Stories

Your business doesn’t need to be famous to be targeted in a cyber attack

Every few weeks, another major cyber attack makes headlines. Most of us read about a large global organisation being breached and assume cyber criminals are focused on bigger targets than our own businesses.

What rarely makes the news are the incidents happening much closer to home. The tradie whose invoicing system is frozen for a fortnight. The accounting firm locked out of its email system during tax season. The family business that pays a ransom and still struggles to recover. The GP clinic that loses access to sensitive patient information.

Vaidik Patel
Cybersecurity Consultant

This post was originally published on the Business Mentors New Zealand website.

Cyber attacks are affecting Kiwi businesses of all sizes, not just the larger ones. According to the National Cyber Security Centre (NCSC) Insights 2025 report, 53% of New Zealand SMEs experienced a cyber threat in the first six months of 2025, up from 36% the year before. Direct financial losses reported to the NCSC totalled $26.9 million last year. However, because reporting cyber incidents is not mandatory and many incidents go unreported, the NCSC estimates the true cost of cyber breaches in New Zealand could be as high as $1.6 billion.

Many business owners assume they’re too small to be a target. In reality, smaller businesses are often targeted because they have valuable information, rely heavily on technology, and may not have the same resources or protections as larger organisations.

It’s unquestionable that cyber attacks are a risk. The question now is whether your business would be ready to respond if one happened tomorrow.

There is no single solution, but there are practical steps every business can take to reduce risk, improve resilience, and put themselves in a stronger position before, during, and after an incident.

Before something goes wrong

To protect your business, you first need to understand what matters most.

Think about your business operations. What would happen if you lost access to your email, accounting software, customer records, payment systems, or critical files? Which systems could you operate without, and which ones would bring the business to a standstill?

Every organisation is different. For a medical practice, patient information may be the most critical asset. For a tradie, it may be quoting, scheduling, and invoicing systems. For an accounting firm, it could be client records and email access.

Once you understand what’s most important, you can focus your efforts on protecting those areas first.

Some practical steps every business should consider include:

  • Protect access to your critical systems: According to the Verizon 2025 Data Breach Investigations Report, 22% of breaches involved stolen or compromised credentials. A strong password combined with multi-factor authentication adds another layer of protection and makes it significantly harder for attackers to gain access to your systems, email, and business data.
  • Reduce the risk of fraudulent emails: Many cyber incidents start with a convincing email that tricks someone into clicking a malicious link, opening an attachment, or transferring money. Tools that identify and filter suspicious emails before they reach staff can significantly reduce this risk.
  • Prevent access to dangerous websites: A single click on the wrong website can lead to malware infections, stolen passwords, or unauthorised access to business systems. Blocking access to known malicious websites helps reduce the likelihood of a simple mistake becoming a major business problem.

When a cyber incident happens

Even with the best precautions in place, incidents can still occur.

The difference between a minor disruption and a major crisis often comes down to how quickly the issue is detected and how prepared you are to respond.

Most cyber attacks don’t announce themselves. They happen quietly. The longer they go unnoticed, the greater the impact can be on your customers, staff, reputation, and operations.

  • Detect problems early: Many attacks begin with a compromised account being used to access systems without anyone realising. Monitoring for unusual activity and suspicious behaviour can help identify an issue before it develops into a larger incident.
  • Have a response plan: When an incident occurs, decisions need to be made quickly. Who contacts your IT provider? Who informs staff? Who speaks to customers? Who contacts your bank, insurer, or legal adviser? Having a documented incident response plan means your team is not trying to answer these questions under pressure.

Getting your business back on track

Once the immediate threat has been contained, the focus shifts to recovery. For many businesses, the greatest cost is not the cyber attack itself. It’s the disruption that follows. The inability to access systems, serve customers, process payments, or continue normal operations can have a significant impact on revenue and customer trust. That’s why preparation is critical.

  • Consider cyber insurance: According to the NCSC, the average cost of a cyber incident for a New Zealand small or medium-sized business is estimated to be around $173,000. Few businesses can absorb that kind of unexpected cost without feeling the impact. Cyber insurance can provide both financial protection and access to specialist support when you need it most.
  • Have backups you can rely on: Backups are only useful if they work when you need them. Regularly testing your backups and ensuring they are separated from day-to-day systems gives your business a pathway to recovery if critical data is lost or encrypted.
  • Plan your communications: Following an incident, customers, staff, suppliers, insurers, and regulators may all expect updates. Having a communications plan helps ensure information is shared clearly and consistently, reducing confusion at a time when trust and transparency matter most.

Where should you start?

If you’re unsure where to begin, start by asking three simple questions:

  • What information and systems are most critical to my business?
  • What would happen if I couldn’t access them tomorrow?
  • Do I have a clear plan for how my business would respond?

The answers will often reveal your biggest priorities.

Business Mentors New Zealand and CodeBlue hosted a practical, jargon-free discussion designed specifically for business owners and business leaders.

In this webinar, you’ll learn:

  • Why small and medium businesses are increasingly being targeted
  • What cyber incidents commonly look like in New Zealand
  • The impact cyber attacks can have on operations, finances, and reputation
  • Practical steps you can take to reduce risk
  • What to do in the critical hours following an incident

Webinar: Understanding Cybersecurity from a business perspective

FAQs

Why are small businesses increasingly being targeted by cyber criminals?

Cyber criminals are often looking for organisations that have valuable data, financial information, customer records, or access to larger supply chains. Small and medium-sized businesses can be attractive targets because they may have fewer resources dedicated to cyber security, while still holding information that attackers can monetise or exploit.

What is the biggest cyber security risk facing New Zealand businesses today?

While threats continue to evolve, phishing emails, business email compromise, stolen credentials, and ransomware remain among the most common causes of cyber incidents. Many attacks begin with a single click, compromised password, or fraudulent email that appears legitimate.

If I could only do three things to improve my cyber security, what should I focus on?

For most businesses, the biggest improvements often come from: enabling multi-factor authentication on critical systems, reducing the risk of malicious emails reaching employees, and ensuring backups are regularly tested and recoverable. These foundational controls can significantly reduce risk and improve resilience if an incident occurs.

How do I know where my business is most vulnerable?

Start by identifying the systems, data, and processes your business relies on every day. Ask yourself: what would stop the business from operating, what information would cause the greatest damage if lost or exposed, or how would we respond if these systems became unavailable tomorrow? Understanding what is most critical to your business is the first step towards prioritising cyber security investments and resources.

What should I do if I suspect my business has suffered a cyber incident?

Time is critical. Contact your IT provider or cyber security partner immediately, contain affected systems if advised to do so, and begin documenting what has occurred. Having an incident response plan in place before an incident happens can significantly reduce confusion, disruption, and recovery time.

Does my business need cyber insurance?

Cyber insurance is becoming an important part of business risk management. A policy can help cover costs associated with forensic investigations, business interruption, legal support, notification requirements, and recovery activities following a cyber incident. However, insurance should complement, not replace, good cyber security practices.

How can CodeBlue help my organisation improve cyber resilience?

CodeBlue helps New Zealand organisations understand and manage cyber risk through advisory services, cyber security assessments, managed security services, incident response planning, and ongoing monitoring. Whether you're just getting started or looking to strengthen an existing cyber programme, our team can help you identify priorities and build a practical roadmap aligned to your business goals. Talk to a CodeBlue cyber security specialist to discuss your organisation's cyber security needs.