Even without a heavy industry regulator, a few obligations and expectations shape sensible IT decisions for almost every business. Your IT provider should understand them and translate them into systems, not paperwork.
Privacy Act 2020. Almost every business holds personal information about customers, staff or suppliers, so the Privacy Act applies to you too. The Office of the Privacy Commissioner expects notification of a notifiable privacy breach without undue delay. The good news is that the same controls that meet this also protect the rest of your business.
Card payments and PCI. If you take card payments in any form, the PCI DSS standard applies to how that data is handled. For most SMBs this is straightforward once payment systems are properly separated from everything else, which is something we set up by default.
Customer and insurer expectations. More of your customers, and almost every cyber insurer, now ask what security you have in place before they sign or renew. Being able to answer that clearly, with multi-factor authentication, managed devices and tested backups, is increasingly part of simply doing business.
The practical security baseline. Frameworks like the ACSC Essential Eight and the NCSC's guidance for small organisations exist precisely so smaller teams have a sensible target without a regulator forcing it. We treat that baseline as the floor, not the ceiling, and align you to the level that fits your business.
In practice that translates to a specific set of controls that suit almost any SMB: multi-factor authentication everywhere, least-privilege access, managed and encrypted devices, email security tuned for phishing and invoice fraud, encrypted backups with tested restores, and a simple plan for what happens if something goes wrong.
The systems most NZ SMBs run, and what we do with each
We are platform-agnostic but practical. We secure and support the everyday systems a smaller business actually depends on, and we keep the stack lean rather than selling you things you don't need.
- Identity and access: Microsoft Entra identity management, conditional access, multi-factor authentication and least-privilege permissions so access is controlled and easy to manage as staff come and go
- Microsoft 365: the productivity and collaboration core, set up properly and secured, with email protection tuned to filter phishing and impersonation
- Devices: managed, encrypted laptops, desktops and mobiles, with endpoint protection that secures without getting in the way
- Networking and connectivity: secure, reliable internet, Wi-Fi and remote access across the office and for people working from home
- Security operations: monitoring, endpoint protection and a tested response process scaled to the size of your business
- Backup and recovery: encrypted backup with tested restores, so the business is genuinely recoverable, not just backed up on paper
We are not here to over-engineer or oversell. We make sure the essentials work properly together, give you one accountable point of contact, and grow the setup with you. If a decision is genuinely complex, such as a cloud migration or a bigger security uplift, we run a structured assessment before recommending anything.