Most cyber security guides are written for IT professionals. This one is not. It is written for NZ business owners, managers, and staff who know they should be taking cyber security seriously but are not sure where to start, what matters, or how much it will cost.
The honest answer to those questions: start with a small number of high-impact controls, most of which are free or low-cost, and build from there. You do not need to solve everything at once.
Why Cybersecurity Matters for NZ Businesses
Cyber crime is the fastest-growing category of crime affecting NZ businesses. CERT NZ receives thousands of incident reports annually, and the reported financial losses run into the hundreds of millions of dollars. The actual total is higher — many incidents are not reported.
More importantly for NZ business owners: cyber incidents are not just an IT problem. A ransomware attack that encrypts your files can halt operations. A phishing attack that compromises your email can enable fraudulent payments. A data breach can trigger Privacy Act obligations and damage customer trust. The business consequences are real and severe.
The Five Things That Matter Most
Security has a long tail of possible controls. These five address the vast majority of successful attacks against NZ SMEs.
### 1. Multi-Factor Authentication (MFA)
MFA means that logging into an account requires two things: something you know (your password) and something you have (a code from an app on your phone). If an attacker steals your password — through phishing, credential stuffing, or a data breach — they still cannot log in without the second factor.
Enable MFA on: your business email (Microsoft 365 or Google Workspace), your accounting software (Xero, MYOB), your banking platforms, and any cloud service accessible from outside your office.
Cost: free. Time to enable: 10-15 minutes per account.
### 2. Staff Training on Phishing
The majority of successful attacks start with an employee clicking something they should not have. Training staff to recognise phishing emails — the warning signs, what to do when something looks suspicious, and how to report it — is the most direct way to reduce this risk.
Training does not need to be expensive or time-consuming. Even a 30-minute session covering the basics — how to check sender addresses, what to do before clicking links, what legitimate IT support will and will not ask for — significantly reduces click rates on phishing simulations.
Cost: low. Ongoing phishing simulation platforms like SecureAZ make it practical for small teams.
### 3. Working, Tested Backups
Ransomware encrypts your files and demands payment for decryption. If you have a recent backup stored somewhere the ransomware cannot reach, you can recover without paying. If your only backups are on the same network that got encrypted, you cannot.
A working backup strategy for a small NZ business means: automated daily backups to a cloud service or external drive, stored separately from your main systems, with the restore process tested at least once to confirm it actually works.
Cost: low to moderate (cloud backup services typically $10-50/month for small businesses).
### 4. Software Updates
Software vulnerabilities are exploited by attackers to gain access to systems. When software vendors release updates, they typically include patches for known vulnerabilities. Keeping your operating system, browser, Microsoft Office or Google Workspace, and any other software current removes those attack vectors.
Enable automatic updates for everything on your work computers and mobile devices. If automatic updates are not possible for some business-critical software, schedule manual updates and treat them as a business maintenance task.
Cost: free. Time: minimal with automatic updates enabled.
### 5. Strong Passwords via a Password Manager
Weak or reused passwords are a primary cause of account compromise. A password manager generates and stores strong, unique passwords for every account so staff do not need to remember them. The only password that needs to be memorised is the master password for the manager itself.
For NZ small businesses, password managers like Bitwarden (free for individuals, low-cost for teams), 1Password, or the built-in managers in Microsoft 365 and Apple devices are practical options.
Cost: free to low.
Basic Security Hygiene Checklist
Beyond the five core controls, these practices significantly reduce your exposure:
- Remove access immediately when staff leave. Former employee accounts left active are a common security risk.
- Do not share passwords or accounts between staff. Every person should have their own login.
- Be suspicious of unexpected requests involving payments or credentials, even from known contacts. Verify through a separate channel.
- Do not plug unknown USB drives into work computers.
- Lock your computer screen when stepping away from your desk.
- Use a business email address for business, not a personal Gmail or Hotmail.
What to Do When Something Goes Wrong
Even with good security hygiene, incidents can happen. Knowing what to do in the first hour matters.
- If an account is compromised: change the password immediately, revoke active sessions, and check for any rules or forwarding set up in email settings.
- If you suspect ransomware: disconnect affected computers from the network (pull the ethernet cable or turn off Wi-Fi) immediately to limit spread, then call IT support.
- If a fraudulent payment was made: contact your bank immediately — many banks can recall payments if contacted quickly enough.
- Report incidents to CERT NZ at cert.govt.nz. They provide free support and use reports to track threat trends affecting NZ organisations.
Getting External Help
If you do not have internal IT support, several options exist for NZ small businesses:
- CERT NZ provides free guidance and incident support at cert.govt.nz
- Managed service providers (MSPs) can handle patching, backup, and security monitoring for a monthly fee
- Security awareness training platforms like SecureAZ handle the human layer — phishing simulations and staff training — without requiring IT expertise to run
Cybersecurity does not have to be complicated. Start with MFA, train your staff, test your backups, keep software updated, and use a password manager. That combination prevents the majority of incidents affecting NZ businesses.
SecureAZ makes security awareness training simple for NZ small businesses