Wellington businesses face the same cyber risk every NZ SMB is dealing with right now. According to the NCSC, 53% of NZ SMBs experienced a cyber threat in the past six months, significantly higher than the 36% reported the year prior. For firms in legal, accounting, finance, and insurance around the Wellington region, a single incident can affect client trust, cash flow, and daily operations.
This guide sets out the IT security best practices that matter most for a Wellington SMB right now: fast quick wins you can apply in 48 hours, a 30-day plan to build on them, and a practical checklist to keep your defences current every month.
What IT security best practices cover for a Wellington SMB
IT security best practices are the practical controls that protect your core assets: identity, devices, email, data, networks, and vendors. Most Wellington SMBs run on Microsoft 365, laptops, mobiles, Wi-Fi, and a mix of cloud applications, all of which need clear ownership and minimum standards.
Cloud services operate on a shared responsibility model. Your provider secures the platform, but your business is responsible for managing user access, data security, and privacy settings on top of it. A structured approach sets clear boundaries, assigns ownership to specific people, and gives your team a plan you can actually maintain month to month, rather than a list of tools nobody owns.
Common cyber threats hitting Wellington SMBs right now
Phishing and business email compromise remain the most frequent attacks, often using fake requests to redirect invoices or payroll payments. Credential theft follows close behind, usually from reused passwords or approved fake sign-in prompts, leading to account takeover. Supplier and third-party access creates risk when accountants, IT providers, or payroll tools keep broad permissions long after a project finishes, and insider mistakes such as accidental data sharing or old mailbox auto-forwarding rules can expose client information with no malicious intent at all.
For a full breakdown of attack types and how each one works, see our guide to common cyber attacks and how to defend against them.
Quick wins in 48 hours to reduce risk fast
These five actions deliver the most impact for a Wellington SMB with minimal effort, and every one of them can be actioned inside two working days.
- Turn on multi-factor authentication. Apply MFA to Microsoft 365, cloud apps, finance systems, and remote access. This single step blocks the majority of credential-based attacks.
- Review admin accounts and access. Reset passwords for all administrative accounts, remove old or unused user accounts, and reduce admin rights to the minimum level needed for each role.
- Patch key systems and apps. Update operating systems, browsers, VPNs, and other critical business applications to close known security holes attackers exploit.
- Block risky settings in email. Block legacy authentication protocols, stop automatic external forwarding, and tighten guest access and external sharing settings.
- Confirm your backups. Make sure your data backups exist, are stored separately from your main network, and that you can restore them quickly if needed.
Build your 30-day IT security plan
A practical plan does not need complex documentation. Start with a clear map of your critical systems and data, such as client files, financial records, and case management tools, and assign a specific owner for each one who is responsible for escalating issues or approving changes.
Set minimum security standards for passwords, user access, data backups, and software updates, then create a simple risk register listing your top threats, their potential impact, their likelihood, and how you plan to reduce each one. Establish a regular schedule for patching, backup checks, access reviews, and staff training, and decide which tasks your team can manage internally and which need specialist support based on risk or complexity.
Identity, endpoints, and network security
Strong identity controls sit at the centre of every plan. Enforce MFA on all key accounts, use a password manager so staff create unique complex passwords for every service, and apply the principle of least privilege so users only get the access their role needs. Separate administrator accounts from daily user accounts, keep admin-level access time-bound, and follow strict offboarding steps, including a device wipe and full access removal, for every departing employee.
Install endpoint detection and response (EDR) and anti-malware on all laptops and mobiles, apply encryption and screen lock policies through device management tools, and secure remote work with a VPN, removed local admin rights, and controlled USB and browser extension access. For the deeper threat-hunting side of endpoint defence, see our guide to protecting your business through endpoint threat hunting.
Harden your firewall with deny-by-default inbound rules, remove exposed Remote Desktop Protocol (RDP) access, enable MFA on VPNs, and use DNS and web filtering to block known malicious sites before a user can reach them. Segment guest and business Wi-Fi, and review your ISP router settings and firmware regularly.
Lock down Microsoft 365 and business email
Set up SPF, DKIM, and DMARC records for your domain to stop spoofed messages and protect your domain name. Disable risky mailbox rules, block external forwarding, and review OAuth application permissions, and require approvals plus MFA for shared mailboxes and finance workflows. Monitor for unusual sign-ins and inbox anomalies such as impossible travel alerts, which help catch credential theft early. Strong email protection, including advanced filtering, safe links, and strict attachment rules, is the foundation this all sits on.
Backups and disaster recovery
Set clear Recovery Point Objective (RPO) and Recovery Time Objective (RTO) targets that match your operations, then use the 3-2-1 method: three copies of your data, on two different systems or media types, with at least one copy offsite or in a separate cloud environment. Prioritise servers, Microsoft 365 data, and critical line-of-business applications, and test restores every quarter so you know you can recover both individual files and full systems without delay.
For the full approach to protecting Microsoft 365 data specifically, see our guide to Microsoft 365 backup for business continuity.
Policies, staff training, and monitoring
Clear policies set the rules for access, devices, and acceptable use. Staff training should help your team recognise phishing attempts, invoice scams, and safe document sharing, with a simple reporting culture so everyone knows what to do within five minutes of spotting something suspicious. Keep sessions short and practical, using simulated phishing exercises and quick refreshers rather than long annual sessions nobody remembers.
Enable logging on Microsoft 365 audit logs, firewalls, and endpoint alerts through a managed SOC so issues surface early, and have an incident response plan with clear roles and contact details for staff, IT, and key suppliers. If personal information is involved, the Office of the Privacy Commissioner sets out a privacy breach response process with four steps: Contain, Assess, Notify, and Prevent. For the full incident response walkthrough, see our incident response checklist.
IT security checklist, monthly and quarterly
A clear checklist keeps your team on track. Assign each task an owner, set due dates, and define escalation steps for anything missed. For a deeper, audit-ready version of this checklist, see our IT security assessment checklist.
| Frequency | Key Tasks |
|---|---|
| Monthly | Review user access and admin accounts. Check device patch status and risky sign-ins. Verify backup reports and success logs. Process new starter and leaver access changes. |
| Quarterly | Perform a backup restore test. Audit third-party and vendor access. Review and update your cyber security policy. Run a short staff awareness refresher. |
Secure your Wellington business with OxygenIT
OxygenIT is Christchurch based and has operated across New Zealand since 2005, with a Wellington office at The Urban Hub, Levels 2–4, 318 Lambton Quay, supporting local legal, accounting, finance, and insurance firms. We hold ISO 27001 and ISO 42001 certification, and our Wellington clients get the same structured approach described in this guide: quick wins first, a 30-day plan next, then ongoing monthly and quarterly review.
Ready to strengthen your Wellington business security? Talk to our Wellington IT support team, or contact us to learn how we can help. Call 0800 101 095.
FAQs about IT security best practices for Wellington businesses
What IT security best practices matter most for a Wellington SMB?
Multi-factor authentication, strong password policies, regular patching, and staff awareness training are the highest-impact foundations. Regular employee security training combined with patch management reduces the most common attack paths at low cost.
What is the fastest way to reduce cyber risk right now?
Apply the 48-hour quick wins in this guide: enable MFA everywhere, review admin accounts, patch key systems, lock down risky email settings, and confirm your backups actually restore. See our guide to common cyber attacks for the threats these steps defend against.
How does data encryption protect a Wellington business?
Encrypting data at rest and in transit keeps it unreadable if intercepted, across networks, cloud environments, and mobile devices. This protects customer information and intellectual property from unauthorised access even if a device or connection is compromised.
What role does a managed service provider play in IT security?
An MSP provides specialised expertise, continuous monitoring through a managed SOC, backup and disaster recovery through services like Microsoft 365 backup, and incident response capabilities that most Wellington SMBs cannot maintain internally.
How should a Wellington business prepare for a security incident?
Build and regularly test an incident response plan using tabletop exercises, and know the four-step privacy breach process (Contain, Assess, Notify, Prevent) if personal information is involved. Our incident response checklist covers the full plan.
Related security services from OxygenIT: network security services, endpoint detection and response (EDR), and penetration testing costs in NZ.