The 10 Cyber Security Basics Every Business Should Have in Place
Many businesses assume cyber security requires expensive software and complex technology. The truth is that most cyber incidents happen because basic controls weren't in place.
According to both NZI Insurance and the National Cyber Security Centre, businesses can significantly reduce their exposure by focusing on a handful of cyber security fundamentals.
1. Protect Sensitive Information
Know what information you hold, who has access to it, and whether that access is genuinely required.
2. Secure Remote Access
With employees working from home, travelling or accessing systems remotely, secure access controls are more important than ever.
3. Control Portable Devices
USB drives, external hard drives and portable devices can introduce malware or create opportunities for sensitive information to leave the business.
4. Verify Payment Instructions
Business Email Compromise remains one of the most common causes of cyber-related financial loss. Always independently verify unusual payment requests before transferring funds.
5. Keep Software Updated
Cyber criminals often target known vulnerabilities. Regular updates and patching are among the most effective security measures available.
6. Use Strong Passwords and Multi-Factor Authentication
Strong passwords are important. Multi-factor authentication is even better.
Many major breaches still begin with compromised user credentials.
7. Maintain Anti-Virus Protection
Ensure all business devices have current security software installed and actively monitored.
8. Include Cyber Risks in Your Business Continuity Plan
Cyber incidents should be treated like any other major disruption, alongside natural disasters, power outages, or supplier failures.
9. Test Your Response Plan
Run exercises and simulations to understand how your business would respond following a cyber incident.
10. Invest in Staff Training
Your employees can be your greatest vulnerability or your strongest line of defence. Regular awareness training helps staff identify phishing emails, suspicious links, impersonation attempts and fraudulent requests.
Your People Matter More Than Your Technology
The National Cyber Security Centre continues to identify social engineering attacks as one of the most successful methods used by cyber criminals. Attackers are increasingly targeting people rather than technology. Because of this, every business should:
Train staff regularly
Review user permissions
Require multi-factor authentication
Establish clear reporting procedures
Test awareness through simulated phishing exercises
Take Action
How confident are you that your business could withstand a cyber attack? If you're unsure, now is the perfect time to review your cyber readiness.
For practical cyber security advice and tools, visit Own Your Online.
If you'd like guidance on managing cyber risks and understanding what protection may be available through cyber insurance, call one of our brokers on 0800 800 320

