What we do

Cyber security

The Essential Eight isn't law. It's the price of entry to a tender.

Most businesses don't go looking for security work. It arrives — as a questionnaire from a head contractor, a renewal form from an insurer, or an invoice that turned out to be fake. We deal with all three.

Australia has the Essential Eight. New Zealand has something different, and calling it by the wrong name is the fastest way to look like a foreign supplier.

Where you actually stand

Let's be straight about what's compulsory.

A lot of IT companies imply the Essential Eight is the law. For a private Australian business, it isn't. It's mandatory for Commonwealth government entities. For you it's a recommendation from the Australian Signals Directorate.

That sounds like good news until you notice where it turns up anyway: in the security questionnaire your biggest customer sends before renewing, in state government tender requirements, and in the proposal form your insurer wants filled in. Nobody legislated it. Everybody asks about it.

So the useful question isn't "do we have to?" It's "can we answer the questions honestly, and what happens to our tender if we can't?"

Where you actually stand

New Zealand doesn't have an Essential Eight. It has something quieter.

The closest New Zealand equivalent is the NCSC's 10 Critical Controls. Worth knowing two things about them straight away, because plenty of Australian providers get both wrong.

First, there are no maturity levels. No ML1, no ML2, nothing to be certified against. Anyone offering you a New Zealand maturity rating has imported an Australian idea and put a koru on it.

Second, the NCSC aims the Critical Controls at larger organisations, and New Zealand has no single SMB control set with the brand recognition the Essential Eight enjoys across the Tasman. For a smaller business the practical guidance is Own Your Online, which is genuinely useful and is a set of tools rather than a checklist.

That gap is real, and it's a reason to have someone opinionated in your corner rather than a framework to wave at people.

What we do about it

Find the gap, cost the fix, close it, keep it closed.

  1. Gap assessment

    We test what's actually configured, not what's meant to be. You get a score against each of the eight controls, evidence for each finding, and a plain-English explanation of what it means if you do nothing.

  2. A costed plan, in priority order

    Not a 60-page report. A list: what to fix, what it costs, how long it takes, and what it buys you. Some items are a configuration change we can do this week at no extra cost. Some need licences you don't have. We'll tell you which is which.

  3. The uplift work

    MFA and conditional access done properly across every application, not just email. Admin rights removed from day-to-day accounts. Patching on a schedule with reporting. Application control. Backups that have actually been restored from, because an untested backup is a hope, not a control.

  4. Ongoing proof

    Controls drift. Someone gets local admin for a printer install and keeps it for two years. We re-check quarterly and show you the trend, so the next questionnaire is a ten-minute job rather than a fortnight of panic.

The bit nobody else offers

We fill in the questionnaire for you.

When a customer sends you forty questions about your security controls, send it to us. We answer it accurately, flag anything we can't answer yet, and tell you what it would take to turn a "no" into a "yes". You review it and sign it. That's the whole job.

It's the single most common reason businesses ring us, and the fastest way to find out whether your security is real or theoretical.

Security awareness training

Government funding for the free Cyber Wardens program finished on 31 July 2026, and the replacement CyberSmart scheme isn't due to pilot until the second half of 2027. There's a real gap right now. We run short, non-patronising staff training and simulated phishing so you can see who clicks — without turning it into a witch hunt.

When something does happen

We contain it, work out what was taken, and help you through the notification decisions. Worth knowing before you're in it: since the Cyber Security Act 2024, paying a ransom is a reportable event, not a private commercial decision. Most business owners have no idea.

Cyber insurance

Answer the proposal form wrong and you may not be covered.

Cyber insurance proposal forms now ask about multi-factor authentication, backup testing, endpoint protection, patching cadence and who holds admin rights. They're yes/no questions and they feel like paperwork.

They aren't. They're the basis on which the policy was written. If someone ticked "yes, MFA is enforced on all remote access" because it felt broadly true, and it turns out three accounts were excluded, that's a problem you find out about at the exact moment you need the policy to work.

We go through the form with you and make the answers true before you sign it. Where they aren't true yet, we tell you what it costs to make them true.

On NZISM: it's a government-sector manual, and compliance with it isn't required as a matter of law. It matters to you only if you supply government under a formal agreement, in which case it flows down contractually. Anyone selling NZISM compliance to a twenty-person business is selling you something you don't need.

We won't tell you what your insurer will or won't pay. We're not brokers and we don't see their underwriting rules. What we can do is make sure that every answer you give them is accurate and evidenced.

Start with the free check.

Ten questions, two minutes, no email address required. You'll get a rough read on where you sit against the Essential Eight and what to look at first.