A guide to Government grants and tax incentives for businesses
A small business can be ruined by just one cyberattack. Many businesses have a hard time getting back on their feet after it causes them to lose money, damage their reputation, and disrupt operations. You might think that cybercriminals only go after big companies, but small businesses are often easier targets, and New Zealand SMBs are no exception. This is where cyber resilience comes in.
Having antivirus software is not enough to be cyber resilient. It’s about how well your business can prepare for, deal with, and bounce back from cyberattacks. It means building a defence system that not only stops threats but also gets you back on your feet quickly if a breach does happen. A cyber-resilient business keeps its data safe, keeps its customers’ trust, and protects its future.
This guide gives you a step-by-step plan for building your small business’s cyber resilience strategy, including where to report an incident and what New Zealand law requires if a breach happens. We’ll cover the most common threats you face, how to find your weaknesses, and the specific steps you can take to keep your business safe.
Understanding the small business threat landscape
You need to know what you’re up against before you can build a good defence. Small businesses are attractive targets because they often hold valuable customer and financial data without the same level of security as larger companies. Recent NCSC (New Zealand’s National Cyber Security Centre) reporting shows small and medium businesses continuing to experience sophisticated network and device compromises, so this isn’t a theoretical risk. Here are the threats you’re most likely to face.
Phishing attacks
Phishing remains one of the most common and dangerous cyber threats. These attacks use fake emails, text messages, or websites to trick employees into giving up private information like passwords, credit card numbers, or login credentials. Spear phishing takes this further, sending personalised messages targeting a specific person or company to make the attack look more convincing.
Malware
Malware, short for malicious software, covers a broad category of software designed to harm or exploit any programmable device or network:
- Viruses attach themselves to clean files and spread through a system, corrupting data and disrupting operations.
- Trojans disguise themselves as legitimate software. Once installed, they can create backdoors for other malware or steal information.
- Spyware monitors activity without your knowledge, gathering keystrokes, browsing history, and login credentials.
Ransomware
Ransomware locks up your files so you can’t access them, and attackers demand a ransom, usually in cryptocurrency, for the decryption key. There’s no guarantee you’ll get your data back if you pay, and paying can make your business a target for future attacks. A ransomware attack can completely halt a small business’s operations, causing significant financial and reputational damage.
Business Email Compromise (BEC)
In a BEC attack, a hacker sends an email pretending to be a trusted vendor or company executive, aiming to get an employee to transfer money or sensitive information without authorisation. These scams are advanced and often bypass standard security filters since they don’t contain links or attachments to flag.

Assessing your current security posture
You need to know where you stand before building a strong cyber resilience programme. A full risk assessment helps you identify your most valuable assets, what could go wrong, and how a cyber incident would affect your business.
Step 1: Identify your most important assets
Start by listing your most important assets. This isn’t just hardware, think about what your business needs to operate and what data, if compromised, would cause the most damage:
- Customer information (names, addresses, payment details)
- Employee records
- Bank accounts, company credit cards, and other financial information
- Intellectual property, including trade secrets and proprietary software
- Key business systems (e-commerce platforms, CRM, accounting software)
- Hardware (servers, laptops, mobile devices)
Step 2: Identify possible threats and weak spots
Once you know what you need to protect, consider the threats that could put these assets at risk, both external (like those listed above) and internal (employee mistakes or, rarely, malicious insiders). Ask yourself:
- Where is our sensitive data stored, and is it secure?
- Who has access to this information?
- Are our systems and software up to date?
- Do our staff know how to recognise a phishing attempt?
- What would happen if our main server went down?
Step 3: Analyse and prioritise risks
Not all risks carry equal weight. For each vulnerability you identify, assess how likely it is to be exploited and the potential impact on your business. This tells you what to tackle first. If a phishing attack on your finance team would cause major financial damage, staff training there should be a priority. A simple low, medium, high matrix works well for ranking risks by likelihood and impact.
Building your cyber resilience plan
With your risk assessment done, you can build a layered defence. A strong cyber security policy for a small business should include preventative controls, a clear incident response plan, and regular staff training.
Implement basic security controls
These are the non-negotiable technical foundations of your defence:
- Firewalls separate your internal network from the outside internet, monitoring and filtering traffic to block malicious connections.
- Antivirus and anti-malware software should run on all company devices and stay updated to catch new threats.
- Multi-factor authentication (MFA) adds a critical layer of protection by requiring a second verification step beyond a password. Enable it on all important systems, especially email and banking.
- Regular software updates close the security gaps attackers exploit most often. Set operating systems, browsers, and applications to update automatically wherever possible.
Build an incident response plan
You will have a cyber incident, it’s a matter of when, not if. An incident response plan is a written set of steps telling your team exactly how to respond to a breach, which keeps people calm and avoids the confusion that slows down an effective response. Your plan should cover:
- Identification: how you find and confirm a security breach.
- Containment: isolating affected systems quickly to stop the threat spreading.
- Eradication: removing the threat from your network.
- Recovery: restoring systems and data from backups.
- Post-incident review: understanding what happened and how to prevent it recurring.
Assign clear roles: who communicates with customers, who contacts your IT support or cybersecurity provider, and who reports the incident externally. Run drills so everyone knows the plan before they need it.
Know your legal obligations if a breach happens
Under the Privacy Act 2020, New Zealand businesses have a mandatory duty to notify the Office of the Privacy Commissioner, and affected individuals, of any privacy breach likely to cause serious harm. This isn’t optional guidance, it’s a legal requirement, and it should be built directly into your incident response plan rather than treated as an afterthought.
To report a cyber security incident, New Zealand individuals and small to medium businesses can go through the National Cyber Security Centre (NCSC) at ncsc.govt.nz/report or call 0800 114 115. NCSC absorbed the former CERT NZ reporting function in 2025, so if you’ve previously heard of CERT NZ, this is now where that reporting goes. Their Own Your Online platform is specifically aimed at individuals and small businesses looking for practical, plain-language security guidance.
Invest in staff training and awareness
Your employees can be your strongest defence or your biggest vulnerability. A proper cyber security training programme should run continuously, not as a one-off session, and should cover:
- Recognising phishing emails and suspicious links
- Creating strong, unique passwords
- Why data privacy and security matter for the business and its customers
- Safe use of company devices and networks, especially for remote workers
- Your company’s specific security policies and procedures
Use real-world examples and short quizzes to keep training engaging. Sending simulated phishing emails periodically, then giving immediate feedback, is one of the more effective ways to keep awareness sharp between formal sessions.
Set up backup and recovery plans
If you’re hit by ransomware, hardware failure, or a natural disaster, reliable backups are what keeps you operating. Follow the 3-2-1 rule:
- Keep at least three copies of your data.
- Store copies on two different types of media, such as a local drive and a cloud service.
- Keep one copy offsite, in the cloud or at a secure physical location.
Test your backups regularly to confirm you can actually restore from them. A backup you can’t restore is no backup at all.
Maintaining and improving your cyber resilience
Cyber resilience isn’t a one-off project, it’s an ongoing process that needs to keep pace with an evolving threat landscape.
- Regular security audits: review your controls, policies, and plans periodically, whether through internal review or an external vulnerability assessment.
- Stay current: follow the latest guidance from the NCSC and Own Your Online, which publish New Zealand-specific threat advisories and quarterly incident insights relevant to what local businesses are actually experiencing.
- Keep improving: use findings from audits, incident reviews, and staff feedback to refine your plan as your business and the threat landscape change.
Your path to a more secure business
Building cyber resilience can feel like a lot of work, but it’s a necessary investment in your company’s future. A structured approach, risk assessment, basic controls, staff training, and incident planning, significantly reduces your exposure.
Start small and manageable. Address your highest-priority risks first, then build out further defences over time. The goal isn’t to be unbreachable, it’s to be prepared, able to respond quickly, and able to recover. If you’re also working on your business’s broader resilience beyond cyber threats, our guide on building operational resilience covers the wider picture. And if you’re moving more of your operations online, our guide to going digital is worth reading alongside this one, since more digital infrastructure means more surface area to secure.
