The 10 Cyber Security Basics Every Business Should Have in Place

Many businesses assume cyber security requires expensive software and complex technology. The truth is that most cyber incidents happen because basic controls weren't in place.

According to both NZI Insurance and the National Cyber Security Centre, businesses can significantly reduce their exposure by focusing on a handful of cyber security fundamentals.

1. Protect Sensitive Information

Know what information you hold, who has access to it, and whether that access is genuinely required.

2. Secure Remote Access

With employees working from home, travelling or accessing systems remotely, secure access controls are more important than ever.

3. Control Portable Devices

USB drives, external hard drives and portable devices can introduce malware or create opportunities for sensitive information to leave the business.

4. Verify Payment Instructions

Business Email Compromise remains one of the most common causes of cyber-related financial loss. Always independently verify unusual payment requests before transferring funds.

5. Keep Software Updated

Cyber criminals often target known vulnerabilities. Regular updates and patching are among the most effective security measures available.

6. Use Strong Passwords and Multi-Factor Authentication

Strong passwords are important. Multi-factor authentication is even better.

Many major breaches still begin with compromised user credentials.

7. Maintain Anti-Virus Protection

Ensure all business devices have current security software installed and actively monitored.

8. Include Cyber Risks in Your Business Continuity Plan

Cyber incidents should be treated like any other major disruption, alongside natural disasters, power outages, or supplier failures.

9. Test Your Response Plan

Run exercises and simulations to understand how your business would respond following a cyber incident.

10. Invest in Staff Training

Your employees can be your greatest vulnerability or your strongest line of defence. Regular awareness training helps staff identify phishing emails, suspicious links, impersonation attempts and fraudulent requests.

Your People Matter More Than Your Technology

The National Cyber Security Centre continues to identify social engineering attacks as one of the most successful methods used by cyber criminals. Attackers are increasingly targeting people rather than technology. Because of this, every business should:

  • Train staff regularly

  • Review user permissions

  • Require multi-factor authentication

  • Establish clear reporting procedures

  • Test awareness through simulated phishing exercises

Take Action

How confident are you that your business could withstand a cyber attack? If you're unsure, now is the perfect time to review your cyber readiness.

For practical cyber security advice and tools, visit Own Your Online.

If you'd like guidance on managing cyber risks and understanding what protection may be available through cyber insurance, call one of our brokers on 0800 800 320

Previous
Previous

"We're Too Small for Cyber Insurance"

Next
Next

Cyber Threats Are No Longer Just an IT Problem. They're a Business Risk.