Cyber Security Services for New Zealand Business
Protection that covers the whole path an attack takes: the inbox, the device, the network and the people. Monitored and supported by a local team.
Supporting New Zealand businesses since 1989
What are cyber security services?
Cyber security services are the ongoing work of keeping attackers out of your systems, spotting them quickly when something gets through, and being able to recover when it does. Not a product you install once, but a set of controls that someone maintains, watches and tests.
For most businesses it covers four things: stopping the obvious attacks before they arrive, protecting the devices and accounts people actually use, noticing unusual activity early, and having a plan for the day something works. The words vary. Cyber security, cybersecurity, IT security and information security all get used interchangeably.
Attacks now arrive looking entirely reasonable
The old advice was to watch for bad spelling and odd addresses. That advice is finished. An attacker can now write in your industry’s language, reference a real invoice, and copy the tone of someone your staff email every week.
Which means the question is no longer whether somebody will eventually click. Somebody will. What matters is how much that click can reach, how quickly anyone notices, and whether you can put it right without losing a week. A ransomware attack is rarely the first thing that happened. It is the last, and usually weeks after someone got in.
Security is not about making your staff faultless. It is about making a single mistake survivable.
What we do
What protection actually covers
Six areas, working together rather than as separate purchases.
Email security
Most attacks arrive by email, so this is where the most is stopped. Filtering for phishing, malicious attachments and impersonation of people your staff already trust, before any of it reaches an inbox.
Endpoint protection
Every laptop, desktop and mobile is a way in. Protection that blocks malware and ransomware and works the same whether the device is in the office, at home or on a client site. See mobile device management.
Network security
Firewalls configured and maintained rather than installed and forgotten, with traffic monitored and unwanted connections blocked before they reach anything that matters.
Monitoring and response
Attacks do not keep business hours. Systems are watched around the clock for unusual behaviour, so the gap between something starting and somebody noticing is measured in minutes. See managed detection and response.
Dark web monitoring
Staff credentials get exposed in breaches at other companies and end up for sale. We watch criminal marketplaces and data dumps for your domains, so a leaked password is something you hear about from us.
Training that sticks
Scenario-based training and phishing simulations, including what convincing AI-generated attempts now look like. The aim is a habit rather than a certificate nobody remembers.
How it fits together
Prevent, detect, recover
Security spending goes wrong when it all lands in one of these three and none of the others. Most businesses we assess are heavily weighted to the first.
Prevent
Email filtering, endpoint protection, firewalls, patching and access control.
- Stops the large majority of attempts, quietly and without anyone noticing
- Limit it cannot stop everything, and it will not tell you what it missed
Detect and respond
Continuous monitoring, alerting, and somebody who acts on what comes back.
- Stops a small breach becoming a large one, which is where the real cost sits
- Limit it only works if someone is actually watching, which is the part businesses skip
Recover and prove
Backups that have been tested, a written response plan, and records of what was in place.
- Stops an incident turning into a closure, and answers the questions that follow
- Limit untested backups are not backups. See incident response plan
The honest summary is that prevention gets bought, detection gets postponed, and recovery gets assumed. We will tell you which of the three you are actually thin on rather than selling you more of what you already have.
Insurance
What cyber insurers now expect you to have
Cyber insurance has changed. Where a policy once asked a few general questions, insurers now ask for specific controls, and a claim can turn on whether what you declared was actually in place on the day.
The controls that come up most often on a New Zealand proposal form:
- Multi-factor authentication (MFA) on email and remote access, applied to everyone rather than most people
- Tested backups held separately from the main environment, with a restore someone has actually attempted
- Endpoint protection across every device, including the laptops that rarely come into the office
- Patching of operating systems and applications, on a schedule rather than when someone remembers
- Staff security training with some record that it happened and who completed it
None of that is exotic. What catches businesses out is being asked to evidence it rather than assert it.
We can work through a proposal form or renewal questionnaire with you, tell you plainly which answers are currently true, and fix the ones that are not. That is usually cheaper than the premium loading, and considerably cheaper than a declined claim.
Cost
What does cyber security cost in New Zealand?
Security is normally a monthly cost per user or per device, with an assessment at the start if you want to know where you actually stand before committing to anything.
The assessment
A review of what you have, what it covers, and where the gaps are, delivered as something you can read and act on. Fixed fee, quoted before it starts, and useful even if you go no further.
The protection
Priced per user or per device depending on the control, and usually bundled into one monthly figure rather than a stack of separate line items you have to reconcile.
What moves the number:
- How many people and devices need covering, including the ones nobody counted
- How much is already in place, since most businesses have some of this and are paying for parts of it twice
- Whether monitoring is included, which is the single biggest difference between a cheap quote and a useful one
- What your obligations are, since a business handling health or financial records carries more than one that does not
- Whether training is part of it or a separate purchase everyone forgets to renew
Worth saying plainly: the cheapest quote is usually the one without monitoring in it. That is the part that costs money to run, and it is the part that limits the damage.
The process
How we start
Find out where you stand
An assessment of what is protecting you now, what it actually covers, and what is assumed rather than configured. Most businesses are surprised by at least one thing in this, usually an account nobody closed. See cyber security assessment.
Fix the cheap things first
Multi-factor authentication, stale accounts, obvious gaps in patching. These cost almost nothing and remove a disproportionate share of the risk, so they happen before anything is bought.
Put the layers in
Email, endpoint, network and access controls deployed in an order that reflects your actual exposure rather than a product catalogue.
Turn on the watching
Monitoring, alerting and a defined path for what happens when an alert is real, including who gets rung at two in the morning.
Test it and keep testing
Phishing simulations, backup restores that are actually attempted, and a review rhythm. A control nobody has tested is a belief rather than a protection.
Security that is run, not just sold
- We already run the environment. Security that sits apart from whoever manages your IT creates seams. We look after both, so there is no gap to argue about.
- Monitoring is included, not upsold. The watching is the expensive part and the useful part. A quote without it is cheaper for a reason.
- We tell you what you do not need. Plenty of security spending buys overlap. Finding that is part of the assessment.
- Training that reflects current attacks. Including AI-generated phishing and impersonation, because last year’s examples no longer look like this year’s.
- Local teams. Christchurch and Dunedin, reachable by someone who knows your environment rather than a queue.
- Since 1989. More than 35 years of New Zealand business technology, through every generation of this problem.
Go deeper
The detail behind each of these
Everything above is covered at length elsewhere on the site. Start wherever your question sits.
Knowing where you stand
Controls and defences
Obligations and response
Where we work
Cyber security in Christchurch and Dunedin
People you can get hold of
Teams based in Christchurch since 2009 and Dunedin since 1989. When something is actually happening, you reach somebody who already knows how your environment is built rather than starting from the beginning.
Nationwide remotely
For businesses elsewhere in New Zealand the monitoring, response and training all work the same remotely. Site visits where an assessment or an incident warrants one.
Questions
Cyber security FAQs
What does cyber security cost in New Zealand?
Protection is normally a monthly cost per user or per device, usually bundled into one figure, with a fixed-fee assessment at the start if you want to know where you stand first. What moves the number is how many people and devices need covering, how much is already in place, whether monitoring is included, what obligations your industry carries, and whether training is part of it. The cheapest quote is usually the one without monitoring, which is the part that limits the damage.
We are small. Are we actually a target?
Most attacks are not aimed at anyone in particular. They are automated, and they find whoever is reachable. Smaller businesses are frequently easier to reach and less able to absorb a week of downtime, which is why they feature so heavily in the numbers rather than despite their size.
What is the single most useful thing we could do?
Multi-factor authentication (MFA) on email and remote access, if you do not already have it everywhere. It costs almost nothing, it is the control most attacks run into, and it is the one insurers ask about first. After that, tested backups.
What do cyber insurers ask for?
Commonly multi-factor authentication (MFA) on email and remote access applied to everyone, tested backups held separately from the main environment with a restore someone has actually attempted, endpoint protection across every device, patching on a schedule, and staff security training with a record of who completed it. The difficulty is usually not having the controls but being able to evidence them. We can work through a proposal or renewal form with you and say which answers are currently true.
Do we still need this if we are in Microsoft 365?
Yes. Microsoft 365 includes real security capability, but much of it is either off by default or on a licence tier you may not hold. The common failure is assuming a feature is active because it exists. Configuration is where the protection actually comes from.
Is antivirus enough on its own?
No, and it has not been for some time. Modern attacks frequently involve no malicious file at all, using stolen credentials to log in as a legitimate user. That is invisible to antivirus and visible to monitoring, which is why the two are not substitutes.
What happens if we have a data breach or a ransomware attack?
The first hours matter most: contain it, work out what was reached, and decide what has to be notified. A ransomware attack is rarely the first thing that happened, so understanding how far back the access goes matters as much as restoring the files. Having all of that written down in advance is the difference between a bad day and a bad month. See our guide to the incident response plan.
Do we have to report a breach?
Under the Privacy Act 2020, a privacy breach that has caused or is likely to cause serious harm must be notified to the Privacy Commissioner and to the people affected. Whether a given incident meets that threshold is a judgement, and it is one worth making with advice rather than alone. See Privacy Act and security.
How often should staff training happen?
Little and often beats an annual session everyone forgets. Short, regular training with occasional phishing simulations builds a habit, and the simulation results tell you where the actual risk sits rather than who sat through a slide deck.
Can you work alongside our existing IT provider?
Yes. Security is a common place for a second set of eyes, and an independent assessment of an existing arrangement is a legitimate engagement. Sometimes the finding is that the incumbent is doing a good job and the gap is one nobody had been asked to cover.
Do you monitor outside business hours?
Monitoring runs around the clock, because attacks are timed for when nobody is watching. Weekends and public holidays are popular for exactly that reason.
Not sure whether what you have is enough?
Most businesses are not certain, and the honest way to find out is to look. Tell us what you are running and we will tell you where you actually stand, including if the answer is that you are in reasonable shape.
Christchurch 03 343 3124 · Dunedin 03 479 2941 · Nationwide 0800 396 3375
About us
Security and IT from one team in Christchurch & Dunedin
Originally formed in 1989 as Willis White & Co, Exodesk was established in Dunedin by Chris Willis and Andrew White. We expanded to Christchurch in 2009, growing into one of New Zealand’s most established IT providers. Today we deliver cyber security, managed IT services, cloud solutions and business phone systems to businesses across Christchurch, Dunedin and beyond.

Contact us
For a cyber security assessment or a second opinion on what you have