Cyber security basics every New Zealand small business needs
Cyber security starts with protecting the systems that keep your business trading: email, banking, payroll, customer records and shared files. Common attacks exploit stolen passwords, unpatched software, excessive access or someone being persuaded to pay a fraudulent invoice. The basics below reduce those opportunities and limit the damage if something gets through.
Start with a one-page register of your important systems, who administers them and who to contact when something breaks. Include cloud services and personal devices used for work, not just office computers. Identify which services you could operate without for a day and which would stop trading immediately.
Assign one person in the business to own this register and review security evidence monthly. An IT provider can operate the controls, but a business decision maker still needs to confirm coverage, exceptions and unresolved risks.
1. Protect accounts and remove unnecessary access
Turn on multi-factor authentication (MFA) for email, remote access, accounting software and every administrator account. Prefer passkeys or hardware security keys where supported because they resist phishing better than codes. An authenticator app is generally preferable to SMS, but SMS is better than leaving an account protected only by a password.
Use a business password manager to create unique passwords and share credentials securely when named accounts are unavailable. Staff should have individual accounts, and administrators should use separate accounts for privileged work rather than reading everyday email with administrator rights.
Make access removal part of the leaving process. Disable the account, revoke active sessions, remove remote access and check any shared secrets the person knew. Review permissions when people change roles.
- Verify MFA enforcement in an administrator report. Enrolment alone does not prove every relevant sign-in requires it; check exceptions and legacy authentication methods.
- Review administrator accounts and external file-sharing access quarterly. Ask why each person needs that level of access.
- Keep emergency account recovery arrangements documented and securely stored. Test recovery without disabling protection across the business.
2. Keep devices supported, patched and monitored
Maintain an inventory of laptops, desktops, phones, servers, routers and firewalls. Record who uses each device, whether its software is supported and when it last checked in. Replace unsupported systems or isolate them while you complete a documented replacement plan.
Enable automatic operating system and application updates wherever practical. Include browsers, PDF tools, remote support software and internet-facing equipment. Critical vulnerabilities affecting exposed systems need urgent assessment rather than waiting for the next routine maintenance window.
Use centrally managed endpoint protection, ideally with endpoint detection and response, so suspicious activity is visible to someone who can act. Enable disk encryption and automatic screen locking on portable devices. Staff should not normally have local administrator rights.
- Check a management report for missing patches, failed updates, devices awaiting restart and security agents that have stopped reporting.
- Compare the report with your device register. A healthy dashboard is misleading if half the laptops are absent.
- Confirm encryption recovery keys are securely available to authorised staff. Use your security vendor’s approved test method to verify alert delivery without introducing real malware.
3. Secure email and verify payment changes outside email
Email security needs technical controls and a payment process that does not trust a convincing message. Configure spam and phishing protection, block unnecessary automatic forwarding to external addresses, and disable outdated sign-in methods where possible.
Have your IT provider configure SPF and DKIM for legitimate email services, then introduce DMARC enforcement after checking every authorised sender. These controls reduce impersonation using your domain; they do not stop lookalike domains or a criminal using a genuinely compromised supplier account.
Require staff to confirm new supplier bank details and payment changes using a phone number already held in your records, not one supplied in the change request. Apply the rule even when the message appears to come from the owner. Use separate payment approval where staffing allows.
Verify the process with a walkthrough: give accounts staff a fictional bank-detail change and ask what they would do. Ask your provider for DMARC reporting and an explanation of rejected or unauthorised senders. Show staff how to report suspicious messages without opening attachments or forwarding them widely.
4. Back up important data and prove you can restore it
Decide what you cannot afford to lose, including cloud email, shared documents, accounting data and specialist application records. Do not assume a cloud subscription includes the backup retention or recovery options your business needs. File synchronisation can copy deletions and encrypted files as readily as legitimate changes.
Keep a backup copy separated from normal user and administrator access. Depending on the platform, this may mean immutable storage, an offline copy or a separately secured backup service. Protect backup administration with MFA and avoid using the same privileged credentials as your production systems.
Set two business requirements: how much recent work you could lose, and how long you could wait to recover. These determine backup frequency and recovery arrangements.
- Review failed and missed backup jobs, not just successful ones. Confirm alerts reach a named person.
- Restore sample files regularly into a safe location and check that they open correctly.
- Periodically test recovery of a critical application or service, including permissions and dependencies. Record actual recovery time and fix anything that prevents meeting your target.
5. Make security alerts somebody’s job
Collect useful logs from email, identity services, endpoints, firewalls and backup systems. Prioritise actionable events such as unexpected administrator changes, suspicious sign-ins, new external forwarding rules and disabled security tools. Retain logs long enough to support investigation, with appropriate access restrictions.
Decide who reviews alerts, how quickly they should respond and who covers evenings, weekends and holidays. A notification sent to an unattended mailbox is not monitoring. For small teams, a managed security operations centre can provide coverage that is difficult to sustain internally.
Ask your provider to explain the distinction between its network operations centre, security operations centre and help desk. Infrastructure availability monitoring is not automatically security monitoring. CoreTech’s Auckland-based managed IT services include a 24/7 NOC, SOC and help desk; agree the systems covered and response authority explicitly.
Verify the arrangement through an agreed, harmless test alert. Confirm who received it, how it was escalated and whether the responder had permission to take the required action.
6. Prepare a short incident plan before you need it
Keep a one-page response plan available outside your normal email system. Include your IT provider, bank fraud team, cyber insurer if applicable, and the person authorised to make operational decisions. Identify who can isolate a device, disable an account or approve emergency recovery work.
If compromise is suspected, contact your responder promptly, preserve messages and logs, and avoid wiping devices before advice is obtained. For suspected payment fraud, call your bank immediately using a trusted number. Report cyber incidents to the National Cyber Security Centre through its official reporting channel.
Assess whether personal information is involved. Under New Zealand’s Privacy Act 2020, breaches that have caused, or are likely to cause, serious harm generally require notification to the Privacy Commissioner and affected people as soon as practicable.
Run a short exercise twice a year: assume email is unavailable or a laptop is encrypting files. Check that contacts work, decisions have owners and backups can support recovery. Finish each monthly security review with unresolved issues, named owners and due dates.
Want this handled for you?
CoreTech provides 24/7 monitoring, security operations and help desk support for businesses across Auckland and New Zealand.