One assessment for both your cyber insurance and AML/CFT obligations.
Most NZ financial advice and insurance firms answer two compliance questionnaires at once, and they don't always agree. Cyber insurance. AML/CFT. FMA obligations. Three regulators, three sets of promises about how your IT is run, and the gap between what you told them and what is actually configured. Our Cyber Security & Compliance Risk Assessment checks your firm against all of it, in one pass, before an underwriter or an auditor does.
Get My Cyber Security & Compliance Risk AssessmentNot ready? See what the assessment covers first.
Four quick questions, then pick a time. No obligation, no sales pitch. You keep the report either way.
Prefer the phone? Call 0800 242 206.
- Supporting NZ businesses since 2005
- 100+ organisations, 20 to 200 staff
- Support calls answered in under 11 seconds
- 98% client retention (Canterbury clients, 2022 to 2025)
ISO 27001 + ISO 42001 certified, independently audited annually
The two-questionnaire problem
Here is the pattern we keep seeing.
A financial advice or insurance firm takes out cyber insurance. Somewhere in the application is a questionnaire. Does your firm use multi-factor authentication? Are your systems patched? Do you have tested backups? Someone ticks yes to all of it, because mostly, roughly, it's true.
Around the same time, the firm is working through its AML/CFT obligations. The risk assessment, the customer due diligence procedures, the reporting. The IT controls the AML programme assumes are in place are usually the same ones the cyber insurance questionnaire asked about. Two regulators, two questionnaires, one set of underlying systems.
Then something goes wrong. A client file is exfiltrated through a compromised inbox, or a transaction is flagged for review because the audit trail is incomplete. The cyber insurer checks whether your answers were accurate on the day of the breach. The AML supervisor checks whether your programme is operating as documented. Both examinations are looking at the same underlying IT controls, and if those controls have drifted, the answer to both is uncomfortable.
That is the gap our Cyber Security & Compliance Risk Assessment closes. We check your firm against the controls both questionnaires assume, in one pass, and we show you exactly where the two pictures don't match.
Four quick questions, then pick a time. No obligation, no sales pitch. You keep the report either way.
Three problems we solve for NZ financial advice and insurance firms
1. Compliance questionnaires that drift out of date.
The answers you gave your cyber insurer last year are a snapshot. The answers you'd give today, if anyone asked, would be different. The audit trail, the documentation, the proof, it doesn't keep itself current. We keep your compliance posture documented as a live picture, not a once-a-year scramble.
2. Client data that is more exposed than the questionnaire says.
You hold client financial records, KYC files, and confidential advice history. A single compromised inbox can expose every client on your books. We put the controls in place that make your firm a hard target: MFA, endpoint protection, email security, DNS filtering, patching, and tested backups.
3. IT support that doesn't understand your sector.
Generic IT providers treat an advice firm the same as a retail shop. The FMA and AML/CFT regime, the way your CRM and portfolio tools integrate, the way your compliance officer needs the system to behave, these are sector-specific. We work with financial advice and insurance firms, and the conversations we have with your compliance team reflect that.
What working with OxygenIT looks like
Managed IT and helpdesk.
Proactive monitoring, patching and a NZ-based team that answers your support line, 0800 101 095, in under 11 seconds. No call centre, no ticket black hole. After-hours cover is an optional add-on staffed by our United Kingdom team.
Cyber security.
The six controls insurers actually ask about: multi-factor authentication, endpoint detection and response, patch management, email security, DNS filtering, and tested backups.
Microsoft 365 and cloud.
Setup, migration, backup and disaster recovery for the platforms your firm runs on.
Strategy when you need it.
Fractional vCIO and vCSO input for firms that need a technology roadmap, not just a helpdesk. The vCSO work in particular maps to the AML/CFT risk assessment and the cyber insurance questionnaire simultaneously.
We work with financial advice and insurance firms across NZ, from boutique practices to multi-adviser operations. Two examples:
i-select
Rangirata
Four quick questions, then pick a time. No obligation, no sales pitch. You keep the report either way.
What the Cyber Security & Compliance Risk Assessment covers
This is not a sales call with a checklist stapled to it. We take your actual cyber insurance policy wording and your AML/CFT risk assessment, and we check your firm against both, control by control.
What gets checked:
- The security controls your insurance questionnaire says you have, verified against what is actually configured
- The IT controls your AML/CFT programme assumes are in place, and whether the audit trail proves it
- Multi-factor authentication coverage across every staff login, including the exceptions nobody mentions
- Backup status, and whether those backups have actually been tested
- Patching, email security, DNS filtering and endpoint protection
- Where client financial records and KYC files live, and who can reach them
What you get:
- A plain-English report: compliant, at risk, or non-compliant, control by control
- A prioritised fix list, so you know what to do first and what can wait
- Documentation you can put in front of your insurer at renewal and your AML supervisor at audit
How it works
- Answer four questions. Takes about a minute, tells us if we're a fit.
- Pick a time. You'll be redirected straight to the booking calendar.
- Get your assessment. A clear report on where you stand with your insurer, your AML/CFT obligations, and what to fix.
Four quick questions, then pick a time. No obligation, no sales pitch. You keep the report either way.
FAQ
Do you only work with Christchurch firms?
No. We're NZ-wide, with offices in Christchurch and Wellington and an engineer in Auckland. Most of what we do is delivered remotely, with on-site work where it's needed.
Do you support our CRM and portfolio tools?
We work with the platforms NZ financial advice and insurance firms use day to day. If you're not sure, ask on the call.
We already have an IT provider. Is the assessment still useful?
Yes, and this is one of the most common situations we see. The assessment is an independent check against your insurance and AML/CFT obligations. If your current provider has everything in order, you'll have documented proof of it. If not, you'll know exactly what to raise with them.
What size firms do you work with?
We support organisations from 20 to 200 staff, and our financial advice and insurance clients range from boutique practices to multi-adviser operations.
What does the assessment cost?
Assessments start from $1,500. The exact price depends on the size of your firm and what your insurance policy and AML/CFT programme require, and we confirm it on the call before any work starts.
Will you try to sell us managed IT on the call?
The assessment stands on its own. If there are gaps and you want help closing them, we'll tell you what that looks like. If everything checks out, you'll hear that too.
How is OxygenIT different from other IT companies?
We publish our numbers. Support calls answered in under 11 seconds, a 15 minute response guarantee on P1 critical issues, 98% client retention across our Canterbury clients from 2022 to 2025, and ISO 27001 plus ISO 42001 certification audited independently every year. Few NZ providers publish even one of those.
Find out where you stand before your insurer, or your AML supervisor, does.
Four questions. One booked call. A clear answer on whether your firm is actually compliant with both your cyber insurance and your AML/CFT obligations, and what to fix if it isn't.
Get My Cyber Security & Compliance Risk AssessmentISO 27001 + ISO 42001 certified, independently audited every year.
Or call 0800 242 206.