Learning Objectives
- Identify common small-business cyber risks.
- Improve account, access and email security controls.
- Strengthen backup, website and supplier risk practices.
- Draft a basic incident and continuity approach.
Implement high-impact cyber controls suitable for small businesses in New Zealand operating environments.
Small businesses are frequently targeted because resources are limited and controls may be inconsistent.
Practical baseline controls can significantly improve resilience and customer trust.
Small-business security starts with account hygiene, patching, backups, and clear staff process. Separate admin from standard access, apply MFA broadly, keep websites/plugins updated, and verify supplier requests. In NZ contexts, scam reporting and timely incident communication are important parts of response maturity.
To reduce risk of broad compromise during routine tasks or phishing events.
Independent verification of payment detail changes with a trusted contact process.
It helps business operations continue or recover faster during disruptions.