Your business doesn't need to be famous to be targeted in a cyberattack

Aug 13, 2026, 1:31:16 PM

By Vaidik Patel, Cybersecurity Consultant, FUJIFILM CodeBlue:

Every few weeks, another major cyber attack makes headlines. Most of us read about a large global organisation being breached and assume cyber criminals are focused on bigger targets than our own businesses.

What rarely makes the news are the incidents happening much closer to home. The tradie whose invoicing system is frozen for a fortnight. The accounting firm locked out of its email system during tax season. The family business that pays a ransom and still struggles to recover. The GP clinic that loses access to sensitive patient information.

The reality is that cyber attacks are no longer just a problem for large organisations. They are affecting Kiwi businesses of all sizes. According to the National Cyber Security Centre (NCSC) Insights 2025 report, 53% of New Zealand SMEs experienced a cyber threat in the first six months of 2025, up from 36% the year before. Direct financial losses reported to the NCSC totalled $26.9 million last year. However, because reporting cyber incidents is not mandatory and many incidents go unreported, the NCSC estimates the true cost of cyber breaches in New Zealand could be as high as $1.6 billion.

Many business owners assume they're too small to be a target. In reality, smaller businesses are often targeted because they have valuable information, rely heavily on technology, and may not have the same resources or protections as larger organisations.

The question is no longer whether cyber attacks happen. It's whether your business would be ready to respond if one happened tomorrow.

There is no single solution, but there are practical steps every business can take to reduce risk, improve resilience, and put themselves in a stronger position before, during, and after an incident.

Before Something Goes Wrong

To protect your business, you first need to understand what matters most.

Think about your business operations. What would happen if you lost access to your email, accounting software, customer records, payment systems, or critical files? Which systems could you operate without, and which ones would bring the business to a standstill?

Every organisation is different. For a medical practice, patient information may be the most critical asset. For a tradie, it may be quoting, scheduling, and invoicing systems. For an accounting firm, it could be client records and email access.

Once you understand what's most important, you can focus your efforts on protecting those areas first.

Some practical steps every business should consider include:

  • Protect access to your critical systems: According to the Verizon 2025 Data Breach Investigations Report, 22% of breaches involved stolen or compromised credentials. A strong password combined with multi-factor authentication adds another layer of protection and makes it significantly harder for attackers to gain access to your systems, email, and business data.
  • Reduce the risk of fraudulent emails: Many cyber incidents start with a convincing email that tricks someone into clicking a malicious link, opening an attachment, or transferring money. Tools that identify and filter suspicious emails before they reach staff can significantly reduce this risk.
  • Prevent access to dangerous websites: A single click on the wrong website can lead to malware infections, stolen passwords, or unauthorised access to business systems. Blocking access to known malicious websites helps reduce the likelihood of a simple mistake becoming a major business problem.

When a Cyber Incident Happens

Even with the best precautions in place, incidents can still occur.

The difference between a minor disruption and a major crisis often comes down to how quickly the issue is detected and how prepared you are to respond.

Most cyber attacks don't announce themselves. They happen quietly. The longer they go unnoticed, the greater the impact can be on your customers, staff, reputation, and operations.

  • Detect problems early: Many attacks begin with a compromised account being used to access systems without anyone realising. Monitoring for unusual activity and suspicious behaviour can help identify an issue before it develops into a larger incident.
  • Have a response plan: When an incident occurs, decisions need to be made quickly. Who contacts your IT provider? Who informs staff? Who speaks to customers? Who contacts your bank, insurer, or legal adviser? Having a documented incident response plan means your team is not trying to answer these questions under pressure.

Getting Your Business Back on Track

Once the immediate threat has been contained, the focus shifts to recovery. For many businesses, the greatest cost is not the cyber attack itself. It's the disruption that follows. The inability to access systems, serve customers, process payments, or continue normal operations can have a significant impact on revenue and customer trust. That's why preparation is critical.

  • Consider cyber insurance: According to the NCSC, the average cost of a cyber incident for a New Zealand small or medium-sized business is estimated to be around $173,000. Few businesses can absorb that kind of unexpected cost without feeling the impact. Cyber insurance can provide both financial protection and access to specialist support when you need it most.
  • Have backups you can rely on: Backups are only useful if they work when you need them. Regularly testing your backups and ensuring they are separated from day-to-day systems gives your business a pathway to recovery if critical data is lost or encrypted.
  • Plan your communications: Following an incident, customers, staff, suppliers, insurers, and regulators may all expect updates. Having a communications plan helps ensure information is shared clearly and consistently, reducing confusion at a time when trust and transparency matter most.

Where Should You Start?

If you're unsure where to begin, start by asking three simple questions:

    • What information and systems are most critical to my business?
    • What would happen if I couldn't access them tomorrow?
    • Do I have a clear plan for how my business would respond?

The answers will often reveal your biggest priorities.

Join Our Complimentary Webinar

BMNZ CodeBlue Cybersecurity Webinar Header-3 (2)

Business Mentors New Zealand and CodeBlue invite you to a practical, jargon-free discussion designed specifically for business owners and business leaders.

You'll learn:

    • Why small and medium businesses are increasingly being targeted
    • What cyber incidents commonly look like in New Zealand
    • The impact cyber attacks can have on operations, finances, and reputation
    • Practical steps you can take to reduce risk
    • What to do in the critical hours following an incident

Register now here to secure your place.