Cyber Security for Larger Auckland Businesses

Share Article

Bigger organisations face targeted attacks rather than opportunistic ones, and carry supply chain risk in both directions.

Auckland hosts the largest concentration of substantial businesses in New Zealand, and organisations above a certain size face a different threat profile from small businesses. The attacks are more targeted, the attack surface is larger, and the consequences reach further.

What changes with scale

Targeted rather than opportunistic. Small businesses are mostly hit by automated attacks that do not care who they are. Larger organisations attract attackers who research the target, identify individuals, and craft approaches specific to them.

More attack surface. More staff, more systems, more suppliers, more remote access. Each addition is another route in.

Supply chain exposure in both directions. Your suppliers can be the entry point, and you can be the entry point into your customers. Organisations that supply larger enterprises are increasingly attacked because of who they supply.

Regulatory and contractual consequence. Privacy Act notification obligations, customer contract requirements, and for some entities sector-specific obligations.

The controls that still do most of the work

Sophistication of threat does not change the effectiveness of the basics:

  • Multi-factor authentication everywhere, email first. It defeats the single most common attack path.
  • Patching, particularly anything internet-facing — firewalls, VPNs, remote access tools, exposed servers. The vulnerabilities used in successful attacks are usually known and patched elsewhere.
  • Tested, offline or immutable backups. Ransomware seeks out connected backups. A backup nobody has restored from is a hypothesis.
  • Least-privilege access and removal the day someone leaves.
  • Logging and monitoring sufficient to detect and investigate, which is where larger organisations should invest beyond the small business baseline.

Business email compromise remains the expensive one

The most financially damaging attack on New Zealand businesses. An attacker gains email access, observes the conversation, and sends altered bank details at the right moment.

The control is procedural: verify any change of bank account details by phone, using a number you already hold, before paying. Not by replying to the email. This must apply to everyone including executives, and staff must feel able to enforce it upward.

Larger organisations should also check for attacker-created mail forwarding rules after any suspected compromise. They frequently persist after a password reset and are missed.

Third-party and supply chain risk

For each significant supplier with access to your systems or data, establish what access they have, what their security posture is, what happens if they are breached, and what their notification commitments are.

Conversely, expect your own customers to ask. Security questionnaires are now routine in enterprise procurement, and an organisation that cannot answer loses contracts on that basis alone.

The privacy obligation

Under the Privacy Act 2020, where a breach has caused or is likely to cause serious harm you must notify the Privacy Commissioner and affected individuals as soon as practicable.

That obligation runs during the incident, while everyone is busy. The decision path should be written down beforehand, and it should sit somewhere not dependent on the systems that may be unavailable.

Note also that most ransomware now exfiltrates data before encrypting, which makes it a privacy breach as well as an availability incident. Assume exfiltration rather than hoping otherwise.

Governance

Cyber risk belongs on the board agenda with substance rather than an assurance that systems are secure. Useful board-level questions:

  • What are our three most likely incident scenarios, and what happens in each?
  • When did we last test a restore, and how long did it actually take?
  • Which suppliers could take us down?
  • Do we have cyber insurance, and what does it actually respond to?
  • Who decides on privacy notification, and how fast can they?

The National Cyber Security Centre publishes guidance for New Zealand organisations including material on AI and agentic systems, and CERT NZ provides free incident support. Both are Crown resources with nothing to sell.

General information only, not legal advice.

ads-2

Explore Business Topics

Whether you’re running a business, growing your career or simply staying informed, discover expert articles from New Zealand’s most important industries.

Accounting

Tax, bookkeeping, Xero, payroll and financial reporting.

Agriculture

Farming, agribusiness, horticulture, innovation and rural industry news.

Construction

Building, trades, regulations, projects and construction industry updates.

Engineering

Engineering innovation, infrastructure, manufacturing and technical expertise.

Finance

Business finance, investing, lending, insurance and economic insights.

Health

Healthcare, medical services, wellbeing, aged care and industry developments.

Law

Commercial law, employment law, property law and legal guidance.

Logistics

Supply chains, warehousing, fulfilment, freight and logistics solutions.

Property

Commercial property, real estate, investment and market trends.

Retail

Retail trends, eCommerce, customer experience and business growth.

Technology

Artificial intelligence, cybersecurity, software and digital transformation.

Transport

Road, rail, marine, aviation and transport industry developments.