Cyber Security for New Zealand Business
Certified against 27 controls, so you can prove it to your insurer
Your insurer is going to ask whether you have multi-factor authentication, tested backups and monitored endpoints. Your biggest customer might ask the same thing before they renew. “We take security seriously” is not an answer to either of them.
IT Live is certified to SMB1001 Gold – an independent standard covering 27 specific security controls – and IT Live holds every business it manages to a Microsoft Secure Score above 70% and keeps them there. That’s a number you can check yourself, in your own admin portal, today.
Can you actually stop a cyber attack?
Quick answer: IT Live can’t stop someone trying to break into your business – nobody can. What IT Live changes is what happens next: multi-factor authentication makes a stolen password useless, the Huntress security operations centre isolates a compromised machine within minutes, and a tested backup gets your data back.
The businesses that come out of an incident fine are the ones where all three of those were already in place before anything happened. The ones that don’t come out fine are usually missing one of them. It’s rarely exotic – it’s almost always something basic that nobody owned.
That’s the whole job, and it is what IT Live does for every business it manages: make the common attacks not work, and make the rare ones survivable.
What does SMB1001 Gold actually cover?
SMB1001 Gold is a cyber security standard written for small and medium business, and Gold is the level where an external body assesses you against 27 specific controls. IT Live is certified to SMB1001 Gold and takes the businesses it manages through the same 27 controls. It was written for small and medium business rather than built for banks and then squeezed down. In plain terms, the controls cover:
Identity – multi-factor authentication on every account, admin accounts separated from daily-use ones, and access reviewed when people change roles or leave.
Email – the thing that gets almost everyone. Spam and phishing filtering, sender authentication (SPF, DKIM and DMARC – the records that stop someone spoofing your domain), and blocking on the dangerous attachment types.
Devices – patching on a schedule, endpoint protection running and reporting, and encryption on laptops so a stolen one isn’t a data breach.
Backup – backups that exist, that are separate from the thing they’re backing up, and that have actually been restored from in a test.
People and process – staff training, a written incident response plan, and a register of who has access to what.
You end up with evidence, not a feeling. See what IT Live holds.
Why does SMB1001 Gold certification matter commercially?
Insurers price cyber cover on evidence – MFA, tested backups, monitored endpoints, a documented incident response plan – and brokers increasingly want a standard named on the application form. Here is what a cyber insurance proposal form asks, and how to evidence each answer. Being able to point at a certification means you’re answering those questions with a document instead of an opinion – which is why IT Live takes the businesses it manages through the same 27 SMB1001 controls IT Live holds itself.
Your biggest customer may ask the same questions before they renew, and tenders now ask them as a matter of course. Not sure where you’d land? Start with the IT Live free 2-minute cyber readiness check.
Does IT Live run a 24/7 security operations centre?
Yes. IT Live runs Huntress as its security operations centre – a SOC, meaning human analysts reviewing alerts around the clock, across every business IT Live manages. The difference between a SOC and an antivirus product is what happens at 2am: antivirus sends an email nobody reads, a SOC isolates the machine off the network and then tells IT Live.
IT Live has had clients who had no idea anything had happened until the IT Live team rang them. If you’d rather see where you stand before you change anything, start with a security audit.
How does IT Live harden and measure Microsoft 365?
IT Live hardens Microsoft 365 with conditional access, MFA enforced, legacy authentication switched off and mailbox rules monitored – a forwarding rule quietly added to the finance mailbox is one of the oldest tricks going. IT Live then measures the result with Microsoft Secure Score, and holds every business it manages above 70%.
Secure Score is measured continuously, so drift shows up. It is Microsoft’s own measure of how well a Microsoft 365 tenant is locked down, it sits in your own admin portal, and you don’t need IT Live to see it.
Does Microsoft 365 need a separate backup?
Yes. Microsoft keeps the platform available, but it does not protect your data from deletion, ransomware, or a staff member on their way out the door – that responsibility stays with you.
IT Live runs Datto third-party backup across email, OneDrive, SharePoint and Teams, and IT Live tests restores rather than trusting a green tick on a dashboard.
How does IT Live patch and monitor every device?
IT Live patches and monitors every device it manages through NinjaOne, on a schedule, reported. Unpatched machines are how most incidents start, and they are the easiest thing on this page to get right – which is what ongoing vulnerability management is for.
IT Live will run a free security review – your Secure Score, where you sit against the 27 controls, and what to fix first. Email info@itlive.co.nz, or talk to the IT Live Whangarei office.
Testimonials
IT Live has been our IT partner for over 8 years. They've been fantastic since day 1. We love their sense of humour - in this industry, you need IT!
Nicki Paramore
nsaTax
Thank you for the concerted effort and great service from all at IT Live during the changeover, it wasn’t a 5-minute job that’s for sure. Very professional, helpful in explaining things and prompt in sorting things out – as indeed Brandon was again today.
Bill Collins
Director,
LouvreTec
Frequently asked questions
What is SMB1001 Gold and do we need it?
SMB1001 is an independent cyber security standard for small and medium business, and Gold means 27 specific controls have been assessed by an external body. You don’t legally need it, but if an insurer, a large customer or a government contract is asking how you manage cyber risk, it’s the cleanest way to answer. IT Live holds SMB1001 Gold and takes the businesses it manages through the same 27 controls.
Will better security get us cheaper cyber insurance?
It changes the conversation, and your broker is the one who confirms what it does to the premium. Insurers price on evidence - MFA, tested backups, monitored endpoints, a documented incident response plan - and a certification plus a measurable Secure Score means you answer those questions with a document rather than a tick-box declaration.
What is a SOC, and isn’t antivirus enough?
A SOC is a security operations centre - human analysts watching alerts 24/7. Antivirus is software that blocks known bad files. The gap between them is the attacker who logs in with a valid stolen password and doesn’t run any malware at all. Antivirus sees nothing. A SOC sees the login from an unusual location at 3am and cuts it off. IT Live runs Huntress for exactly that.
We’ve got MFA. Are we safe?
Safer, and it’s the single best control there is - but not immune. Attackers now steal the session token after you’ve passed MFA, which lets them in without ever needing your code. That’s what identity threat detection catches. Worth knowing so nobody treats MFA as the finish line.
Does Microsoft back up our Microsoft 365 data?
No, and this catches a lot of people. Microsoft guarantees the service is available, not that your data survives someone deleting it, ransomware encrypting it, or a leaver taking a mailbox with them. Retention periods run out. IT Live adds Datto backup across email, OneDrive, SharePoint and Teams, with restores tested rather than assumed.