The unglamorous security basics that stop most attacks

An iTops engineer working on infrastructure

Almost nothing we see in the wild is sophisticated. It's a reused password, an unpatched box, or a backup nobody tested. Here's the order we'd fix them in.

Security marketing has a bias towards the dramatic. Nation-state actors, zero-days, threat intelligence feeds. It makes for a compelling slide.

What we actually see, in New Zealand businesses, week after week, is considerably duller. Someone reused a password. A firewall sat three years past its replacement date. A backup ran nightly for eighteen months and had never once been restored from. None of it is sophisticated. All of it is preventable.

Here's the order we'd tackle it in, and roughly what each step involves.

1. Multi-factor authentication, everywhere

If you do one thing, do this. Not just email — VPN, remote access, your accounting platform, your line-of-business system, and every administrator account without exception.

The objection we hear is that it's disruptive. In practice, when it's rolled out properly with an authenticator app and a bit of communication beforehand, most people stop noticing within a fortnight. We've done this for law firms, engineering groups and 24/7 operations, and the disruption is consistently smaller than expected.

2. Know what you've got, and how old it is

You cannot patch what you don't know about. A proper inventory — every device, its configuration, its age, when it's due for replacement — sounds like housekeeping, and it is. It's also what turns security from a series of surprises into a budget line.

Nearly every serious problem we've been called into started with a device nobody was tracking.

3. Patch on a schedule, not on a scare

Monthly, monitored, reported. The point of a schedule isn't that it catches everything the moment it's published — it's that patching stops depending on whether someone happened to read the news that week.

4. Test the restore, not the backup

A backup job reporting success tells you a file was written. It tells you nothing about whether you can get your business back.

  • Restore something real, at least quarterly
  • Time it, and compare that against what the business assumes
  • Keep a copy somewhere the primary environment can't reach
  • Include email, chat history and cloud file storage — not just servers

That last point catches people out. Moving to Microsoft 365 or a similar platform doesn't remove your responsibility for the data in it. The platform is highly available; that isn't the same as backed up.

5. Replace the firewall before it retires you

Perimeter hardware has a service life, and running it past the point where it receives security updates is a decision, even if nobody made it deliberately. Modern firewalls fold in anti-malware and intrusion prevention, and a well-planned swap is a half-hour of downtime, not a weekend.

Not one of these steps is clever. Together they close off the overwhelming majority of what we see actually happening to New Zealand businesses.

6. Train people, then test the training

Social engineering doesn't care how good your firewall is. Short, regular awareness training paired with the occasional simulated phish tells you where you actually stand — and gives you something to measure improvement against.

Where an audit fits

If you're not sure which of these you've got covered, an audit is the fastest way to find out. Ours combines a structured checklist with penetration testing across networks, wireless, firewall and any internet-facing services, and comes back as a graded list of risks rather than a wall of output.

Most clients find the results reassuring in parts and uncomfortable in others. That's the point — you want to find the gaps before someone else does.

Questions this raises

What is the single most effective security control?

Multi-factor authentication, applied everywhere — email, VPN, remote access, your line-of-business systems and every administrator account without exception. It stops the great majority of what we actually see happening to New Zealand businesses.

How often should we test our backups?

Restore something real at least quarterly, and time it. A backup job reporting success only tells you a file was written; it tells you nothing about whether you can get the business back.

Related reading

Whether it’s taking care of your everyday IT needs or you have a challenge to solve, we can help.

Get in touch