Your cyber insurance may not cover you.
Most NZ law firms find out on claim day. You hold client files, discovery documents, and confidential communications. That makes your firm a target, and your insurer knows it. The questionnaire you signed says you have security controls in place. Our Cyber Security Risk Assessment checks whether that is actually true, before an underwriter does.
Get My Cyber Security Risk AssessmentNot ready? See what the assessment covers first.
Four quick questions, then pick a time. No obligation, no sales pitch. You keep the report either way.
Prefer the phone? Call 0800 242 206.
Supporting NZ businesses since 2005 100+ organisations, 20 to 200 staff Support calls answered in under 11 seconds 98% client retention (2022 to 2025) ISO 27001 + ISO 42001 certified, independently audited annuallyThe insurance problem
Here is the pattern we keep seeing.
A law firm takes out cyber insurance. Somewhere in the application is a questionnaire. Does your firm use multi-factor authentication? Are your systems patched? Do you have tested backups? Someone ticks yes to all of it, because mostly, roughly, it's true. The policy is issued and everyone moves on.
Then something goes wrong. A client file is encrypted by ransomware, or a partner's email is accessed from an unfamiliar location. The claim goes in. And the first thing the insurer does is check whether those answers were accurate on the day of the breach.
For a law firm, the stakes go further than a declined claim. You have client confidentiality obligations, document integrity obligations, and the risk of professional discipline if client material is exposed. If MFA was switched off for one partner because it was annoying, or the backups had not been tested since the questionnaire was signed, that claim is in trouble. Not because anyone lied. Because nobody was checking.
That is the gap our Cyber Security Risk Assessment closes. We check what you told your insurer against what is actually running in your firm, and we show you exactly where the two don't match.
Three problems we solve for NZ law firms
1. Downtime during active matters.
When your practice management system or email goes down in the middle of a hearing, you don't have an IT problem. You have a client problem, and a court-deadline problem. We answer support calls in under 11 seconds and fix issues before they become professional embarrassments.
2. Client confidentiality, document integrity, discovery obligations.
A single compromised inbox can expose every client on your books. You have confidentiality duties to clients, integrity duties around documents, and discovery obligations when litigation is on foot. We put the controls in place that make your firm a hard target: MFA, endpoint protection, email security, DNS filtering, patching, and tested backups.
3. Compliance you can't prove.
Ticking a box on an insurance questionnaire is not the same as having documentation an underwriter will accept. We give you documented, current proof of your security posture, so renewal time is a formality instead of a scramble.
What working with OxygenIT looks like
Managed IT and helpdesk.
Proactive monitoring, patching and a NZ-based team that answers your support line, 0800 101 095, in under 11 seconds. No call centre, no ticket black hole. After-hours cover is an optional add-on staffed by our United Kingdom team.
Cyber security.
The six controls insurers actually ask about: multi-factor authentication, endpoint detection and response, patch management, email security, DNS filtering, and tested backups.
Microsoft 365 and cloud.
Setup, migration, backup and disaster recovery for the platforms your firm runs on.
Practice management software support.
We support OneLaw, Infinitylaw and ActionStep, and we work with the other platforms NZ law firms use day to day.
Strategy when you need it.
Fractional vCIO and vCSO input for firms that need a technology roadmap, not just a helpdesk.
We support NZ law firms from boutique practices to multi-partner operations, across the country.
Argyle Welsh Finnigan
What the Cyber Security Risk Assessment covers
This is not a sales call with a checklist stapled to it. We take your actual cyber insurance policy wording and check your firm against it, control by control.
What gets checked
- The security controls your insurance questionnaire says you have, verified against what is actually configured
- Multi-factor authentication coverage across every staff login, including the exceptions nobody mentions
- Backup status, and whether those backups have actually been tested
- Patching, email security, DNS filtering and endpoint protection
- Where client files, document repositories and confidential communications live, and who can reach them
What you get
- A plain-English report: compliant, at risk, or non-compliant, control by control
- A prioritised fix list, so you know what to do first and what can wait
- Documentation you can put in front of your insurer at renewal
Assessments start from $1,500. Exact scope and price are confirmed on the call, based on the size of your firm.
How it works
-
Answer four questions.
Takes about a minute, tells us if we're a fit.
-
Pick a time.
You'll be redirected straight to the booking calendar.
-
Get your assessment.
A clear report on where you stand with your insurer, and what to fix.
FAQ
Do you only work with Christchurch firms?
Do you support our practice management software?
We already have an IT provider. Is the assessment still useful?
What size firms do you work with?
What does the assessment cost?
Will you try to sell us managed IT on the call?
How is OxygenIT different from other IT companies?
Find out where you stand before your insurer does.
Four questions. One booked call. A clear answer on whether your firm is actually compliant with its cyber insurance, and what to fix if it isn't.
Get My Cyber Security Risk AssessmentISO 27001 + ISO 42001 certified, independently audited every year.
Or call 0800 242 206.