Practical Cyber Security for New Zealand SMEs: NCSC Guidance in Plain English

Share Article

The controls that stop most attacks are unglamorous and cheap. Here is the order to do them in.

Small businesses tend to assume they are too small to be targeted. The assumption is wrong, and it is wrong in a specific way: most attacks are not targeted at all. They are automated, opportunistic and indifferent to who you are. Being small does not make you invisible; it makes you cheaper to attack successfully.

The good news is that the controls preventing the overwhelming majority of incidents are neither expensive nor technically difficult.

Multi-factor authentication, first and without exception

If you do one thing, do this. Multi-factor authentication defeats the single most common attack path — a stolen or guessed password — because the password alone is no longer sufficient.

Enable it on email first. Email is the master key: it resets every other password you own, and business email compromise remains among the most financially damaging attacks on New Zealand businesses. Then apply it to accounting software, banking, remote access and anything holding customer data.

Prefer an authenticator app or hardware key over SMS where the option exists. SMS is better than nothing and worse than the alternatives.

Patching, because most exploits are old

The vulnerabilities used in successful attacks are usually not novel. They are known, published, patched, and unpatched on the target.

Turn on automatic updates for operating systems, browsers, phones and applications. Pay particular attention to anything exposed to the internet — firewalls, VPNs, remote access tools, and any server reachable from outside. Replace equipment that no longer receives security updates; an unsupported device on your network is a permanent open door.

Backups you have actually tested

Ransomware is survivable with good backups and expensive without them. The standard advice is three copies of your data, on two different media, with one held offsite or offline.

The critical qualifier is that a backup nobody has restored from is a hypothesis, not a backup. Test a restore at least annually. Businesses regularly discover during an incident that their backup has been silently failing for months, or that it is connected to the network in a way that let the ransomware encrypt it too.

Email is where the money goes

Invoice fraud is the most common way New Zealand small businesses lose material sums. The pattern is consistent: an attacker gains access to an email account, watches the conversation, and at the right moment sends an invoice with altered bank details.

The control that works is procedural rather than technical. Verify any change of bank account details by phone, using a number you already hold, before paying. Not by replying to the email. Make this a rule that applies to everyone including the owner, and make it socially acceptable for a junior staff member to enforce it.

Access and offboarding

Give people the access their role requires and no more. Remove access the day someone leaves — email, cloud services, shared drives, payment systems, and any shared password they knew.

Keep a simple list of every system the business uses and who has access. Most businesses cannot produce this, which is precisely why old accounts persist for years.

AI tools and business data

Staff are using AI tools whether or not there is a policy. The risk is not the technology; it is people pasting customer data, contracts or financial information into services without knowing where it goes or how it is retained.

A short, clear position — which tools are approved, what may and may not be entered into them — is more effective than a prohibition that will simply be ignored. The National Cyber Security Centre has published guidance on AI security, including on agentic systems, which is worth reading before setting policy.

When something goes wrong

Know in advance who to call. Report incidents to CERT NZ, which provides free guidance to businesses and individuals and can direct you to appropriate help. Where personal information has been compromised and serious harm is likely, you also have obligations to notify the Privacy Commissioner and affected individuals under the Privacy Act 2020.

Preserve evidence, disconnect affected systems rather than wiping them, and resist the instinct to hide the incident. Businesses that report early consistently recover better than those that do not.

Where to start

The National Cyber Security Centre publishes practical guidance for New Zealand organisations free, and CERT NZ produces material written specifically for small business without technical jargon. Both are Crown resources with no product to sell, which distinguishes them from most cyber security advice a small business will encounter.

ads-2

Explore Business Topics

Whether you’re running a business, growing your career or simply staying informed, discover expert articles from New Zealand’s most important industries.

Accounting

Tax, bookkeeping, Xero, payroll and financial reporting.

Agriculture

Farming, agribusiness, horticulture, innovation and rural industry news.

Construction

Building, trades, regulations, projects and construction industry updates.

Engineering

Engineering innovation, infrastructure, manufacturing and technical expertise.

Finance

Business finance, investing, lending, insurance and economic insights.

Health

Healthcare, medical services, wellbeing, aged care and industry developments.

Law

Commercial law, employment law, property law and legal guidance.

Logistics

Supply chains, warehousing, fulfilment, freight and logistics solutions.

Property

Commercial property, real estate, investment and market trends.

Retail

Retail trends, eCommerce, customer experience and business growth.

Technology

Artificial intelligence, cybersecurity, software and digital transformation.

Transport

Road, rail, marine, aviation and transport industry developments.