Cyber Security for New Zealand Business
Certified against 27 controls, so you can prove it to your insurer
Your insurer is going to ask whether you have multi-factor authentication, tested backups and monitored endpoints. Your biggest customer might ask the same thing before they renew. “We take security seriously” is not an answer to either of them.
IT Live is certified to SMB1001 Gold – an independent standard covering 27 specific security controls – and we get every business we manage to a Microsoft Secure Score above 70% and keep them there. That’s a number you can check yourself, in your own admin portal, today.
Can you actually stop an attack?
You can’t stop someone trying. You can absolutely change what happens when they do.
The businesses that come out of an incident fine are the ones where MFA stopped the stolen password from being useful, where the SOC isolated the machine in minutes, and where the backup was real and tested. The ones that don’t come out fine are usually missing one of those three. It’s rarely exotic – it’s almost always something basic that nobody owned.
That’s the whole job: make the common attacks not work, and make the rare ones survivable.
SMB1001 Gold - what it actually covers
SMB1001 is a cyber security standard written for small and medium business, rather than one built for banks and then squeezed down. Gold is the level where an external body assesses you against 27 controls. In plain terms, those controls cover:
Identity – multi-factor authentication on every account, admin accounts separated from daily-use ones, and access reviewed when people change roles or leave.
Email – the thing that gets almost everyone. Spam and phishing filtering, sender authentication (SPF, DKIM and DMARC – the records that stop someone spoofing your domain), and blocking on the dangerous attachment types.
Devices – patching on a schedule, endpoint protection running and reporting, and encryption on laptops so a stolen one isn’t a data breach.
Backup – backups that exist, that are separate from the thing they’re backing up, and that have actually been restored from in a test.
People and process – staff training, a written incident response plan, and a register of who has access to what.
We hold the certification ourselves and we work our clients through the same list. You end up with evidence, not a feeling. See what we hold.
Why it matters commercially
Insurers price cyber cover on evidence – MFA, tested backups, monitored endpoints, a documented incident response plan – and brokers increasingly want a standard named on the application form. Here is what a cyber insurance proposal form asks, and how to evidence each answer. Being able to point at a certification means you’re answering those questions with a document instead of an opinion.
Your biggest customer may ask the same questions before they renew, and tenders now ask them as a matter of course. Not sure where you’d land? Start with our free 2-minute cyber readiness check.
Huntress - a 24/7 security operations centre
A SOC is a room full of human analysts reviewing alerts around the clock. Ours is Huntress. The difference between a SOC and an antivirus product is what happens at 2am: antivirus sends an email nobody reads, a SOC isolates the machine off the network and then tells us.
We’ve had clients who had no idea anything had happened until we rang them. If you’d rather see where you stand before you change anything, start with a security audit.
Microsoft 365 hardened and measured
Conditional access, MFA enforced, legacy authentication switched off, mailbox rules monitored – a forwarding rule quietly added to the finance mailbox is one of the oldest tricks going.
It is measured continuously by Microsoft Secure Score, so drift shows up. Secure Score is Microsoft’s own measure of how well a Microsoft 365 tenant is locked down, it sits in your own admin portal, and you don’t need us to see it.
Datto backup on Microsoft 365
Microsoft keeps the platform available. It does not protect your data from deletion, ransomware, or a staff member on their way out the door – that responsibility stays with you.
So we run third-party backup across email, OneDrive, SharePoint and Teams, and we test restores rather than trusting a green tick on a dashboard.
Monitoring and patching on every device
Through NinjaOne, on a schedule, reported. Unpatched machines are how most incidents start, and they are the easiest thing on this page to get right – which is what ongoing vulnerability management is for.
We’ll run a free security review – your Secure Score, where you sit against the 27 controls, and what to fix first. Email info@itlive.co.nz, or talk to our Whangarei office.
Testimonials
IT Live has been our IT partner for over 8 years. They've been fantastic since day 1. We love their sense of humour - in this industry, you need IT!
Nicki Paramore
nsaTax
Thank you for the concerted effort and great service from all at IT Live during the changeover, it wasn’t a 5-minute job that’s for sure. Very professional, helpful in explaining things and prompt in sorting things out – as indeed Brandon was again today.
Bill Collins
Director,
LouvreTec
Frequently asked questions
What is SMB1001 Gold and do we need it?
SMB1001 is an independent cyber security standard for small and medium business, and Gold means 27 specific controls have been assessed by an external body. You don’t legally need it, but if an insurer, a large customer or a government contract is asking how you manage cyber risk, it’s the cleanest way to answer. We hold it and we take clients through the same controls.
Will better security get us cheaper cyber insurance?
It changes the conversation, and your broker is the one who confirms what it does to the premium. Insurers price on evidence - MFA, tested backups, monitored endpoints, a documented incident response plan - and a certification plus a measurable Secure Score means you answer those questions with a document rather than a tick-box declaration.
What is a SOC, and isn’t antivirus enough?
A SOC is a security operations centre - human analysts watching alerts 24/7. Antivirus is software that blocks known bad files. The gap between them is the attacker who logs in with a valid stolen password and doesn’t run any malware at all. Antivirus sees nothing. A SOC sees the login from an unusual location at 3am and cuts it off. We run Huntress for exactly that.
We’ve got MFA. Are we safe?
Safer, and it’s the single best control there is - but not immune. Attackers now steal the session token after you’ve passed MFA, which lets them in without ever needing your code. That’s what identity threat detection catches. Worth knowing so nobody treats MFA as the finish line.
Does Microsoft back up our Microsoft 365 data?
No, and this catches a lot of people. Microsoft guarantees the service is available, not that your data survives someone deleting it, ransomware encrypting it, or a leaver taking a mailbox with them. Retention periods run out. We add Datto backup across email, OneDrive, SharePoint and Teams, with restores tested rather than assumed.