Five Security Controls Every NZ Business Thinks They Have — But Often Don’t

Five Security Controls Every NZ Business Thinks They Have — But Often Don’t

Most New Zealand businesses feel reasonably confident about their cybersecurity posture – until something forces them to take a closer look. A cyber insurance renewal, a client security questionnaire, or even a near‑miss incident often reveals the same pattern: controls that appear to be “in place” are actually incomplete, inconsistent, or misunderstood.

Here are the five controls we most commonly see overestimated, and why they matter more than ever.

1. Multi‑Factor Authentication on All Accounts

Many organisations proudly say they “have MFA,” but when we dig deeper, it’s usually only enabled on Microsoft 365. The gaps are where attackers strike:

  • Admin accounts without MFA
  • Remote access tools (RDP, VPN) left unprotected
  • Legacy applications that don’t support MFA
  • Third‑party platforms with optional MFA that was never turned on

Attackers don’t need to break in – they just need one unprotected login. If MFA isn’t universal, it’s not doing its job.

2. Backups That Are Tested, Not Just Running

A backup that hasn’t been restored is a backup you can’t trust.

Businesses often have:

  • Backups that haven’t been tested in months (or years)
  • Backups that fail silently
  • Backups stored in the same environment that gets encrypted during ransomware.

A tested backup is the difference between a bad day and a catastrophic one. Testing should be scheduled, documented, and verified.

3. A Written, Practised Incident Response Plan

Many organisations believe they have an incident response plan because “we know what we’d do.” But in a real incident, stress, confusion, and time pressure take over.

A functional plan includes:

  • Who to call
  • What systems to isolate
  • How to communicate if email is down
  • Who has authority to make decisions
  • How to document actions for insurers and regulators

Even better: rehearse it. A one‑hour tabletop exercise can expose gaps you didn’t know existed.

4. Software Updates Applied Within 30 Days

This is now a standard requirement from insurers – and for good reason. Most major breaches exploit vulnerabilities that have had patches available for weeks or months.

Common issues include:

  • Servers patched quarterly instead of monthly
  • Third‑party apps (Java, Chrome, PDF readers) left outdated
  • Network devices (firewalls, switches) running years‑old firmware
  • “Critical” patches applied, but “important” ones ignored.

Attackers don’t care about your patching schedule. They care about the easiest way in.

5. Independent Review of Microsoft 365 Security Settings

Microsoft 365 is powerful, but it’s not secure out of the box. Many businesses assume their tenant is configured correctly because “it’s all in the cloud”, or “head office” has it sorted.

But misconfigurations are incredibly common:

  • Mail rules that allow forwarding outside the organisation
  • Legacy authentication still enabled
  • Conditional Access policies missing
  • Excessive admin privileges
  • No alerting or auditing configured.

An independent review often uncovers issues that internal teams simply don’t know to look for.

These five controls form the foundation of modern cyber resilience. They’re also the exact controls insurers, auditors, and attackers focus on. Getting them right isn’t just good practice – it’s essential. If you’re unsure where you stand, a structured readiness assessment can give you clarity before a breach or an insurer forces the issue. and strengthen your setup today can prevent costly incidents tomorrow. Because when it comes to cybersecurity, it’s not just about having the right tools – it’s about using them properly.

Find out how we can work together

Contact us