Internal vs External Penetration Testing for NZ SMBs: What You Need, How Often, and What It Costs
Penetration testing in NZ splits into two distinct exercises, internal and external, and they answer different questions about your security. This guide explains the difference, which one a New Zealand SMB should run first, what testing costs, how often to test, and how the results support cyber insurance applications and SMB1001 certification. It is written […]
Cyber Insurance Requirements in NZ 2026: The Readiness Checklist Underwriters Actually Want
Cyber insurance requirements in NZ have tightened sharply. A proposal form that once asked whether you ran antivirus and a firewall now demands proof of multi-factor authentication, endpoint detection and response, tested backups and a written incident response plan, and underwriters verify those answers when a claim arrives. This guide sets out the cyber insurance […]
Essential Eight vs SMB1001 vs ISO 27001: Which Cyber Framework Does Your NZ Business Actually Need?
Cyber security framework comparison questions land on the desk of almost every NZ owner and GM eventually, usually triggered by an insurance renewal, a tender or a customer questionnaire. The three names that keep coming up are the Essential Eight, SMB1001 and ISO 27001. They solve different problems, cost wildly different amounts and are asked […]
Microsoft Copilot Readiness for NZ SMBs: Is Your Data Safe Before You Switch It On?
Microsoft Copilot readiness is the question NZ businesses keep skipping. Copilot answers staff questions using everything their accounts can access across SharePoint, OneDrive, Teams and email, which means it is only as safe as the permissions underneath it. Switch it on before checking those permissions and the salary spreadsheet nobody was meant to find becomes […]
SMB1001 Gold Certification in New Zealand: The Complete 2026 Guide
SMB1001 Gold certification is fast becoming the cyber security benchmark New Zealand SMBs are asked to meet in insurance applications, supply chain questionnaires and tender responses. This guide explains what SMB1001 Gold certification in NZ involves, what it costs, which controls you need, who signs it off and how long it takes. It is written […]
Multi-factor authentication setup: A step-by-step guide for businesses
Key Takeaways MFA blocks the vast majority of automated credential attacks on its own. Start with an audit of your assets, users, and highest-risk access points before rolling anything out. Authenticator apps and hardware keys are stronger than SMS codes. Use SMS as a fallback, not the default. Conditional access policies mean staff on trusted […]
A comprehensive guide to ransomware protection for modern businesses
Key Takeaways Layer your defences: endpoints, identity, backups, and email all need separate controls, not one silver bullet. Immutable, offsite backups are what actually gets you back online without paying a ransom. Modern ransomware steals your data before encrypting it, so backups alone do not remove the extortion risk. A written incident response plan turns […]
A comprehensive guide to phishing protection for modern organizations
Key Takeaways Most phishing gets through on trust, not technical trickery. Train staff to question urgency, not just spot bad spelling. DMARC, SPF, and DKIM stop attackers from spoofing your domain in the first place. Multi-factor authentication is the single biggest thing you can do to stop a stolen password becoming a breach. Simulated phishing […]
The comprehensive guide to using Keeper password manager
Key Takeaways Securing your digital environment requires a consistent and disciplined approach to managing credentials across all platforms. Adopting a structured strategy for storage and access significantly improves your long-term security posture. Prioritize the use of unique, complex passwords for every single online account you own. Utilize a centralized vault to store and protect sensitive […]
The Essential Guide to Privileged Access Management for Modern Security
To wrap things up, managing who gets access to what is super important for keeping your digital stuff safe. Here are the main things to remember: Key Takeaways Always give people only the access they absolutely need to do their job. No more, no less. Use extra security steps, like a second password or code, […]
Implementing Zero Trust Security: A Comprehensive Guide for Modern Businesses
Implementing zero trust security is a big step, but it’s worth it. Here are the main things to remember: Key Takeaways Zero trust means you don’t automatically trust anyone or anything, even if they’re already inside your network. You always check. Strong passwords and making sure people can only access what they absolutely need are […]
Mastering Microsoft Intune Management for Modern Device Security
Keeping your devices and data safe is super important these days. Microsoft Intune management helps make sure everything is locked down tight. Here are some of the main things to remember: Key Takeaways Use strong, unique passwords and two-factor authentication to stop bad guys from getting in. Always keep your software updated to fix security […]