Most breaches are not clever. They are unlocked doors.

Very few New Zealand businesses are targeted by anything exotic. What gets them is a reused password with no multi-factor authentication, an unpatched machine, an invoice email that looked genuine, or a backup nobody had tested.

We start by closing those doors. The controls below are the ones that give ordinary organisations the biggest reduction in risk for the least disruption, and they map to the New Zealand NCSC's Critical Controls and the guidance CERT NZ publishes for businesses.

The foundations we put in place

  • Multi-factor authentication everywhere it can be turned on - email first, then remote access, then line-of-business systems
  • Endpoint detection and response on every workstation and server, monitored rather than merely installed
  • Patching of operating systems and the third-party apps attackers actually target, on a schedule you can see
  • Email security - filtering, plus SPF, DKIM and DMARC so your domain cannot be casually spoofed
  • Administrator account separation, so day-to-day accounts cannot make environment-wide changes
  • Application and macro controls to stop the common Office document attack paths
  • Tested backups held so that ransomware on the network cannot reach them - see backup and disaster recovery
  • Logging and alerting, so a suspicious sign-in from overseas raises something rather than nothing

Your people are the other half

Technical controls do not help much when someone is talked into approving a payment change over the phone. We run short, practical awareness training and simulated phishing so staff know what a real attempt looks like, and know that reporting one is welcomed rather than embarrassing.

We also help you write down the boring but decisive things: who can authorise a change of bank account details, who to ring at 7pm on a Sunday, and what the first hour looks like if something does happen.

Where you stand today

Security assessment

We review your Microsoft 365 tenancy, endpoints, network edge, backups and admin accounts, and score them against a recognised baseline.

A prioritised plan

Findings ranked by risk and effort, in plain English, with the quick wins separated from the projects.

Remediation

We do the work, in an order that does not bring the business to a halt while it happens.

Ongoing monitoring and review

Security drifts. We re-check the baseline regularly and report on what has changed.

Free security review

A no-obligation look at your Microsoft 365 tenancy, endpoints and backups, with a written summary of the gaps.

Common questions

We are small. Are we really a target?

Most attacks are not aimed at anyone in particular - they are automated and hit whatever is exposed. Small organisations get caught because they are easier, not because someone chose them. The invoice-redirection scams that cost New Zealand businesses the most money each year are almost entirely aimed at smaller operations.

Will MFA annoy our staff?

Set up badly, yes. Set up well, most people approve a prompt once every couple of weeks on a trusted device. We configure trusted locations and device compliance so the friction lands on genuinely unusual sign-ins.

Do you handle cyber insurance questionnaires?

Yes. Insurers increasingly ask specific technical questions about MFA, backups, patching and admin accounts. We help you answer them accurately, and flag where an honest answer would currently be "no".

What if we are attacked while you support us?

We work to an incident response plan agreed with you in advance: contain, assess, restore from known-good backups, and report. Having the plan written down before the day it is needed is most of the value.

Find the gaps before someone else does

A free security review takes about an hour of your time and gives you a written picture of where you stand - useful whether or not you end up working with us.

© Copyright 2026 Business Distributors Ltd | Terms & Conditions | Privacy Policy