Topic
Cyber security
Identity, email compromise, backups you have actually restored, incident response, and the controls that survive contact with an attacker.
13 articles
Guest Wi-Fi is still your network
The visitor network gets set up in ten minutes and forgotten for five years. Meanwhile contractors, personal phones and the odd device nobody can identify end up on it, and it is often closer to the business systems than anyone realises.
Read it →
Is this a notifiable breach? Making the serious harm call
The Privacy Act asks one judgement of you after an incident: whether the breach is likely to cause serious harm. It is far easier to make well if you worked out how you would make it before anything happened.
Read it →
Incident response starts well before the incident
During a serious incident nobody reads a forty page plan. What gets used is a single page of phone numbers and the first four decisions, agreed while everyone was calm.
Read it →
What a board actually needs to hear about security
A slide of red and amber indicators tells a board that something is wrong and gives them no way to act on it. Three questions do more work than any dashboard.
Read it →
The security questionnaire that decides whether you keep the contract
A spreadsheet arrives from your largest customer asking sixty questions about your security. How you answer it matters less than whether the answers are true.
Read it →
Access control is an identity problem wearing a hard hat
Door systems and IT systems answer the same question about the same people, and in most businesses they answer it from two different lists that disagree.
Read it →
Your cyber insurance renewal is now a security audit
The proposal form used to be three questions. It is now a controls checklist, the answers are warranties, and the price is set by what you can evidence.
Read it →
Seasonal staff, and the accounts that never leave
A business that triples its headcount for eight weeks has an onboarding problem in March and an access problem for the following five years.
Read it →
Shadow IT is a symptom, not a crime
When a department buys its own software on a credit card, the interesting question is not who broke the rules. It is what took so long through the front door.
Read it →
The invoice that was not: how business email compromise actually works
No malware, no dramatic breach. Someone reads your mail for a few weeks, waits for a real invoice, and changes one line. It is the most common way New Zealand businesses lose money to attack.
Read it →
The network your plant runs on is not your office network
Operational technology and business IT end up sharing one flat network far more often than anyone intends. Here is what that actually costs, and what separating them involves.
Read it →
A backup you have not restored is a hope, not a plan
Backup jobs report success for years while quietly protecting the wrong things. The only test that counts is putting the data back, timed, in front of someone who cares how long it took.
Read it →
MFA is not the finish line
Turning on multi-factor authentication is the single best security decision most businesses make. It is also routinely bypassed, and the reasons are worth understanding before you call identity done.
Read it →
Next step
Recognise any of this? Let's talk.
We respond within one business day.