• About Us
  • Advertise with Us
  • Contact Us
  • Events
  • Newsletter
  • Podcasts
  • Digital Magazine
  • Home
  • News
  • Opinion
  • Entrepreneurship
  • Self Development
  • Growth
  • Finance
  • Marketing
  • Technology
  • Sustainability
  • About Us
  • Advertise with Us
  • Contact Us
  • Events
  • Newsletter
  • Podcasts
  • Digital Magazine
NZBusiness Magazine

Type and hit Enter to search

Linkedin Facebook Instagram Youtube
  • Home
  • News
  • Opinion
  • Entrepreneurship
  • Self Development
  • Growth
  • Finance
  • Marketing
  • Technology
  • Sustainability
NZBusiness Magazine
  • News
  • Opinion
  • Entrepreneurship
  • Self Development
  • Growth
  • Finance
  • Marketing
  • Technology
  • Sustainability
Technology

Time to test your business’s defences

Nilesh Kapoor explains how cyber harm can come to your business, what the threats look like, and offers a plan to shore up your online defences.

Glenn Baker
Glenn Baker
November 17, 2021 3 Mins Read
304

Almost every Kiwi business now has an online presence. Nilesh Kapoor talks you through exactly how harm can come to your business over the Internet, what those threats look like, and make a plan to shore up your online defences.

SMBs with less than 50 employees make up 95 to 97 percent of our economy. While we have plenty of billion-dollar organisations in this country, it could come as a surprise that often victims of damage delivered over the Internet might be an SMB such as your humble daycare centre, flower shop or Subway franchise. This occurs more frequently than the well-publicised attacks on Waikato DHB, NZX, NZ Post, Metservice and DOC.

We’re getting a few things wrong in our assumptions about Internet-based harm to businesses.

  • There isn’t always a human coordinating every attack. Some malware viruses have lived online for decades.
  • Penetration of your software doesn’t always mean money is stolen. Data of any kind can be copied, because hackers know you’ll give them around USD$150,000 to get it back.

Which companies are targeted for cyber attacks can seem quite random, though what all victims have in common is not investing in penetration testing to identify vulnerabilities.

We’re wrong to think it’s just big earners at risk of cyber attack. Even kindergartens can suffer.

Whānau Manaaki, the Free Kindergarten Association, were users of an IT management tool called VSA, provided by Kaseya. An attack on Kaseya in June 2021 harmed users worldwide and meant over 100 member kindergartens in New Zealand had to shut down their computers for a week. Penetration testing might have shown that VSA was making these kindergartens vulnerable, and the kindergartens could have chosen a better software provider.

Phishing causes more harm to Kiwi businesses than viruses. 

The most-reported incidents of cyber harm in New Zealand in 2021 were:

  • Phishing and credential harvesting – 50% of attacks.
  • Scams and fraud – 25% of attacks.
  • Unauthorised access – 13%.

Phishing often leads to ransomware. You’ll know ransomware when it invades because often you get a message saying your computer is now locked, and the message may give you a digital wallet to pay your ransom into. This happened to the small Auckland financial management business Staircase last Christmas.

This sort of attack often begins with an email urging you to open it. You open, and an exploit bursts into life within your computer meaning the hacker can now see inside your network. This happened to Waikato DHB in May 2021. Hackers copied then locked up data and when the DHB didn’t pay a ransom, confidential medical information was dumped on the dark web – inviting others to copy and exploit the data.

Password dumps are a feature of the Dark Web, too: one hacker will collect a tranche of passwords from businesses like yours, publish the passwords, and invite others to log in to the vulnerable business and wreak havoc. 

Cyber security advice for SMBs:

  • Remember that phishing (encouraging staff to open damaging emails) is the main way hackers victimise us – and it all starts with opening emails against our better judgement.  
  • Keep backups of all your data and records.
  • Consider having distributed network architecture.
  • If you receive a ransomware notification, disconnect, isolate, unplug and call an IT doctor.
  • Don’t pay any ransom. Payment doesn’t guarantee your data will be decrypted, and you’ll still likely need IT professional help. It may also open you up to future blackmail.
  • Keep your operating system and apps up-to-date.
  • Make sure you back up your files regularly to an external hard drive or cloud service.
  • Create an incident response plan including a plan for who to call for help, an action plan and a plan for communicating to colleagues and customers

 

Nilesh Kapoor is award-nominated cybersecurity expert and founder of Wellington-based of penetration testing service Blacklock.io and Security Simplified. He has worked to combat hacking threats to many New Zealand businesses.

Share Article

Glenn Baker
Follow Me Written By

Glenn Baker

Glenn is a professional writer/editor with 50-plus years’ experience across radio, television and magazine publishing.

Other Articles

Squarekicker
Previous

Complicated website coding no longer a barrier

Damon Kelly_Lo_Res Image
Next

Going global in a post-COVID environment

Next
Damon Kelly_Lo_Res Image
November 22, 2021

Going global in a post-COVID environment

Previous
November 17, 2021

Complicated website coding no longer a barrier

Squarekicker

Subscribe to our newsletter

NZBusiness Digital Issue – March 2025

READ MORE

The Latest

Step back to move forward – how Kiwi business owners can unlock growth

May 12, 2025

Samsung CSP: Leading the way in tech repairs across New Zealand

May 12, 2025

A business journey from surgeon to CEO

May 9, 2025

Entries open for 2025 Sustainable Business Awards

May 8, 2025

The new concrete flooring system that won’t end up in landfill

May 8, 2025

The business of saving lives

May 7, 2025

Most Popular

NZBusiness Digital Issue – June 2024
Understanding AI
Navigating economic headwinds: Insights for SME owners
Nourishing success: Sam Bridgewater on his entrepreneurship journey with The Pure Food Co
Navigating challenges: Small business resilience amidst sales decline

Related Posts

Samsung CSP: Leading the way in tech repairs across New Zealand

May 12, 2025

Cyber security in 2025: A guide on how to protect your business

April 22, 2025

A family business built on trust, now with the support of AI

April 18, 2025

Building cyber resilience: A practical guide for small businesses

April 15, 2025
NZBusiness Magazine

New Zealand’s leading source for business news, training guides and opinion from small businesses to multi-national corporations.

© Pure 360 Limited.
All Rights Reserved.

Quick Links

  • Advertise with us
  • Magazine issues
  • About us
  • Contact us
  • Privacy policy
  • Sitemap

Categories

  • News
  • Entrepreneurship
  • Growth
  • Finance
  • Education & Development
  • Marketing
  • Technology
  • Sustainability

Follow Us

LinkedIn
Facebook
Instagram
YouTube
  • Home
  • News
  • Opinion
  • Entrepreneurship
  • Self Development
  • Growth
  • Finance
  • Marketing
  • Technology
  • Sustainability