C://SECURE28Managed Cybersecurity
Security you can
actually evidence.
Managed cybersecurity for New Zealand organisations that need to show a customer, an insurer, or a board that their controls are real. Tools configured properly, monitored continuously, and reported in language a non-technical director can act on.
THE PROBLEM
Most organisations already own good security tools. Very few have them switched on properly.
Multi-factor authentication is bought but not enforced. The endpoint tool is installed but nobody reads its alerts. A licence bundle includes protections that were never enabled because turning them on required a decision nobody owned.
The gap is almost never budget. It is that security is somebody’s fourth priority, and controls decay quietly: a new starter added outside the process, an exception granted "temporarily" two years ago.
- 01You cannot answer a security questionnaireA customer asks how you control access and the honest answer is that you are not sure.
- 02Alerts go to an inbox nobody ownsDetection without response is just a record of what happened to you.
- 03Leavers keep their accessOffboarding is a conversation, not a checklist, so accounts linger.
- 04Your insurer is asking harder questionsRenewal now depends on controls you have not evidenced before.
WHAT YOU GET
Three layers of cover
Named for the layers of the earth, and built the same way. Each level is a complete posture rather than a partial one, and you move outward when your risk, your customers, or your insurer requires it.
BEST FOROrganisations putting a real security layer in place for the first time.
The layer closest to your people. Most attacks arrive through an inbox and succeed because of a reused password, so this is where the cheapest protection lives.
- Dark web monitoring for exposed staff credentials
- Email screening for phishing, spoofing, and impersonation
- Security awareness training for every staff member
- Simulated phishing campaigns, with coaching rather than blame
- Advanced antivirus and endpoint detection
- Extended detection and response (XDR)
- 24/7 monitoring and response
HOW WE WORK
Find the gaps, close them, prove it
Security work is only credible if you can show what changed. Every stage produces something you can hand to someone else.
- 01Week 1
Baseline
We assess what is configured today against a recognised framework and produce a gap list ranked by real-world risk, not by vendor score.
- 02Weeks 2 – 6
Remediate
We close the gaps in order of what buys the most safety fastest. Nearly always identity first, because it is where most breaches actually begin.
- 03Ongoing
Monitor
Detection is tuned to your environment so alerts mean something, and every alert has an owner. Noise is a security failure too.
- 04Quarterly
Evidence
A written posture report showing what changed, what it protects against, and what is still open. Usable for insurers, customers, and the board.
WHAT CHANGES
What good looks like
- Security questionnaires get answered from a document, not from memory.
- Every alert has a named owner and a recorded outcome.
- Leavers lose access the day they leave, automatically.
- Your insurer sees evidence rather than assurances.
FAQ
Questions we get asked
01What is EDR, and how is it different from antivirus?
Endpoint detection and response watches behaviour rather than matching known-bad files. Traditional antivirus asks "have I seen this file before?"; EDR asks "why is this ordinary program suddenly encrypting documents?" It also records what happened, which is what makes an incident investigable afterwards.
02We are small. Are we really a target?
Most attacks are not targeted. They are automated sweeps for exposed accounts and unpatched systems, and a small business with weak identity controls is cheaper to compromise than a large one. Being small changes your odds much less than most people assume.
03Which framework do you align to?
We work to a recognised baseline and map the controls to whatever your customers or insurer require, whether that is the NZISM, Essential Eight, CIS Controls, or an ISO 27001 programme. Ask us which one we are proposing for you and why.
04Do we need this if we already have Microsoft 365 Business Premium?
That licence includes most of the tooling, which is exactly the problem, because organisations pay for it and use a fraction of it. A large part of Core and Mantle is turning on and correctly configuring capability you are already buying.
05Will this slow our staff down?
Badly implemented security does. Well implemented security is mostly invisible: single sign-on, conditional access that only challenges unusual sign-ins, and device policies staff never see. If a control creates daily friction we look for a better control.
06What happens if we do get breached?
Assured includes a pre-scoped incident response retainer, which means we already hold the access and knowledge to act immediately. Foundation and Monitored clients get priority access to the same team on time and materials.
07How much should a small business spend on cyber security?
Less than most people fear, and the first tranche is the cheapest. Multi-factor authentication, correctly configured Microsoft 365 security, tested backups, and managed endpoint protection cover the large majority of realistic attacks, and much of that capability is already inside licences you hold. The expensive part is monitoring and response, and that is a step you take once the foundations are in rather than instead of them.
08We have done nothing so far. What should we do first?
Multi-factor authentication on every account, without exceptions, including administrators and service accounts. It is free with your existing licensing, it takes days rather than months, and it defeats the single most common attack there is. Then tested backups, then managed endpoint protection. In that order, and do not let a discussion about a security platform delay the first one.
09Our insurer or a customer wants evidence of our security controls. Can you help?
Yes, and it is one of the most common reasons organisations call us. We establish where you genuinely stand, close the gaps that matter to the questionnaire, and produce documented answers you can stand behind. Answering optimistically on an insurance proposal is a genuinely bad idea, because a claim can be declined on the basis of what you stated.
10Is our IT provider not already handling security?
Partly, and the gap is worth understanding rather than assuming either way. Most managed IT includes antivirus, patching, and backup, which are necessary and are not the whole picture. What is often missing is identity configuration, monitoring with someone actually watching, and the evidence an insurer or customer will ask for. Ask your provider specifically which of those they cover, and treat an unclear answer as an answer.
Start with a baseline.
We assess what you have configured today and give you a ranked gap list. It is useful on its own, whether or not you go further with us.
← All services