Gisborne businesses face a national threat with regional consequences
The five risks Gisborne businesses should address first are phishing and payment fraud, weak identity controls, unsupported or unpatched systems, ransomware without tested recovery, and unmanaged supplier or remote access. These are not unique to Gisborne, and there is no basis for claiming the region is attacked more often. The local consequence can still be sharper when a seasonal operation, rural site, small internal team, or specialist system has few immediate alternatives. The NCSC reported that 53% of New Zealand SMEs surveyed had experienced a cyber threat in the first half of 2025. The useful response is to make a small number of controls routine and owned.
1. Phishing and business-email compromise
A convincing supplier invoice, payment-change request, Microsoft sign-in page, courier notice, or helpdesk call can bypass expensive technology by persuading a person to approve the action. Phishing and credential harvesting remain among the most commonly reported incident types in New Zealand. Practical control: require an independent check using a known phone number before changing bank details, releasing an unusual payment, or resetting sensitive access. Support that with safer email controls, MFA, and a simple way for staff to report uncertainty.
- Self-check: would accounts verify new bank details outside the email thread?
- Self-check: can staff report a suspicious message without fear of blame?
- Self-check: does the helpdesk verify identity before resetting MFA?
2. Weak identity and administrator controls
A reused password, legacy account, excessive administrator role, or poorly handled phone change can open email, files, finance applications, and customer data at once. MFA reduces risk, but the enrolment, recovery, and emergency-access processes matter as much as the licence. Practical control: enforce MFA, remove daily-use administrator accounts, review privileged access, and document a verified recovery path that does not depend on one person's phone or memory.
- Self-check: are all remote and cloud accounts protected by MFA?
- Self-check: who can approve applications or create new administrators?
- Self-check: can access be removed promptly when somebody leaves?
3. Unsupported and unpatched systems
Old laptops, forgotten servers, internet-facing firewalls, remote-access tools, and specialist applications often remain because replacing them feels disruptive. The risk is not simply age: it is a known weakness with no supported fix, no monitoring, or no owner. Practical control: maintain an asset list, automate operating-system and application patching, scan for meaningful vulnerabilities, and record an upgrade or isolation decision for anything that cannot be brought current.
- Self-check: can you list every internet-facing service and its owner?
- Self-check: which devices have missed patches in the last 30 days?
- Self-check: what is the plan for the oldest business-critical system?
4. Ransomware without tested recovery
Ransomware can encrypt systems, steal data, interrupt production, and target the backups needed for recovery. The NCSC describes it as one of the most damaging criminal attack types and recorded an increase in reported ransomware during 2024/25. A successful backup job is not proof that the business can recover. Practical control: keep protected backup copies outside the normal administrative path, define recovery order and time objectives, and test a restore far enough to prove the application and people can use the recovered data.
- Self-check: can an ordinary administrator delete every backup copy?
- Self-check: when was the last documented restore test?
- Self-check: which system must return first to restart revenue or production?
5. Supplier, contractor, and remote-access exposure
Regional businesses often depend on software vendors, accountants, machinery specialists, web providers, seasonal staff, and contractors who need some form of access. A permanent shared login or unattended remote tool can quietly become a route around stronger internal controls. Practical control: give each supplier named, least-privilege access with MFA, approval, logging, and an expiry or review date. Keep a register of remote tools and remove access when the work ends.
- Self-check: which third parties can access systems today?
- Self-check: is their access named, logged, and restricted to what they need?
- Self-check: who reviews or removes it after the project or season?
Regional operating conditions change the impact, not the attacker
An automated phishing campaign does not care whether the recipient is in Gisborne or Auckland. What changes is the business context around the incident. A horticulture or production system may be busiest during a narrow seasonal window. A rural site may have limited connectivity and no spare device nearby. A small finance team may have one person who understands a payment run. A specialist application may depend on a vendor outside the region. Build the response around those constraints. Identify the dates and processes where downtime is most damaging, keep secure replacement devices and account-recovery options available, and agree how external specialists will be contacted if ordinary communications are impaired. Cyber resilience and regional business continuity belong in the same conversation because recovery still depends on power, communications, people, and physical access.
- Record seasonal periods when change or downtime carries extra risk
- Identify roles with no immediate backup person
- Keep secure alternatives for critical devices and authentication
- Include connectivity loss in cyber incident and recovery exercises
Turn the five risks into a 90-day sequence
In the first 30 days, verify MFA, administrator access, backup coverage, and payment-change procedures. In the next 30, bring patching and asset records under control and test a restore. By day 90, review supplier access, run a realistic incident exercise, and assign owners for the work that repeats. Put each recurring task on a calendar with a named owner and evidence of completion. Review privileged access and leavers monthly, patch status and security alerts continuously, restores on a risk-based schedule, and the wider incident plan at least annually or after a material change. A control with no owner will eventually become an assumption. The aim is not perfect security. It is fewer easy paths in, faster detection, and a recovery plan the team can execute without improvising under pressure.
Frequently asked questions
Are Gisborne businesses targeted more often than other NZ businesses?
We do not claim that. The evidence describes New Zealand-wide risks. This guide applies those patterns to the operating realities of Gisborne businesses without inventing a local attack-rate comparison.
What is the first cyber-security control a small business should implement?
Start with MFA on email, remote access, finance, and administrator accounts, then verify backups and payment-change procedures. Those controls address several common and costly paths at once.
Is antivirus enough for a business laptop?
No. Devices also need current software, monitoring, secure configuration, controlled administrator access, recovery, and a response path when protection raises an alert.
How often should we test a backup restore?
Use a schedule tied to the importance and rate of change of the system, and test again after major changes. The test should prove the recovered application or data is usable, not only that a file can be downloaded.
Should suppliers share one remote-access account?
No. Give each person named access with MFA, least privilege, logging, approval, and a review or expiry date. Shared accounts make accountability and safe removal much harder.
Can Tier1 assess our current cyber-security position?
Yes. Start with the IT Health Check or a focused review of identity, email, devices, patching, backups, supplier access, and incident readiness.