For years, many small and medium businesses (SMBs) in New Zealand operated under the assumption that they were too small to be targeted by cybercriminals. “They’ll go after the big guys,” was the common thought. Unfortunately, that assumption is now dangerously outdated.
Cyber attackers have realised that SMBs often have less robust security measures and fewer resources dedicated to cyber security, making them attractive, easier targets. Breaching an SMB can provide a stepping stone to larger partners, access to sensitive customer data, or a quick payday through ransomware.
The financial and reputational damage of such an attack can be devastating, often leading to business closure.
CERT NZ (Computer Emergency Response Team New Zealand) consistently highlights in their annual reports how heavily SMBs are targeted by phishing, business email compromise, and ransomware. While specific company names are often kept confidential, their reports detail millions of dollars lost annually by New Zealand organisations, a significant portion of which are SMBs.
Cyber criminals view SMBs as having valuable data but often weaker defences than large corporations, making them an “easier win.”
The good news? You don’t need an enterprise-level budget or an in-house team of security experts to get enterprise-grade protection.
Solutions designed specifically for the SMB market now provide comprehensive security – including 24/7 monitoring, staff training, and robust backup solutions – without the complexity or prohibitive cost. It’s about getting the same level of protection as larger organisations, tailored for your business needs. Don’t wait to become a statistic; empower your SMB with strong, accessible cyber security.
We are here to help, just give us a call!
In the meantime, here are some tips for small businesses to get started with, or talk with your IT provider about.
1. Lock Down the Basics
- Enable MFA everywhere: Email, banking, cloud apps, social accounts. A stolen password alone shouldn’t be enough.
- Update promptly: Turn on auto-updates for OS, browsers, POS systems, routers. Most breaches exploit old, known flaws.
2. Train the Human Firewall
- Phishing drills: Teach staff to spot urgent wire transfer requests, fake invoices, and “IT support” calls.
- Rule of verification: Any money or data request via email must be confirmed by phone using a known number, not the one in the email.
3. Secure Access & Data
- Least privilege: Employees only get access to what they need. The intern doesn’t need admin rights.
- Backups 3-2-1: 3 copies, 2 different media types, 1 offsite/offline. Test restoring quarterly. Ransomware hates good backups.
- Encrypt devices: BitLocker for Windows, FileVault for Mac. Lost laptop ≠ lost data.
4. Protect Customer Touchpoints
- Lock down your website: Use HTTPS, keep CMS/plugins updated, delete unused accounts. Many small biz sites get hijacked for malware.
- Secure payments: Use a PCI-compliant processor. Never store card numbers in spreadsheets or email.
- Email domain protection: Set up SPF, DKIM, DMARC so scammers can’t easily spoof you to your customers.
5. Plan for “When”, Not “If”
- Incident plan on 1 page: Who to call, how to isolate infected devices, where backups are, cyber insurance contact.
- Cyber insurance: For many SMBs, a $1M policy costs less than one ransomware event. Read exclusions carefully.
- Vendor check: Ask your IT provider, accountant, and cloud vendors what security they have. Their breach becomes yours.