What Every Northland Business Should Know About Cyber Security in 2026

Posted: August 5, 2026Category:

Most of the businesses we help in Northland are not big banks — they are the local accountant, the building supplier, the transport yard, the dental practice. And being small is exactly why the attackers like you.

We had a Northland client last year who did everything they thought was right. They had Multi-Factor Authentication (MFA) turned on — the six-digit code most of us now use to log in. They still got hacked. The attacker stole the login token straight out of the session, so the code never came into it. No alarm, no locked account, no sign anything was wrong. The customer had no idea until we called them. With the right identity-monitoring tool it was shut down in about 10 minutes — but without it, that same break-in runs for weeks while someone reads your email and waits for an invoice to change.

That is the shift I want every business owner up here to understand. The old advice — have a good password, run antivirus — is not enough anymore. So here is what actually matters in 2026, in plain English.

The most expensive attack is an email, not a virus

The single most expensive incident we see is not ransomware. It is a fake invoice. Someone gets into an email account, watches the conversation, then quietly changes the bank account number on a real invoice at the right moment. The money goes out the door looking completely normal.

One New Zealand business lost $700K this way — they made off with the lot before anyone noticed the account number had changed. This is Business Email Compromise, and it is the quiet one because there is no scary screen and no locked files. Just money gone.

What to look for: does your provider actually monitor your Microsoft 365 accounts for this — not just have MFA switched on, but watch for stolen sessions and dodgy mailbox rules? If the answer is that MFA was set up years ago, that is not the same thing.

MFA is the front door, not the whole house

MFA is still worth having — please turn it on everywhere. But treat it as the lock on the front door, not the whole security system. The attackers have moved on to stealing the session after you have logged in. You want something watching for that — Identity Threat Detection, which is a fancy way of saying an alarm that goes off when your login is used from somewhere it should not be.

You cannot protect what you cannot see

A lot of Northland businesses genuinely do not know how many laptops, phones and old machines are connected to their systems. We regularly find Windows 10 devices still logging in months after they should have been retired — each one a door left open. Step one of good security is boring: a real list of every device, kept current, with the old ones switched off. Nice and simple, but almost nobody does it.

Cyber insurance now asks hard questions

More insurers are refusing to pay out when the basics were not in place. The application forms have got a lot more specific — they now ask whether you have MFA, whether you back up, and whether you can prove it. If you are signing one of these, make sure your answers are actually true, because a wrong yes can void the cover exactly when you need it.

There is finally a simple standard to aim at

For years, security felt like an endless list with no finish line. That has changed. SMB1001 is a tiered cyber-security standard built for small and medium businesses — it gives you a clear level to reach and certify against, instead of guessing. It is the first time I have been able to show a client a straight answer to how do we know when we are secure enough.

We run our clients through it as a gap assessment — we check what is actually in place against the standard and hand back a plain list of what to fix, ranked. No 80-page report nobody reads.

What to look for before you hire anyone

If you are weighing up an IT or security provider in Northland, three honest questions cut through most of the noise:

  • Ask them to show you how they would know if you were already breached right now. If the answer is vague, keep looking.
  • Ask what they are monitoring, and who actually looks at the alerts. Tools with nobody watching them are just decoration.
  • Ask whether they can measure you against a real standard and show you the gaps. If they cannot, you have no way to know where you stand.

None of this needs to be scary or expensive to start. The first step is small — a proper look at where you actually stand today. Most owners are relieved to find it is only two or three things that matter most, not two hundred.

We have made that first step as easy as it gets — a free Cyber Readiness Self-Check you can run yourself in a few minutes. It measures you against the SMB1001 standard and shows you the gaps, no cost and no sales call required. Have a read, run the check, and if you want a hand with what it turns up, give us a call. We will keep it nice and simple.

Contact us today