Cloud Security Services for New Zealand Businesses
Your cloud platform gives you security features. Someone still has to configure them, keep them right as the business changes, and act when something looks wrong. Exodesk manages that work.
Supporting New Zealand businesses since 1989
What cloud security actually covers
Your provider secures the platform. Your business stays accountable for the accounts, settings, sharing and data you put on it.
Providers such as Microsoft and Google protect the data centres, hardware and core services their platforms run on. Everything your business puts on top of that stays with your business. What that leaves with you is how the tenant is configured, which staff hold administrator rights, whether accounts use multi-factor authentication, and who can reach your data.
This page is about who manages that second half. If the question is where your systems should run in the first place, that is covered on our cloud solutions page.
What our cloud security service includes
Six areas of work, shaped around the cloud services you use and what your own team already handles.
We manage cloud security on Microsoft 365 and on the Exodesk hosted platform in New Zealand, and assess other cloud services individually against the access and controls they expose. Before work starts we confirm the systems covered, the work included and the responsibilities your team keeps. Identity protection runs through several of these areas, because a compromised account can expose the information and services it can reach.
Accounts and access
Sign-in protection and permissions that match each role, with permissions updated when roles change and access removed when someone leaves. More on multi-factor authentication and identity and access management.
Security configuration
Establishing what is actually configured, which exceptions exist and whether the result suits your business, then keeping it that way as the platforms change underneath you.
Sharing and permissions
External sharing, guest access and file permissions reviewed and tightened. A Microsoft 365 permissions audit shows what is currently exposed rather than what you assume is.
Connected applications
Bringing the cloud tools staff have adopted into view, so company data is not sitting in services nobody is managing. Background on shadow IT.
Backup and recovery
Deciding what needs backup beyond the retention your platform provides, with restoration tested rather than assumed. See Microsoft 365 backup and data backup strategy.
Identity threat detection and response
Watching for unexpected sign-ins, unusual downloads, new mailbox rules and permission changes, then investigating and acting on what turns up, to the limits set for your service.
Who is responsible for cloud security
Three parties, and the boundaries between them are worth writing down.
Your cloud platform provider
Operates and protects the platform, and supplies the security and recovery features that come with it. Your business still chooses which services to use, including whatever data location options each one offers.
Exodesk
Carries out the configuration, management, monitoring and recovery work set out in your agreement, and tells you when something needs a decision from your side.
Your business
Approves who should have access, tells us when people or requirements change, and decides what level of risk is acceptable.
The split is not identical for business cloud apps, hosted servers and custom applications, so we set it out for the systems we cover rather than leaving it to assumption.
How the service works
Confirm what is covered
Identify the cloud systems, users and data involved, the work your own team already handles and the work we take on. This is also where exclusions get named.
Put the controls in place
Plan the changes around business access and application dependencies, with responsibility for approval and implementation clear on both sides before anything is switched.
Manage and review
Maintain the controls we put in place, handle the alerts we cover, and revisit the setup when people, applications or business requirements change.
What we keep under review
A cloud tenant can look perfectly healthy while its settings drift.
- Access that outlived its reason. Staff who changed role, contractors whose work finished, guests invited for a project that ended.
- Sharing that widened quietly. Links set to anyone who has them, folders opened to the whole company, permissions nobody revisited.
- Defaults that were switched off. Security defaults are commonly disabled when conditional access policies are introduced, and what replaced them is worth checking.
- Backups nobody has restored from. A backup job that completes is not a tested recovery, and the two answer different questions.
- Applications nobody approved. Connected apps holding company data outside anything the business is managing.
Reporting worth having shows what is covered, what changed, what is still outstanding and what needs a decision from you. Reporting that only lists activity is describing effort rather than position.
What affects the cost of cloud security
Scope drives it, which is why a headline figure tells you very little.
- How much is in scope. The number of cloud services and users covered, and whether hosted servers or custom applications are included.
- What is already in place. Whether the configuration needs putting right first, and how much of that is a one-off piece of work.
- Licensing. Which controls need licences you do not already hold, and which are available within what you have.
- Backup and recovery. Whether backup management and recovery testing form part of the service or sit alongside it.
- Ongoing management. How much continuing review, alert handling and reporting you want from us rather than doing yourselves.
We separate the work needed to establish the service from the work included month to month, identify any additional licences the controls require, and name what sits outside both before the work starts.
Why work with Exodesk
We have supported New Zealand businesses since 1989, with teams in Christchurch and Dunedin and clients around the country. Cloud security sits inside our wider cyber security services, so the people managing your cloud environment can see the rest of your technology rather than one slice of it.
If you want a picture of where you stand before committing to anything ongoing, an IT assessment is the usual starting point.
Cloud security questions
What do cloud security services include?
They can include access controls, security configuration, sharing and permission management, oversight of connected applications, monitoring and backup management. We agree which systems and which of those tasks are covered, and which responsibilities stay with your team.
Does our cloud provider already handle security?
Your provider protects the platform it operates and supplies security features with it. Your business still needs suitable access controls, configuration and recovery arrangements on top of that. We can manage agreed parts of that work.
Which cloud platforms do you support?
We manage cloud security on Microsoft 365 and on the Exodesk hosted platform in New Zealand. On Microsoft 365 that covers sign-in protection and conditional access, administrator roles, sharing and guest access, connected applications, and the recovery and retention settings. For other cloud services, what we can take on depends on the access, logging and controls that service exposes, so we assess those individually rather than claiming coverage we cannot deliver. The platforms covered are named in your agreement.
What monitoring and response is included?
That is set out in your agreement rather than implied. Confirm what is monitored, who investigates an alert, what we are authorised to change without asking, and what happens outside business hours. Monitoring software running continuously is a different thing from people investigating around the clock. Where you need detection that reaches beyond identity into endpoints and networks, that is managed detection and response.
Can you help if we already use cloud services?
Yes. The service is scoped around the environment you already have. The starting point is identifying the systems involved, the controls already in place and the work you want us to manage.
Can you work alongside our internal IT team?
Yes. The responsibilities get divided rather than duplicated. Agree who approves access, who maintains controls, who handles alerts and who leads the response to an incident, so nothing is done twice and nothing is left unassigned.
Is cloud backup included?
Only where it is agreed as part of the scope. Check which applications and data are protected, how far back the retention reaches and how restoration works. Do not assume that a cloud subscription or a security service includes backup.
Does Microsoft 365 already include backup?
It includes recovery and retention features, and what is available depends on the workload and the settings in place. Microsoft also sells a separate backup service on some plans. Whether any of that meets your recovery needs is worth establishing rather than assuming, and our Microsoft 365 backup guide covers what it does and does not reach.
What determines the cost?
The systems and users covered, what is already configured, the licences the controls require and how much ongoing management you want. Work needed to establish the service is separated from the work included month to month, with exclusions named before the agreement starts.
What does our business still need to do?
Approve who has access, tell us when people or requirements change, and decide what level of risk is acceptable. We carry out the work assigned to us in the agreement and raise the decisions that are yours to make.
What cloud security gaps do you help address?
The common ones are a reused password on an account without multi-factor authentication, a file shared more widely than intended, a connected application nobody approved, and a setting left as it arrived. Those are the areas this service is built to manage.
Do we need an IT provider to secure our cloud systems?
Not necessarily. A business with the time and the skills can manage its own cloud security. The work is ongoing rather than one-off, which is where it tends to slip, so the real question is who owns it rather than whether a provider is required.
Talk to us about cloud security
Tell us which cloud systems your business uses and what you need help managing. We will discuss the work Exodesk can take on and the responsibilities that need to stay with your team.
It helps to know which platforms you are on and roughly how many users. If you do not have those details to hand, start with what you know.
Discuss your cloud security
Tell us a little about your setup and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941