IT Services

Cybersecurity

Managed security services for NZ and Australian businesses. Protecting your people, data and systems before, during and after an attack.

Cyber threats are no longer a question of if, but when. We give businesses access to enterprise-grade security capabilities without the cost of an in-house security team.

Our security capabilities

Our team brings qualified security analysts, proven tooling and structured processes to protect your business.

  • Qualified security analysts and incident responders
  • Tooling and processes aligned to NIST and ISO 27001 frameworks
  • 24/7 monitoring and threat detection
  • Reporting and evidence packages for regulatory compliance

Who we protect

We work with businesses across sectors that handle sensitive data or face regulatory requirements.

  • Financial services and accounting firms
  • Healthcare and professional services
  • Government and public sector organisations
  • Media and entertainment companies (content pipeline security)
  • SMEs that need enterprise security without enterprise headcount

How we protect you

Six jobs, not one product

Protection is not a tool you switch on. We work to the six Functions of the NIST Cyber Security Framework, so every part of the job has an owner and nothing sits in the gap between them.

GVGovern

Decide what matters, in writing

Security decisions only hold if somebody owns them. We agree what you are protecting, who is accountable, what risk you are willing to carry and when it gets reviewed. This is also the layer insurers and enterprise customers ask to see, and the one most businesses have never documented.

IDIdentify

Know what you actually have

Every device, cloud tenancy, application and account with access to your data, including the ones nobody remembers creating. The gap between the environment people think they run and the one they actually run is exactly where attackers operate.

PRProtect

Close the gaps

Multi-factor authentication everywhere, patching that actually completes, admin rights removed from accounts that do not need them, managed devices, and backups tested rather than assumed. None of it is glamorous and all of it prevents the majority of incidents we are called about.

DEDetect

See it happening

Endpoint and identity telemetry feeds monitoring that runs continuously, so a compromised login at 2am is caught at 2am rather than found on Monday. Alerts are triaged by people, because a dashboard nobody is watching is not detection.

RSRespond

Act, with authority already agreed

Detection without response is an alarm nobody hears. Severity levels, escalation paths and who may isolate a machine are agreed in writing before monitoring goes live, alongside your notification obligations, so nobody is improvising at 3am on a Sunday.

RCRecover

Get you running again

Restoring from backups that have been restore-tested, confirming the intruder is actually out rather than merely quiet, and a written account of what happened. That record is what you hand to a board, a broker or a regulator afterwards.

The stack

What each layer is for

We are vendor-aligned rather than vendor-locked. The right tool depends on your environment, your existing licensing and what you already run well, so this is the shape of a typical deployment rather than a fixed bundle.

Endpoint protection

Stops and contains malicious software on laptops, desktops and servers, and isolates a machine that starts behaving badly.

Sophos, ESET

Identity and access

Proves people are who they claim to be before they reach anything, and removes that access the day they leave.

Duo, JumpCloud

Device management

Enforces encryption, patch level and configuration on every device, including the ones that never come into an office.

Hexnode, Mosyle

Network and edge

Filters hostile traffic before it reaches your systems and keeps services available when volume is the attack.

Cloudflare, Ubiquiti

Backup and recovery

Keeps a copy an attacker cannot reach or encrypt, and proves on a schedule that it actually restores.

Synology, Archiware

FAQ

Questions we are asked most

What does an MSSP do that our IT support does not?
IT support keeps things working. Security operations assume something has already gone wrong and go looking for it. The two need different tooling, different skills and, critically, different hours: a helpdesk runs during business hours, while intrusions are timed deliberately for evenings, weekends and public holidays. As a Managed Security Service Provider we run the monitoring, detection and response layer alongside whoever handles your day to day IT, including your existing provider. See Managed Security
We have antivirus and a firewall. Is that not enough?
It has not been enough for some years. Most breaches we are called about do not involve malware defeating antivirus. They involve a valid username and password being used by the wrong person, usually harvested through a convincing phishing page, with no second factor standing in the way. A firewall does not see that, and antivirus has nothing to scan. What catches it is identity monitoring and multi-factor authentication, which is why both sit at the front of every engagement we run.
How quickly do you respond to an incident?
Severity definitions, escalation paths and response commitments are agreed with you in writing before monitoring goes live, so both sides know exactly what happens at 3am on a Sunday and who holds the authority to isolate a machine. We would rather set that out specifically against your environment than quote a headline number that means very little in practice.
Do we still need penetration testing if you are monitoring us?
Yes, because they answer different questions. Monitoring tells you what is happening right now. A penetration test tells you what would happen if a capable attacker spent a week deliberately trying to get in. Testing on a regular cycle is also increasingly a condition of cyber insurance and of enterprise supplier onboarding, so many clients run one annually and again after any significant change to their environment. See Penetration Testing
What do we legally have to do if we have a breach?
Under the New Zealand Privacy Act 2020, if a privacy breach has caused or is likely to cause anyone serious harm, you must notify the Office of the Privacy Commissioner and the affected people as soon as you are practically able. There is no fixed number of days, which sounds lenient until you try to establish what was accessed, by whom and when. Australian businesses face a comparable duty under the Notifiable Data Breaches scheme. In both cases the practical requirement is logging and monitoring that already existed before the incident, not after it.

Ready to get started?

Talk to our team about how IT Services can help your business.