

We are too small to be targeted. Are we still at risk?

Most SME incidents are opportunistic, not personal. Automated attacks and invoice fraud do not require you to be famous.

What is the first thing to do after a suspected breach?

Isolate affected systems if safe to do so, reset critical passwords from a clean device, preserve evidence where possible, and contact your IT provider or incident response support quickly. Do not quietly reboot everything and hope.

How often should we review security?

Review after major staff or system changes, and at least annually. Monitoring and patching should be continuous, not annual-only.