Cyber security for small businesses in New Zealand comes down to a handful of controls done well: multi-factor authentication, prompt updates, sensible access, tested backups, careful payments and staff who know what a scam looks like. Security Solution Consultants (SSC) helps small and medium businesses across New Zealand put those basics in place, meet Privacy Act 2020 obligations and answer the security questions larger customers now ask, without enterprise-sized budgets or jargon.

Most attacks on small businesses are not sophisticated. Criminals send convincing invoices with changed bank details, take over email accounts with stolen passwords, encrypt files with ransomware, or trick staff into approving payments. They target small businesses because they expect weak passwords, no second factor and no one checking the logs. The good news is that the same few controls stop most of these attacks.
The National Cyber Security Centre (NCSC) publishes Critical Controls based on the incidents it sees in New Zealand, and reviews them every year. For a small business, the most important are:

Most small business incidents we see start with a compromised email account. Once an attacker is inside a mailbox, they watch conversations, send fake invoices and reset passwords for other systems. Turning on multi-factor authentication for every account, starting with email and accounting, closes that door. We help you switch it on across Microsoft 365 or Google Workspace, remove old login methods that bypass it, and set up recovery so staff are not locked out.

Ransomware and accidental deletion are survivable when backups are complete, separate from the systems they protect, and tested. Cloud services such as Microsoft 365 do not automatically protect you from every deletion or attack, so we check what is really backed up, how long it is kept, and how quickly you could restore your most important information.
| When | What to do |
|---|---|
| Week 1 | Turn on multi-factor authentication for email, banking and accounting. Remove accounts for people who have left. |
| Week 2 | Turn on automatic updates everywhere. Check that only one or two people have administrator access. |
| Week 3 | Confirm what is backed up, where, and for how long. Restore one important file or folder to prove it works. |
| Week 4 | Set up SPF, DKIM and DMARC for your email domain. Agree the rule for checking bank detail changes, and run a 30-minute scam awareness session with the team. |
Write down what you did and when. That short record is the start of your security policy, and it is exactly what customers and insurers ask to see.
If the answers are unclear, that is the first gap to close. We can join that conversation and turn the answers into a short plan.
We work with your existing IT provider rather than replacing them, so improvements are made by the people who already look after your systems.
Our incident response and recovery service can help you plan ahead so these steps are not being worked out under pressure.
We support small and medium businesses in Auckland, Wellington, Christchurch, Hamilton, Tauranga and Dunedin. For local detail, read our guides to cyber security for small businesses in Wellington and cyber security services for Auckland SMEs, and our article on AI cyber attacks and how New Zealand businesses can defend against them. See all our cyber security services in New Zealand, or contact us for a cyber health check.
Start with multi-factor authentication on every account, automatic updates, limited administrator access, tested backups, email protection with SPF, DKIM and DMARC, a rule to verify any change of bank details by phone, and short staff training on scams. These cover most attacks against small businesses.
Yes. Many attacks are automated and opportunistic, looking for weak passwords and missing updates regardless of business size. Invoice fraud and email account takeover are among the most common incidents affecting small businesses.
Yes, if a privacy breach has caused or is likely to cause serious harm. The Privacy Act 2020 requires you to notify the Privacy Commissioner and affected individuals as soon as practicable; the Commissioner expects notification within 72 hours.
The most effective controls, such as multi-factor authentication, updates and backups, often use tools you already pay for. Advisory help is usually a short, fixed-scope engagement. We scope the work to your size and risk before quoting.
Usually not at first. Get the basics in place and documented. If customers or tenders require independent certification, ISO 27001 can be scoped to suit a small organisation.
Yes. We advise and assess, and work alongside your IT provider so they can implement the improvements in systems they already manage.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.