Is OxygenIT Licensed, Insured and Certified?

OxygenIT engineers reviewing network monitoring in the Christchurch office
OxygenIT holds ISO 27001 and ISO 42001 certification, has operated continuously since 2005, and every engineer and technician is New Zealand based, with optional after-hours cover staffed by our United Kingdom team. We support more than 500 employees and endpoints, and have supported 100+ New Zealand businesses since 2005.
ISO 27001 and ISO 42001 certifiedNZ based engineers onlyOperating since 2005100+ NZ businesses supported

All OxygenIT prices in one place. This page covers one service. Every price we publish, and what is never included in any of them, is on our pricing page.

What certifications should you look for in a New Zealand IT provider?

Ask any New Zealand IT provider to show you four things in writing before you sign: a recognised cyber security framework such as SMB1001 or ISO 27001, a professional indemnity insurance certificate you can actually see, and the named individual certifications held by the engineers who will actually work on your systems, not only a company-level logo on the homepage. A provider that cannot produce all four, or that answers with reassurance instead of a document, is telling you something.

A recognised cyber security framework. SMB1001 is a five tier cyber security standard, developed by Dynamic Standards International and certified through the CyberCert platform, built specifically for New Zealand and Australian small and medium businesses. It is attested annually by a company director, which matters because it puts a named person’s judgement behind the claim rather than a marketing page. ISO 27001 is the international standard for information security management, a heavier, more formal system typically suited to larger practices or those serving enterprise and government clients. Ask which framework the provider holds for itself, not only which ones it can help you get.

Professional indemnity insurance. This is different from the cyber insurance a provider might sell or recommend to you. It covers the provider’s own advice and work. Ask to see a current certificate of currency, not a verbal assurance, and ask what the cover limit is.

Named individual certifications. A company can hold a vendor partnership status while the actual engineer sent to your site holds nothing current. Ask which named, individual, vendor-specific certifications (Microsoft, or relevant security-vendor accreditations, for example) the people who will touch your systems currently hold, and ask to see them.

Here is how the cyber security framework check reads for OxygenIT specifically, as a worked example, not a substitute for asking your own shortlist the same questions directly.

Who We Are and How Long We’ve Been Doing This

Quick Summary: OxygenIT has been running continuously since 2005, which adds up to more than two decades of hands-on experience with New Zealand businesses. Every engineer is New Zealand-based, and the company manages IT and cybersecurity for more than 500 employees and endpoints, and has supported 100+ New Zealand businesses since 2005.

When you’re handing over control of your network, your data, and your compliance obligations, how long a company has been at it actually matters. OxygenIT started in 2005, so this business has spent more than twenty years solving IT problems for Kiwi organisations. That’s long enough to have lived through several distinct eras of technology, from the move off on-premise servers to full cloud adoption, and more recently the sharp rise in ransomware and phishing attacks aimed squarely at small and mid-sized businesses. That kind of staying power isn’t just a number to put on a website. It reflects a real track record of adapting as threats and technology shift, rather than folding after a rough couple of years in a crowded market.

During business hours every engineer and technician at OxygenIT works from New Zealand, and there is no anonymous call centre. After-hours cover is an optional add-on staffed by our United Kingdom team, working the same ticketing system and the same response targets. For Christchurch businesses, that’s not a small detail. It means whoever is diagnosing a server issue or chasing down a suspicious login understands local business hours and local compliance expectations, and can be reached directly during a genuine emergency without language or timezone friction slowing things down.

These numbers are worth sitting with for a moment, because scale and continuity tell a different story than a list of credentials ever could. A business can hold every relevant certification and still be a two-person outfit without the capacity to respond quickly when something goes wrong. OxygenIT’s current footprint, managing devices and staff across more than a hundred organisations, points to the operational depth needed to support businesses of different sizes reliably over the long haul. You can see how this plays out day to day by looking at our managed IT and cybersecurity services, which lay out the specific coverage this team provides across Christchurch and the wider region.

Call now

How We Decide If We’re a Good Fit for You

Certificates and insurance paperwork only tell part of the story. What actually determines whether we can protect a Christchurch business properly is whether our approach fits how that business runs, what risks it’s carrying, and what its team can realistically keep up with. Instead of pushing every enquiry straight into a generic consultation, we run a fixed four-step process that lets both sides work out, with real evidence rather than guesswork, whether we’re the right fit.

This sequence matters because Christchurch businesses face real consequences when cyber risk decisions go wrong, from breached insurance conditions to falling foul of sector licensing requirements. A generic sales pitch simply can’t surface details that specific. Each step builds on the one before it, so by the time you receive a proposal, it’s grounded in verified findings about your business rather than assumptions about what a business like yours probably needs.

If at any point during the founder call or discovery call it becomes clear we’re not the right match, we’ll say so directly. That honesty protects your time and ours, and it’s a big part of why local businesses trust the process instead of writing it off as another cold sales funnel.

Call now

Who We Don’t Take On

We’ll state this plainly: we don’t take on residential customers, and we don’t take on businesses with fewer than 5 employees. It’s the clearest limitation on this page, and we’re leaving it as-is rather than dressing it up as a sales pitch. If your household needs help with a home network or a personal laptop, or you’re running a solo operation or a two-person shop in Christchurch, this isn’t the right fit for you.

The five-employee threshold isn’t an arbitrary line we drew for the sake of it. It marks the point where a Christchurch business typically has enough devices, shared data, and staff turnover that ad hoc IT support or a single in-house generalist starts creating real risk. Below that size, the overhead of a full Cyber Risk Assessment, structured discovery, and ongoing managed endpoints usually costs more than it saves. Above it, that same setup starts paying for itself through reduced downtime and fewer security gaps.

None of this is a comment on the quality or seriousness of smaller operators or residential users. A sole trader in Sydenham running a tight, well-managed setup isn’t a lesser business for sitting below this threshold. It simply means the service model here, built for small-to-medium and larger New Zealand businesses, isn’t shaped to fit a one- or two-person operation. Businesses in that smaller category are usually better served by a local independent technician, a managed print or device retailer, or a simpler retainer arrangement rather than a full managed services engagement.

Fit Check: Not sure whether your business meets the minimum scale for this kind of engagement? The simplest test is headcount and device count together. Five or more employees with shared systems, shared data, or regulatory exposure is generally the point where this service model starts to make sense.

IT Support and Cybersecurity: Frequently Asked Questions

Are you licensed, insured, or certified for this kind of work?

We hold ISO 27001 certification for information security and ISO 42001 for AI management, both held by very few managed IT providers in New Zealand. Our cybersecurity approach is built around the SMB1001 framework. We’ve been running continuously since 2005, giving us over 20 years of hands-on IT work with New Zealand businesses.

How long have you been in business?

We started in 2005, so we’ve been operating for more than 20 years. That span covers major shifts in technology, from on-premise servers to full cloud adoption, and the rise in ransomware and phishing attacks aimed at small and mid-sized businesses. We currently manage IT and security for over 500 employees and endpoints across more than 100 New Zealand businesses.

How do you decide whether to take on a new client?

We use a fixed four-step process: a 15-minute founder call, a 45-minute discovery call, a Cyber Risk Assessment, then a customised proposal built from that assessment. Each step builds on the one before it. If either side sees a mismatch during the founder call or discovery call, we say so at that point rather than pushing ahead.

Is there work or clients you turn down?

Yes. We don’t take on residential customers, and we don’t work with businesses that have fewer than 5 employees. Our onboarding runs a formal Cyber Risk Assessment that assumes multiple users, devices, and systems to check, which doesn’t fit a home network or a one or two-person operation. If that describes your setup, we’re not the right match.

Do you use offshore staff or outsourced support desks?

Not during business hours. Every engineer and technician on our New Zealand team works from Christchurch, Wellington or Auckland, and there is no anonymous call centre. Calls to the support line are answered in an average of 11 seconds during business hours, by someone who understands local business hours and compliance expectations directly. After-hours cover is an optional add-on and is staffed by our United Kingdom team, on the same ticketing system, the same escalation path and the same response targets.