Is OxygenIT Licensed, Insured and Certified?

All OxygenIT prices in one place. This page covers one service. Every price we publish, and what is never included in any of them, is on our pricing page.
What certifications should you look for in a New Zealand IT provider?
Ask any New Zealand IT provider to show you four things in writing before you sign: a recognised cyber security framework such as SMB1001 or ISO 27001, a professional indemnity insurance certificate you can actually see, and the named individual certifications held by the engineers who will actually work on your systems, not only a company-level logo on the homepage. A provider that cannot produce all four, or that answers with reassurance instead of a document, is telling you something.
A recognised cyber security framework. SMB1001 is a five tier cyber security standard, developed by Dynamic Standards International and certified through the CyberCert platform, built specifically for New Zealand and Australian small and medium businesses. It is attested annually by a company director, which matters because it puts a named person’s judgement behind the claim rather than a marketing page. ISO 27001 is the international standard for information security management, a heavier, more formal system typically suited to larger practices or those serving enterprise and government clients. Ask which framework the provider holds for itself, not only which ones it can help you get.
Professional indemnity insurance. This is different from the cyber insurance a provider might sell or recommend to you. It covers the provider’s own advice and work. Ask to see a current certificate of currency, not a verbal assurance, and ask what the cover limit is.
Named individual certifications. A company can hold a vendor partnership status while the actual engineer sent to your site holds nothing current. Ask which named, individual, vendor-specific certifications (Microsoft, or relevant security-vendor accreditations, for example) the people who will touch your systems currently hold, and ask to see them.
Here is how the cyber security framework check reads for OxygenIT specifically, as a worked example, not a substitute for asking your own shortlist the same questions directly.
- Cyber security framework: ISO 27001 and ISO 42001 certified. OxygenIT’s own client base also runs on SMB1001, with the majority of clients at Silver tier or better.
Who We Are and How Long We’ve Been Doing This
When you’re handing over control of your network, your data, and your compliance obligations, how long a company has been at it actually matters. OxygenIT started in 2005, so this business has spent more than twenty years solving IT problems for Kiwi organisations. That’s long enough to have lived through several distinct eras of technology, from the move off on-premise servers to full cloud adoption, and more recently the sharp rise in ransomware and phishing attacks aimed squarely at small and mid-sized businesses. That kind of staying power isn’t just a number to put on a website. It reflects a real track record of adapting as threats and technology shift, rather than folding after a rough couple of years in a crowded market.
During business hours every engineer and technician at OxygenIT works from New Zealand, and there is no anonymous call centre. After-hours cover is an optional add-on staffed by our United Kingdom team, working the same ticketing system and the same response targets. For Christchurch businesses, that’s not a small detail. It means whoever is diagnosing a server issue or chasing down a suspicious login understands local business hours and local compliance expectations, and can be reached directly during a genuine emergency without language or timezone friction slowing things down.
- Operating continuously since 2005, over 20 years in the New Zealand IT services market
- New Zealand team in business hours, United Kingdom team for optional after-hours cover
- Supporting more than 500 employees and endpoints across client organisations
- Have supported 100+ New Zealand businesses since 2005, across multiple industries
- Consistent service delivery through major shifts in technology and cyber threat landscapes
These numbers are worth sitting with for a moment, because scale and continuity tell a different story than a list of credentials ever could. A business can hold every relevant certification and still be a two-person outfit without the capacity to respond quickly when something goes wrong. OxygenIT’s current footprint, managing devices and staff across more than a hundred organisations, points to the operational depth needed to support businesses of different sizes reliably over the long haul. You can see how this plays out day to day by looking at our managed IT and cybersecurity services, which lay out the specific coverage this team provides across Christchurch and the wider region.
How We Decide If We’re a Good Fit for You
Certificates and insurance paperwork only tell part of the story. What actually determines whether we can protect a Christchurch business properly is whether our approach fits how that business runs, what risks it’s carrying, and what its team can realistically keep up with. Instead of pushing every enquiry straight into a generic consultation, we run a fixed four-step process that lets both sides work out, with real evidence rather than guesswork, whether we’re the right fit.
- Step 1: A 15-minute founder call. This is a direct conversation, not a sales script, where we ask about your industry, current IT setup, and why you’re looking at cyber risk now. It filters out mismatches early, before either side invests real time.
- Step 2: A full 45-minute discovery call. Here we go deeper into your systems, compliance obligations, existing insurance coverage, and any licensing requirements specific to your sector, whether that’s healthcare, legal, trades, or professional services common across Christchurch and the wider Canterbury region.
- Step 3: A Cyber Risk Assessment. Using the detail gathered in discovery, we run a structured assessment against your actual infrastructure to identify specific gaps, whether that’s outdated endpoint protection, missing cyber insurance clauses, unpatched systems, or credential management weaknesses.
- Step 4: A customised proposal. This is built directly from the assessment findings, not a template. It sets out exactly what needs fixing, what it costs, and how it aligns with any licensing or insurance obligations your business already carries.
This sequence matters because Christchurch businesses face real consequences when cyber risk decisions go wrong, from breached insurance conditions to falling foul of sector licensing requirements. A generic sales pitch simply can’t surface details that specific. Each step builds on the one before it, so by the time you receive a proposal, it’s grounded in verified findings about your business rather than assumptions about what a business like yours probably needs.
If at any point during the founder call or discovery call it becomes clear we’re not the right match, we’ll say so directly. That honesty protects your time and ours, and it’s a big part of why local businesses trust the process instead of writing it off as another cold sales funnel.
Who We Don’t Take On
We’ll state this plainly: we don’t take on residential customers, and we don’t take on businesses with fewer than 5 employees. It’s the clearest limitation on this page, and we’re leaving it as-is rather than dressing it up as a sales pitch. If your household needs help with a home network or a personal laptop, or you’re running a solo operation or a two-person shop in Christchurch, this isn’t the right fit for you.
- Every new client goes through a formal Cyber Risk Assessment before onboarding, which assumes multiple users, devices, and systems to evaluate
- The discovery process maps network topology, endpoint inventory, and access permissions across a team, which has little value for a single user or household
- Ongoing endpoint management is priced and structured around fleets of devices, not one or two machines
- Compliance and reporting frameworks referenced elsewhere on this page are built for businesses with employees, contracts, and regulatory exposure
- Support response tiers and escalation paths are designed around business continuity, not personal convenience
The five-employee threshold isn’t an arbitrary line we drew for the sake of it. It marks the point where a Christchurch business typically has enough devices, shared data, and staff turnover that ad hoc IT support or a single in-house generalist starts creating real risk. Below that size, the overhead of a full Cyber Risk Assessment, structured discovery, and ongoing managed endpoints usually costs more than it saves. Above it, that same setup starts paying for itself through reduced downtime and fewer security gaps.
None of this is a comment on the quality or seriousness of smaller operators or residential users. A sole trader in Sydenham running a tight, well-managed setup isn’t a lesser business for sitting below this threshold. It simply means the service model here, built for small-to-medium and larger New Zealand businesses, isn’t shaped to fit a one- or two-person operation. Businesses in that smaller category are usually better served by a local independent technician, a managed print or device retailer, or a simpler retainer arrangement rather than a full managed services engagement.
IT Support and Cybersecurity: Frequently Asked Questions
Are you licensed, insured, or certified for this kind of work?
We hold ISO 27001 certification for information security and ISO 42001 for AI management, both held by very few managed IT providers in New Zealand. Our cybersecurity approach is built around the SMB1001 framework. We’ve been running continuously since 2005, giving us over 20 years of hands-on IT work with New Zealand businesses.
How long have you been in business?
We started in 2005, so we’ve been operating for more than 20 years. That span covers major shifts in technology, from on-premise servers to full cloud adoption, and the rise in ransomware and phishing attacks aimed at small and mid-sized businesses. We currently manage IT and security for over 500 employees and endpoints across more than 100 New Zealand businesses.
How do you decide whether to take on a new client?
We use a fixed four-step process: a 15-minute founder call, a 45-minute discovery call, a Cyber Risk Assessment, then a customised proposal built from that assessment. Each step builds on the one before it. If either side sees a mismatch during the founder call or discovery call, we say so at that point rather than pushing ahead.
Is there work or clients you turn down?
Yes. We don’t take on residential customers, and we don’t work with businesses that have fewer than 5 employees. Our onboarding runs a formal Cyber Risk Assessment that assumes multiple users, devices, and systems to check, which doesn’t fit a home network or a one or two-person operation. If that describes your setup, we’re not the right match.
Do you use offshore staff or outsourced support desks?
Not during business hours. Every engineer and technician on our New Zealand team works from Christchurch, Wellington or Auckland, and there is no anonymous call centre. Calls to the support line are answered in an average of 11 seconds during business hours, by someone who understands local business hours and compliance expectations directly. After-hours cover is an optional add-on and is staffed by our United Kingdom team, on the same ticketing system, the same escalation path and the same response targets.
What each of these services costs, and what goes wrong
Related reading