Christchurch · Dunedin · Nationwide
Network Security Services for NZ Businesses
Secure the connections your business relies on, from office networks and Wi-Fi to remote access and the systems your team uses every day. Exodesk works with you to define what needs protecting, what needs changing and who will look after it.
Supporting New Zealand businesses since 1989
The short answer
What is network security?
Network security protects the connections your business uses by controlling access, limiting unwanted traffic and maintaining the equipment that connects your systems.
It includes firewalls, network separation, Wi-Fi, remote access, monitoring and the logging that lets you review what happened. A firewall is one part of it, not the whole of it.
Network security protects the connections between devices and the systems they reach. Endpoint security protects the devices themselves. The two cover different ground, which is why a business needs both.
When to look closer
When your network needs attention
A network can grow one change at a time: a new office, extra wireless coverage, supplier access, or a system that now needs to work remotely.
The connections can keep working long after anyone has checked whether they are still appropriate. These are signs it is worth a closer look, not a diagnosis.
Nobody can say what is reachable
There is no current list of which services and devices can be reached from the internet, or why they were opened.
Guests share the staff network
Visitor devices connect to the same network as staff laptops, printers and the systems the business runs on.
Supplier access with no end date
A contractor or vendor still has a route in long after the job that needed it has finished.
One shared administrator login
Network equipment is managed through a single account, so changes cannot be traced to a person.
Equipment past vendor support
Switches, access points or gateways no longer receive security updates, and nobody has planned the replacement.
Alerts with no owner
Equipment raises warnings, but it is not clear who reviews them, when, or what happens next.
The service
What our network security services include
Six areas of work, scoped around your sites, the systems your business depends on and the people who need access.
Your agreement sets out which areas apply, the devices and locations covered, and the support hours.
Network design and segmentation
Separating guest access, business devices and sensitive systems, based on which connections each one needs.
Firewall and gateway management
The rules governing traffic into, out of and between networks. Our managed firewall service explains gateway management in more detail.
Wi-Fi security
Current encryption, separate guest networks and authentication suited to staff, visitors and devices that nobody logs into.
Remote access
How staff and suppliers reach business systems from outside the office, with authentication and access limited to what each person needs.
Maintenance and monitoring
Firmware updates, configuration changes and alert monitoring for the network equipment in scope, with changes recorded. This includes securing administrator access with named accounts and multi-factor authentication where the equipment supports it.
Logs and access reviews
Keeping useful records from the network and reviewing access and rules on an agreed schedule, so access that is no longer needed is removed.
Monitoring and response are different parts of the service. Your agreement identifies which alerts are reviewed, when they are reviewed and who acts on them. Network fault support and security incident response may have different arrangements. Where managed detection and response is included, its scope sets out the systems and security signals covered, the response hours and the actions the team can take.
How you can buy it
A project, ongoing management, or both
Network security work can be a one-off improvement, an ongoing arrangement, or a project followed by ongoing management.
Network security can be bought on its own, without moving the rest of your IT to us.
An improvement project
A defined piece of work, such as separating guest Wi-Fi, replacing unsupported equipment or tightening remote access, quoted and scoped before it starts.
Ongoing management
Agreed maintenance, monitoring and reviews for the equipment and locations in scope. Redesign, replacement hardware and larger remediation are scoped separately rather than assumed to sit inside a recurring fee.
Alongside your IT team
If you have your own IT person or team, we can work on a co-managed basis, with each task and device given a named owner.
Some related work sits in its own service with its own scope, including endpoint protection, email security, cloud security and backup. Where your network security work depends on one of these, the scope says so.
How we work
How the work is delivered
Changes to a network affect the systems people use every day, so the order matters.
Establish what is connected
Identify the sites, equipment, internet-facing services, remote access paths and supplier connections in scope, along with the business requirements behind them.
Agree priorities and dependencies
Decide what to change first, and identify any equipment, application or supplier dependencies before anything is touched.
Plan and test each change
Schedule changes around how your business operates, test the connections essential systems need, and keep a way to reverse a change if something is affected.
Hand over with responsibilities defined
Where ongoing management is agreed, set out maintenance, monitoring and response responsibilities before handover, including who approves future changes.
Keep it current
Apply updates, record changes and review access and rules on the agreed schedule, so the arrangements keep pace with the business.
In your agreement
What your agreement should make clear
Network security depends on decisions only your business can make, as well as on the technical work.
- Who approves access and changes. Named people on your side, and a record of each change and who approved it.
- Who manages each supplier. Line-of-business vendors, telcos and other providers with their own access or equipment.
- What is covered. The devices, locations and support hours in scope, and what is project work rather than ongoing management.
- Where monitoring ends. The difference between an automated alert, human investigation, containing an incident and the recovery work that follows.
- Who accepts the risk. Where a recommended change is not made, who decided and why.
NZ guidance
How New Zealand guidance informs the work
The National Cyber Security Centre and the New Zealand Information Security Manual are useful reference points for network protection.
The NCSC guidance on network separation and segmentation advises allowing only the ports and protocols each network needs, putting guests on a network of their own, reviewing network devices at least once a year, and starting small with high-risk areas such as devices holding sensitive data or controlling administrative functions.
The NZISM is written for New Zealand government agencies and for the vendors, contractors and consultants who provide services to them, and other organisations are encouraged to use it. For a private business it is a reference point rather than a general compliance requirement, unless a contract, including one with a government agency, sets security requirements your business must meet. The network security controls your business needs depend on its systems, risks and commitments, so we apply the relevant guidance to your environment rather than treating a government checklist as a universal rule.
Cost
What affects the cost of network security?
It depends on the network, the equipment and the work you want managed.
We scope those requirements before quoting. These are the things that move the figure:
- Sites and equipment. The number of locations, switches, access points and gateways, and whether existing equipment can stay.
- Remote access. How many people and suppliers connect from outside, and to which systems.
- Project work. Redesign, segmentation, replacement and migration, quoted separately from ongoing work.
- Ongoing management. Maintenance, monitoring, reviews and the support hours agreed.
- Licences and hardware. Security subscriptions and any replacement equipment.
Your quote sets out the setup costs, recurring charges, licences and hardware required, plus how additional work is approved and charged.
Why Exodesk
Why work with Exodesk?
Supporting businesses since 1989
We support New Zealand organisations from our teams in Christchurch and Dunedin, with the network considered alongside your systems, connectivity and support.
Clear responsibility for the work
Your agreement identifies the work Exodesk handles and the decisions that need your approval, so changes and issues have a clear route.
Connected to the rest of your security
Network security sits alongside our cyber security services, with zero trust principles informing how access is granted.
Questions
Network security questions
What does a network security service cover?
It can cover network design and segmentation, firewall and gateway management, Wi-Fi, remote access, maintenance, monitoring and log reviews. The agreed scope identifies the systems covered, what is managed routinely and what needs separate project work.
Is network security the same as a managed firewall?
A managed firewall is one part of network security. The wider service considers connections inside the business, wireless access, remote users and network equipment as well as the gateway. The two services have clear, complementary responsibilities, and our managed firewall service covers the gateway in more detail.
Can our existing equipment be used?
That depends on whether it is still supported by the vendor, can provide the controls required and suits the network. Equipment and licensing requirements are identified before the implementation scope is agreed.
Will network changes disrupt our business?
Some changes need a maintenance window. We identify application and supplier dependencies, test essential connections and agree a rollback plan before implementation. The impact depends on the work involved.
How much does network security cost?
The cost depends on the sites, equipment, remote access and ongoing work in scope. Setup and project costs are quoted separately from recurring management, licences and any replacement hardware. Your quote also sets out how additional work is approved and charged.
Does monitoring include a response at any time?
Not automatically. Your agreement states when alerts are reviewed and what happens outside supported hours. Any managed detection and response service has its own coverage and response scope, which sets out which security alerts it handles and how network faults are supported.
Can we buy network security without managed IT?
Yes. Network security can be taken as a one-off improvement project, as ongoing management, or both, without moving the rest of your IT to us. The scope sets out which parts apply.
Can you work alongside our own IT team?
Yes. We can work with an internal IT person or team on a co-managed basis. The agreement sets out who looks after each device and task, who approves changes and who leads an incident that involves both teams.
Does the NZISM apply to our business?
The New Zealand Information Security Manual is intended for government agencies and for the vendors, contractors and consultants who provide services to them. Other organisations are encouraged to use it, and particular requirements can also form part of a contract. For a private business without those commitments it is a useful reference, so check your contracts before treating it as optional.
Do cyber insurers require network controls?
Requirements differ between insurers and policies, so check the proposal form and policy wording for your own cover. Answer the questions accurately, because your answers form part of the basis of the policy. Our cyber insurance guide covers what to check.
How long should network logs be kept?
Long enough to investigate an incident that is found some time after it began. The NZISM says government agencies should keep DNS, proxy and event logs for at least twelve months, which is a useful reference point. Log sources, retention and storage costs are agreed in the scope.
Do you work outside Christchurch and Dunedin?
Yes. We support organisations throughout New Zealand from our teams in Christchurch and Dunedin. How on-site work is arranged for other locations is agreed in the scope.
Next step
Need a clearer view of your network security?
Talk to Exodesk about the systems you rely on and the work you need managed. We will discuss what you have, what needs checking and what a sensible first step looks like.
It helps to know the number of sites, the main network equipment and how staff connect remotely. If you do not have those details to hand, start with what you know. For a wider look at your systems, an IT assessment is also available.
Get in touch
Discuss your network security
Tell us a little about your network and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941