Skip to content
Practitioner guideVerified October 2026

Security Housekeeping for NZ SMEs: A Baseline Built on NCSC's Critical Controls

A practical security baseline for New Zealand small and medium businesses. Nineteen controls built on NCSC's Critical Controls, each with the first step, what done looks like, the evidence an insurer or auditor accepts, and a mapping to ISO/IEC 27001, SOC 2 and CIS Controls.

By Krish Pasumarthi, Founder, CybrGenCRISC, CEH, CDPSE

controls
19controls
NCSC Critical Controls
10/10NCSC Critical Controls
frameworks mapped
4frameworks mapped
day rollout
90day rollout

How to read each control

Owner tag
Who usually does the work: leadership, finance or your IT provider.
Do this first
The first concrete step, usually possible in a day.
Done looks like
A test you can check, not an aspiration.
Evidence produced
What an auditor, insurer or enterprise customer will accept.
Framework mapping
Where the control lands in NCSC, ISO/IEC 27001, SOC 2 and CIS Controls v8.1.
Watch out
The mistake we see most often in real environments.

Framework mappings are CybrGen's practitioner view of the most relevant clause, not an official crosswalk. NCSC reviews its Critical Controls every year, so check the current list. This guide is general information, not legal advice or an assessment of your environment.

Stage 01

1. Know what you have

What devices, software and suppliers can reach your data?

Every other control depends on this list. Start with what you own, what is past its supported life, and which suppliers hold your data or the keys to your systems.

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical Controls

Keep one register of devices, software and accounts

You cannot patch, protect or recover what you do not know you have. One register of laptops, phones, servers, network gear, cloud services and the software on them is the base every other control stands on.

Do this first
Export the device list from your device management tool or your Microsoft 365 or Google Workspace admin console, add servers and network gear by hand, and name an owner for each item.
Done looks like
Every device that can reach company data is in the register with an owner, and the register was reviewed in the last quarter.
Evidence produced
  • Asset register with owner and last-review date
  • Device management export
  • Quarterly review record
Framework mapping

NCSC Critical Controls

  • Asset lifecycle management

ISO/IEC 27001:2022

  • A.5.9 Inventory of information and other associated assets

SOC 2 (TSC)

  • CC6.1 Logical access security (asset inventory)

CIS Controls v8.1

  • 1.1 Enterprise asset inventory
  • 2.1 Software inventory
Watch out

A spreadsheet nobody updates is worse than none, because it gives false comfort. Tie the register to onboarding and offboarding so it stays current without a separate effort.

NCSC: Asset lifecycle management (opens in a new tab)

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Replace software and devices that no longer get security updates

End-of-life systems never get fixed. Old operating systems, unsupported firewalls and routers, and legacy line-of-business servers are a common way in, and NCSC calls out the moment a system moves from supported to legacy.

Do this first
Add an end-of-support date to every item in the asset register and flag anything already past it or due within 12 months.
Done looks like
No unsupported operating system, firewall or router is connected to the network, or each exception is isolated and has a signed replacement date.
Evidence produced
  • End-of-support report from the register
  • Replacement plan with dates and budget
  • Risk acceptance for any exception, signed by leadership
Framework mapping

NCSC Critical Controls

  • Asset lifecycle management
  • Patch your software and systems

ISO/IEC 27001:2022

  • A.8.8 Management of technical vulnerabilities

SOC 2 (TSC)

  • CC7.1 Detection of vulnerabilities

CIS Controls v8.1

  • 2.2 Authorised software is currently supported
Watch out

The risky device is often not a laptop but the edge firewall, VPN appliance or network storage box nobody logs into. Those face the internet and are scanned by attackers first.

NCSC: Asset lifecycle management (opens in a new tab)

Leadership

Know which suppliers and SaaS apps hold your data

Most SME data now lives in other people's systems: accounting, CRM, payroll, file sharing and IT support. A breach at a supplier is still yours to explain to customers.

Do this first
List every SaaS app and supplier with access to your systems or data. Use finance records and sign-in logs to find the ones nobody mentioned.
Done looks like
Each supplier has an owner, a note of what data it holds, whether MFA is on, and how you would get your data back if you left.
Evidence produced
  • Supplier and SaaS register
  • Due diligence notes for critical suppliers
  • Contract clauses on security and breach notice
Framework mapping

ISO/IEC 27001:2022

  • A.5.19 Information security in supplier relationships
  • A.5.23 Information security for use of cloud services

SOC 2 (TSC)

  • CC9.2 Vendor and business partner risk

CIS Controls v8.1

  • 15.1 Inventory of service providers
Watch out

Your IT provider usually holds the keys to everything. Treat them as your highest-risk supplier: confirm they use MFA, named accounts and logged access into your environment.

Stage 02

2. Lock down accounts

Could a stolen password alone get someone into email, the network or the bank?

Most SME incidents start with an account, not an exploit. MFA, unique passwords, separate admin accounts and prompt leaver removal close the door that attackers use most.

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Turn on MFA for email, remote access, admin and finance

NCSC describes enforcing multi-factor authentication as the most critical control for preventing unauthorised access. It stops most attacks that start with a stolen or guessed password.

Do this first
Enforce MFA in Microsoft 365 or Google Workspace for every user, starting with admins, then remote access (VPN and remote desktop), banking and accounting platforms.
Done looks like
No account that can read email, reach the network remotely or move money signs in with a password alone, and legacy sign-in methods that skip MFA are blocked.
Evidence produced
  • MFA registration report showing full coverage
  • Conditional Access or security defaults configuration
  • Exception list with an expiry date for each entry
Framework mapping

NCSC Critical Controls

  • Implement multi-factor authentication and verification

ISO/IEC 27001:2022

  • A.8.5 Secure authentication

SOC 2 (TSC)

  • CC6.1 Logical access security
  • CC6.6 Threats from outside the system boundary

CIS Controls v8.1

  • 6.3 MFA for externally exposed applications
  • 6.4 MFA for remote network access
  • 6.5 MFA for administrative access
Watch out

Text message codes are better than nothing but can be intercepted or SIM-swapped. Use an authenticator app or passkeys for admins and finance staff, and teach people to deny MFA prompts they did not start.

NCSC: Multi-factor authentication and verification (opens in a new tab)

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical Controls

Give everyone a password manager

People reuse passwords because remembering dozens is impossible. A business password manager makes long, unique passwords the easy option and gives you a safe home for accounts that cannot have individual logins.

Do this first
Roll out a business password manager to admins and finance first, and move shared accounts such as social media, supplier portals and Wi-Fi into shared vaults.
Done looks like
Shared credentials live only in the vault, nobody keeps passwords in spreadsheets or notebooks, and leavers lose vault access on their last day.
Evidence produced
  • Password manager adoption report
  • Shared vault list with owners
  • Password policy
Framework mapping

NCSC Critical Controls

  • Provide and use a password manager

ISO/IEC 27001:2022

  • A.5.17 Authentication information

SOC 2 (TSC)

  • CC6.1 Logical access security

CIS Controls v8.1

  • 5.2 Use unique passwords
Watch out

The vault is now your most valuable credential store. Protect it with MFA and agree a recovery process, or one lost phone can lock the business out.

NCSC: Password managers (opens in a new tab)

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Separate admin accounts and remove standing admin rights

If everyday accounts have admin rights, one phishing click becomes a full compromise. Admin work should happen from separate accounts that are never used for email or browsing.

Do this first
Remove local admin rights from staff laptops and give each IT admin a separate admin account with no mailbox, protected by the strongest MFA you have.
Done looks like
Global admin is held by a small named group (Microsoft recommends fewer than five), none of them use that account for email, and admin rights are reviewed every quarter.
Evidence produced
  • Privileged account list with owners
  • Quarterly privileged access review
  • Local admin removal report from device management
Framework mapping

NCSC Critical Controls

  • Enforce the principle of least privilege

ISO/IEC 27001:2022

  • A.8.2 Privileged access rights
  • A.5.15 Access control

SOC 2 (TSC)

  • CC6.3 Role-based access and least privilege

CIS Controls v8.1

  • 5.4 Restrict admin privileges to dedicated admin accounts
Watch out

Emergency break-glass accounts are fine, but they must be deliberate, monitored and tested. Forgotten ones become an attacker's favourite way back in.

NCSC: Principle of least privilege (opens in a new tab)

LeadershipNCSC top 10: One of NCSC NZ's current top ten Critical Controls

Remove access the day someone leaves

Former staff and contractors with live accounts are a quiet, common risk. Access should follow the person's role, and end when their role does.

Do this first
Write a one-page joiner, mover and leaver checklist covering email, SaaS apps, the password manager, building access and company devices, and have HR or the manager trigger it.
Done looks like
Every leaver in the last quarter has a completed checklist dated on or before their last day, and a quarterly review finds no active accounts for people who have left.
Evidence produced
  • Completed leaver checklists
  • Quarterly user access review sign-off
  • Account list reconciled to payroll
Framework mapping

NCSC Critical Controls

  • Enforce the principle of least privilege

ISO/IEC 27001:2022

  • A.5.18 Access rights
  • A.6.5 Responsibilities after termination or change of employment

SOC 2 (TSC)

  • CC6.2 User registration and removal
  • CC6.3 Role-based access and least privilege

CIS Controls v8.1

  • 6.1 Access granting process
  • 6.2 Access revoking process
  • 5.3 Disable dormant accounts
Watch out

SaaS apps outside single sign-on are where leavers keep access. Reconcile the supplier register against the leaver checklist so no app is missed.

Stage 03

3. Patch and harden

Are your systems current, configured safely and separated from each other?

Patch on a timeline you can prove, run protection that someone watches, and change the cloud and network defaults that favour convenience over safety.

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Patch on a clock, not when convenient

Many NCSC advisories concern vulnerabilities that already have a fix. A written timeline turns "we patch regularly" into something you can prove. Ours borrows the UK Cyber Essentials 14-day rule and ASD's 48-hour expectation for actively exploited internet-facing systems.

Do this first
Turn on automatic updates for operating systems, browsers and office apps, and set a written timeline for everything else, starting with internet-facing systems.
Done looks like
Internet-facing systems get critical fixes within 48 hours when exploitation is known, everything else within 14 days, and a monthly report shows it.
Evidence produced
  • Patch policy with timelines
  • Monthly patch compliance report
  • Vulnerability scan results with closure dates
Framework mapping

NCSC Critical Controls

  • Patch your software and systems

ISO/IEC 27001:2022

  • A.8.8 Management of technical vulnerabilities

SOC 2 (TSC)

  • CC7.1 Detection of vulnerabilities
  • CC8.1 Change management

CIS Controls v8.1

  • 7.1 Vulnerability management process
  • 7.3 Automated OS patch management
  • 7.4 Automated application patch management
Watch out

Firewalls, VPN appliances and routers are usually outside automatic patching and are the systems attackers scan for first. Give them a named owner and their own check.

NCSC: Patching (opens in a new tab)

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Run endpoint protection and control what can run

Endpoint detection and response (EDR) catches ransomware behaviour that signature antivirus misses. Application control goes further, letting only approved programs and file types run.

Do this first
Confirm every laptop and server runs managed EDR reporting to one console, then block macros in Office files from the internet and stop staff installing unapproved software.
Done looks like
The EDR console shows full coverage with no stale devices, alerts reach someone who acts on them, and new software needs a request.
Evidence produced
  • EDR coverage report
  • Alert handling record or managed service report
  • Software installation policy or allowlist
Framework mapping

NCSC Critical Controls

  • Implement application control

ISO/IEC 27001:2022

  • A.8.7 Protection against malware
  • A.8.19 Installation of software on operational systems

SOC 2 (TSC)

  • CC6.8 Prevention and detection of malicious software

CIS Controls v8.1

  • 10.1 Deploy and maintain anti-malware software
  • 2.5 Allowlist authorised software
Watch out

EDR with nobody watching the alerts is a smoke alarm in an empty building. If no one is on call, buy the managed version or route alerts to your IT provider with an agreed response time.

NCSC: Application control (opens in a new tab)

IT provider

Harden Microsoft 365 or Google Workspace

For most SMEs the cloud tenant is the network. Default settings favour convenience: legacy sign-in, open external sharing and automatic forwarding to personal mailboxes.

Do this first
In Microsoft 365, turn on security defaults or equivalent Conditional Access, block legacy authentication and disable automatic forwarding to external addresses. Apply the equivalent settings in Google Workspace.
Done looks like
Legacy authentication is blocked, external sharing is limited to named domains or expiring links, external auto-forwarding is off, and the admin console's security recommendations are reviewed monthly.
Evidence produced
  • Secure Score or security health report with trend
  • Exported tenant configuration
  • Monthly review notes
Framework mapping

ISO/IEC 27001:2022

  • A.8.9 Configuration management
  • A.5.23 Information security for use of cloud services

SOC 2 (TSC)

  • CC6.1 Logical access security
  • CC7.1 Detection of configuration changes

CIS Controls v8.1

  • 4.1 Secure configuration process
Watch out

Attackers who get into a mailbox often add a hidden rule that forwards or deletes finance emails. Check for unexpected inbox rules in every monthly review and at the start of any incident.

Microsoft Learn: Security defaults (opens in a new tab)

IT provider

Stop your domain being spoofed: SPF, DKIM and DMARC

Without these three DNS records, anyone can send email that appears to come from your domain to your customers and suppliers. They also help your genuine email reach inboxes.

Do this first
Publish SPF and DKIM for every service that sends as your domain, then a DMARC record in monitoring mode (p=none) with reporting turned on.
Done looks like
DMARC reports show every legitimate sender passing, and the policy has moved to quarantine or reject.
Evidence produced
  • DNS records for SPF, DKIM and DMARC
  • DMARC report summary
  • Change record for the move to enforcement
Framework mapping

ISO/IEC 27001:2022

  • A.5.14 Information transfer

CIS Controls v8.1

  • 9.5 Implement DMARC
Watch out

Jumping straight to p=reject breaks invoices and newsletters sent by your accounting, CRM or marketing platforms. Monitor for two to four weeks first.

Microsoft Learn: Set up DMARC (opens in a new tab)

IT provider

Encrypt and manage laptops and phones

A lost laptop holding personal information can become a notifiable privacy breach unless its disk is encrypted. Device management enforces encryption, screen lock and updates, and lets you wipe a lost device.

Do this first
Turn on BitLocker or FileVault on every laptop, store the recovery keys in your device management console, and require a passcode and remote wipe on phones that hold company email.
Done looks like
Device management reports every laptop encrypted and every phone with company data either enrolled or protected at app level.
Evidence produced
  • Encryption compliance report
  • Device enrolment report
  • Lost device procedure
Framework mapping

ISO/IEC 27001:2022

  • A.8.1 User endpoint devices
  • A.8.24 Use of cryptography

SOC 2 (TSC)

  • CC6.1 Logical access security
  • CC6.7 Restriction of data transmission and movement

CIS Controls v8.1

  • 3.6 Encrypt data on end-user devices
Watch out

Encryption without centrally stored recovery keys turns a forgotten PIN into permanent data loss. Escrow the keys before you enforce encryption.

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Separate guest, staff and critical systems on the network

On a flat network, one infected laptop can reach every server, camera and printer. Segments with rules between them limit how far an attacker can move.

Do this first
Put guest Wi-Fi, staff devices, servers and smart devices such as cameras, printers and building systems on separate networks, and allow only the traffic each one needs.
Done looks like
Guest Wi-Fi cannot reach internal systems, smart devices cannot reach servers, and remote desktop is not open to the internet.
Evidence produced
  • Network diagram showing segments and rules
  • Firewall rule export
  • External scan showing no exposed remote desktop
Framework mapping

NCSC Critical Controls

  • Implement network segmentation and separation

ISO/IEC 27001:2022

  • A.8.22 Segregation of networks
  • A.8.20 Networks security

SOC 2 (TSC)

  • CC6.1 Logical access security
  • CC6.6 Threats from outside the system boundary

CIS Controls v8.1

  • 12.2 Secure network architecture
Watch out

Remote desktop exposed to the internet remains a common ransomware entry point. Put it behind a VPN or gateway with MFA, or switch it off.

NCSC: Network separation and segmentation (opens in a new tab)

Stage 04

4. People and process

Would your team spot a fake invoice and say so straight away?

Two habits stop a large share of SME losses: reporting suspicious email quickly, and confirming any change to bank details with a phone call.

LeadershipNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Train people to spot phishing and to report it fast

Human behaviour features in many breaches. Short, regular training and a no-blame way to report mistakes beat an annual slide deck.

Do this first
Run a 20-minute session on phishing, payment fraud and how to report, and give everyone one obvious way to report a suspicious email.
Done looks like
New staff complete training in their first week, everyone refreshes at least yearly, and reported emails are acknowledged within a working day.
Evidence produced
  • Training completion records
  • Phishing simulation results, if you run them
  • Reported-email log
Framework mapping

NCSC Critical Controls

  • Build security awareness in your organisation

ISO/IEC 27001:2022

  • A.6.3 Information security awareness, education and training

SOC 2 (TSC)

  • CC1.4 Commitment to competence
  • CC2.2 Internal communication

CIS Controls v8.1

  • 14.1 Security awareness programme
  • 14.2 Recognising social engineering attacks
Watch out

Punishing people who click teaches them to stay quiet. Your fastest detection is a staff member who reports a mistake in the first five minutes.

NCSC: Build security awareness (opens in a new tab)

FinanceNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Verify any change to bank details by phone

Invoice and payment redirection fraud is a common and costly incident for small businesses. NCSC pairs MFA with verification for this reason. The fix is a process, not a product.

Do this first
Make it a rule that any new payee or change of bank details is confirmed by calling a number you already hold, never one in the email, and that urgent payment requests from executives get the same check.
Done looks like
The rule is in the payments procedure, a second person approves new payees and changes, and finance staff have practised refusing an urgent request.
Evidence produced
  • Payments procedure
  • Payee change log with call-back record
  • Dual approval settings in your banking platform
Framework mapping

NCSC Critical Controls

  • Implement multi-factor authentication and verification

ISO/IEC 27001:2022

  • A.5.3 Segregation of duties

CIS Controls v8.1

  • 14.2 Recognising social engineering attacks
Watch out

Fraudsters often reply from inside a genuine, compromised supplier mailbox, so the email will look completely legitimate. The call-back is the control that still works.

NCSC: Multi-factor authentication and verification (opens in a new tab)

Stage 05

5. Detect and respond

Would you know about an intrusion, and know who to call?

Logs you keep and alerts you read shorten incidents. A one-page plan means the first hour is spent responding, not finding phone numbers.

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical Controls

Turn on logs and alerts you will actually look at

NCSC notes that incidents reported to it often lack the detail to work out what happened. Logs collected in one place, with alerts for a handful of key events, make incidents shorter and cheaper.

Do this first
Confirm the Microsoft 365 or Google Workspace audit log is on, extend retention as far as your licence allows, and alert on new admin accounts, MFA changes, new forwarding rules and sign-ins from unexpected countries.
Done looks like
Cloud, firewall and endpoint logs land in one place, are kept for at least a year where your licence or tooling allows, and someone reviews alerts every working day.
Evidence produced
  • Log source list and retention settings
  • Alert rules
  • Alert review record
Framework mapping

NCSC Critical Controls

  • Centralised logging

ISO/IEC 27001:2022

  • A.8.15 Logging
  • A.8.16 Monitoring activities

SOC 2 (TSC)

  • CC7.2 Monitoring of system components

CIS Controls v8.1

  • 8.2 Collect audit logs
  • 8.9 Centralise audit logs
Watch out

Default log retention in cloud platforms can be shorter than the time it takes to notice an intrusion. Check what your licence keeps before you need it.

NCSC: Centralised logging (opens in a new tab)

LeadershipInsurer asks: Commonly asked on SME cyber insurance proposal forms

Write a one-page incident plan with phone numbers

In the first hour of an incident, people need to know who decides, who to call and what not to touch. One page that people can find beats a long policy that nobody can.

Do this first
Write one page covering who leads, how to reach your IT provider, insurer incident line, bank and lawyer out of hours, and when to report to NCSC and the Privacy Commissioner. Keep a printed copy.
Done looks like
The plan names a decision-maker and a deputy, every number has been tested, and the plan can be reached if email is down.
Evidence produced
  • Incident response plan with version date
  • Contact list test record
  • Incident log template
Framework mapping

ISO/IEC 27001:2022

  • A.5.24 Incident management planning and preparation
  • A.5.26 Response to information security incidents

SOC 2 (TSC)

  • CC7.3 Evaluation of security events
  • CC7.4 Incident response

CIS Controls v8.1

  • 17.1 Designate incident handling personnel
  • 17.2 Incident reporting contacts
  • 17.3 Incident reporting process
Watch out

Read your cyber insurance policy before you need it. Some policies require you to call the insurer's incident line first and use its panel providers, and acting alone can affect cover.

NCSC: Report a cyber security issue (opens in a new tab)

Stage 06

6. Recover

If everything were encrypted tomorrow, how long until you trade again?

A backup attackers cannot touch, a restore you have timed, and a rehearsal with the people who make the decisions.

IT providerNCSC top 10: One of NCSC NZ's current top ten Critical ControlsInsurer asks: Commonly asked on SME cyber insurance proposal forms

Keep an offline backup and prove you can restore it

Ransomware goes after backups first. A copy attackers cannot reach or change, and a restore you have actually tested, decide whether an incident costs days or the business.

Do this first
Follow 3-2-1: three copies, on two types of storage, one offline or immutable. Include SaaS data such as Microsoft 365 or Google Workspace, because platform retention and recycle bins are not a backup you control.
Done looks like
A full restore of a critical system was tested in the last six months and written up, and the backup console uses a separate account protected by MFA.
Evidence produced
  • Backup policy and schedule
  • Restore test record with date and duration
  • Immutable or offline storage configuration
Framework mapping

NCSC Critical Controls

  • Implement and test backups

ISO/IEC 27001:2022

  • A.8.13 Information backup

SOC 2 (TSC)

  • A1.2 Recovery infrastructure and backups
  • A1.3 Recovery plan testing

CIS Controls v8.1

  • 11.2 Perform automated backups
  • 11.4 Isolated instance of recovery data
  • 11.5 Test data recovery
Watch out

A backup that has never been restored is a hope, not a control. Time the restore too: if it takes four days and the business can survive two, you have found a gap before an attacker did.

NCSC: Implement and test backups (opens in a new tab)

Leadership

Rehearse a bad day once a year

A 90-minute tabletop exercise, walking leadership through a realistic ransomware or payment fraud scenario, finds the gaps in the plan, the contacts and the backups before an attacker does.

Do this first
Pick the scenario that would hurt most, such as ransomware on the file server or a hijacked finance mailbox, and walk the leadership team through the first 24 hours with the incident plan in hand.
Done looks like
An exercise ran in the last 12 months, the gaps found have owners and dates, and the incident plan was updated afterwards.
Evidence produced
  • Exercise scenario and attendance
  • After-action report with actions
  • Updated incident plan
Framework mapping

ISO/IEC 27001:2022

  • A.5.29 Information security during disruption
  • A.5.30 ICT readiness for business continuity

SOC 2 (TSC)

  • CC7.5 Recovery from security incidents
  • CC9.1 Business disruption risk mitigation

CIS Controls v8.1

  • 17.7 Routine incident response exercises
Watch out

Exercises that only involve IT miss the hard decisions. Include whoever would speak to customers, the bank and the insurer.

Cyber insurance

What insurers usually ask, and the control that answers it

Proposal forms differ by insurer and change at each renewal. These questions commonly appear on SME forms, and each one maps to a control in this guide.

Common cyber insurance proposal questions and the control in this guide that answers each
Is MFA enforced for email, remote access and privileged accounts?Turn on MFA for email, remote access, admin and finance
Are backups kept offline or immutable, and when did you last test a restore?Keep an offline backup and prove you can restore it
How quickly do you apply critical security patches?Patch on a clock, not when convenient
Do you run endpoint detection and response on all devices?Run endpoint protection and control what can run
Do you run any software or systems that are no longer supported?Replace software and devices that no longer get security updates
How do you verify requests to change a payee's bank details?Verify any change to bank details by phone
Are administrator rights restricted and separate from everyday accounts?Separate admin accounts and remove standing admin rights
Do staff receive regular security awareness or phishing training?Train people to spot phishing and to report it fast
Do you have a documented incident response plan?Write a one-page incident plan with phone numbers
Is remote desktop exposed to the internet?Separate guest, staff and critical systems on the network

Answering yes when a control is only partly in place can put cover at risk at claim time. Answer for the control as it actually operates, and keep the evidence listed on each card.

Week 1 / 30 / 90

A 90-day rollout that ends in evidence

  1. Week 1

    Phase 1: Quick wins

    1. 1.Enforce MFA for email, admins, remote access and finance platforms
    2. 2.Turn on automatic updates for operating systems, browsers and office apps
    3. 3.Adopt the call-back rule for any change to bank details
    4. 4.Confirm the cloud audit log is on and add alerts for admin and MFA changes
    5. 5.Publish a DMARC record in monitoring mode
    6. 6.Write the one-page incident plan and print it

    Exit criteria

    Every account that touches email, remote access or money uses MFA, and everyone knows who to call.

  2. Days 8 to 30

    Phase 2: Close the big gaps

    1. 1.Build the asset and supplier registers with owners
    2. 2.Remove local admin rights and create separate admin accounts
    3. 3.Roll out a business password manager, admins and finance first
    4. 4.Check EDR coverage and who responds to alerts
    5. 5.Block legacy authentication and external auto-forwarding
    6. 6.Run and time a restore of one critical system

    Exit criteria

    One register, admin rights under control, and a restore you have timed.

  3. Days 31 to 90

    Phase 3: Make it stick

    1. 1.Replace or isolate unsupported systems, with dated plans for the rest
    2. 2.Separate guest, staff, server and smart-device networks
    3. 3.Move DMARC to quarantine or reject
    4. 4.Adopt the leaver checklist and a quarterly access review
    5. 5.Run awareness training and agree a no-blame reporting route
    6. 6.Hold a 90-minute tabletop exercise and update the plan

    Exit criteria

    Evidence for every control on this page, and a quarterly review in the diary.

Field notes

Common pitfalls

  • Buying tools before switching on what you own

    Many SMEs already pay for MFA, audit logs and, on some plans, endpoint protection, and have not turned them on. Check your licence before you buy.

  • Treating the IT provider as the control

    Outsourcing IT does not outsource accountability. Ask your provider for the evidence listed on each card, not a verbal assurance.

  • MFA exceptions that never expire

    The account excluded temporarily for a scanner, a legacy app or a senior executive is the one attackers find. Give every exception an end date.

  • Backups on the same network

    A backup drive that is always connected, or a backup console using a normal admin account, is encrypted along with everything else.

  • A policy without a practice

    Insurers, auditors and enterprise customers increasingly ask for evidence, not documents. A patch policy needs a patch report behind it.

  • Forgetting the edge devices

    Firewalls, VPNs and network storage face the internet, are rarely patched automatically and are heavily targeted. Give each one a named owner.

One control set

Answer once, satisfy many

Every control on this page is mapped to the frameworks your customers, insurers and auditors use. Build the baseline once and reuse the evidence.

How far this baseline takes you against each framework
NCSC Critical Controls (New Zealand)Covers all ten current Critical Controls.
CIS Controls v8.1Covers a substantial share of Implementation Group 1, which CIS describes as essential cyber hygiene.
ISO/IEC 27001:2022Covers many Annex A technological and people controls. Certification also needs the management system: scope, risk assessment, Statement of Applicability, internal audit and management review.
SOC 2Supports much of the logical access and system operations criteria (CC6 and CC7). A report also needs governance, risk assessment, change management and evidence over a period, examined by an independent CPA firm.
UK Cyber EssentialsAligns with all five technical themes: firewalls, secure configuration, security update management, user access control and malware protection.
Australia's Essential EightTouches all eight strategies. Reaching Maturity Level One still needs the specific settings and timeframes in ASD's maturity model, such as Office macro and application hardening settings.

The efficient pattern is one control set: implement a control once, map it to every framework you answer to, and keep the evidence in one place so renewals and customer questionnaires take hours, not weeks.

Regional overlays

Where the baseline lands in NZ, Australia and the UK

New Zealand

Guidance-led, with a binding privacy breach duty

  • NCSC's Critical Controls are reviewed every year against the incidents NCSC sees, and are the closest thing to an official baseline for NZ organisations.
  • Privacy Act 2020: IPP 5 requires reasonable security safeguards for personal information. A notifiable privacy breach, one likely to cause serious harm, must be reported to the Privacy Commissioner and affected people as soon as practicable. The Commissioner expects notification within 72 hours of knowing a breach is notifiable.
  • Cyber incidents can be reported to NCSC online, by IT specialists for an organisation or by small businesses directly.
  • Own Your Online, from NCSC, offers a free business security assessment tool and plain-language guides for small businesses.
  • The Cyber Security Strategy 2026 to 2030 signals a regulatory regime for critical infrastructure. Suppliers to those operators are likely to see security requirements flow down through contracts.

Australia

Essential Eight as the practical baseline; NDB scheme for breaches

  • ASD's Essential Eight: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication and regular backups.
  • The November 2023 maturity model remains current. ASD consulted in mid-2026 on evolving it into a broader Essentials series, with a transition expected over about two years.
  • Where a vulnerability in an internet-facing service is being actively exploited, ASD expects a patch within 48 hours.
  • The Notifiable Data Breaches scheme requires organisations covered by the Privacy Act 1988 to notify the OAIC and affected individuals of eligible data breaches. Many small businesses are exempt, with exceptions, so confirm whether you are covered.

United Kingdom

Cyber Essentials as the entry certification; UK GDPR for breaches

  • Cyber Essentials covers five technical themes: firewalls, secure configuration, security update management, user access control and malware protection.
  • Requirements v3.3 require critical and high-risk updates within 14 days of release, and MFA for every cloud service.
  • Cyber Essentials is required for some UK government contracts that handle personal information.
  • Under UK GDPR, personal data breaches that pose a risk to individuals must be reported to the ICO within 72 hours of becoming aware of them.
FAQ

Questions we get asked

What is the minimum cyber security a New Zealand small business should have?

Start with NCSC's ten Critical Controls: patching, MFA and verification, a password manager, centralised logging, security awareness, asset lifecycle management, tested backups, application control, least privilege and network segmentation. Then close the common SME gaps around them: supplier access, cloud tenant settings, email spoofing protection, device encryption, leaver access, payment verification and a one-page incident plan.

What are the NCSC Critical Controls?

They are NCSC New Zealand's top ten controls, reviewed every year against the incidents reported to it. NCSC says that, when correctly implemented, they would prevent, detect or contain most of the attacks it sees. The current list covers patching, MFA and verification, password managers, centralised logging, security awareness, asset lifecycle management, backups, application control, least privilege and network segmentation.

Do I have to report a cyber incident in New Zealand?

If personal information is involved and the breach is likely to cause serious harm, the Privacy Act 2020 requires you to notify the Privacy Commissioner and affected people as soon as practicable. The Commissioner expects this within 72 hours of knowing the breach is notifiable. Reporting a cyber incident to NCSC is encouraged, and contracts or insurance policies may set their own notice requirements.

Is Microsoft 365 data backed up automatically?

Microsoft 365 keeps deleted items and versions for limited periods, but that is not the same as a backup you control. If ransomware, a malicious insider or a sync error damages data, you need your own copy with its own retention. Treat Microsoft 365 and Google Workspace like any other system in your backup plan.

Will these controls get us cyber insurance?

They answer the questions most SME proposal forms ask, which strengthens your position, but insurers make their own underwriting decisions. Answer each question for the control as it actually operates, and keep the evidence listed on each card for renewals and claims.

How long does this baseline take for a 20 to 200 person business?

With an IT provider engaged, the quick wins take about a week and the full baseline about 90 days, as set out in the rollout plan. Replacing unsupported systems and separating networks usually take longest because they need budget and downtime.

Is this enough for ISO 27001 or SOC 2?

It is a strong start, not the finish. Both need a management layer on top: defined scope, risk assessment, policies and internal review, and for SOC 2 an examination by an independent CPA firm over a period of time. The controls and evidence here carry straight into either programme.

Want a second pair of eyes on your baseline?

CybrGen runs fixed-scope cyber insurance readiness reviews and external penetration tests for New Zealand businesses, scored against this baseline, so you finish with a prioritised fix list and the evidence your insurer and customers will accept.