By Vaidik Patel, Cybersecurity Consultant, FUJIFILM CodeBlue:
Every few weeks, another major cyber attack makes headlines. Most of us read about a large global organisation being breached and assume cyber criminals are focused on bigger targets than our own businesses.
What rarely makes the news are the incidents happening much closer to home. The tradie whose invoicing system is frozen for a fortnight. The accounting firm locked out of its email system during tax season. The family business that pays a ransom and still struggles to recover. The GP clinic that loses access to sensitive patient information.
The reality is that cyber attacks are no longer just a problem for large organisations. They are affecting Kiwi businesses of all sizes. According to the National Cyber Security Centre (NCSC) Insights 2025 report, 53% of New Zealand SMEs experienced a cyber threat in the first six months of 2025, up from 36% the year before. Direct financial losses reported to the NCSC totalled $26.9 million last year. However, because reporting cyber incidents is not mandatory and many incidents go unreported, the NCSC estimates the true cost of cyber breaches in New Zealand could be as high as $1.6 billion.
Many business owners assume they're too small to be a target. In reality, smaller businesses are often targeted because they have valuable information, rely heavily on technology, and may not have the same resources or protections as larger organisations.
The question is no longer whether cyber attacks happen. It's whether your business would be ready to respond if one happened tomorrow.
There is no single solution, but there are practical steps every business can take to reduce risk, improve resilience, and put themselves in a stronger position before, during, and after an incident.
To protect your business, you first need to understand what matters most.
Think about your business operations. What would happen if you lost access to your email, accounting software, customer records, payment systems, or critical files? Which systems could you operate without, and which ones would bring the business to a standstill?
Every organisation is different. For a medical practice, patient information may be the most critical asset. For a tradie, it may be quoting, scheduling, and invoicing systems. For an accounting firm, it could be client records and email access.
Once you understand what's most important, you can focus your efforts on protecting those areas first.
Some practical steps every business should consider include:
Even with the best precautions in place, incidents can still occur.
The difference between a minor disruption and a major crisis often comes down to how quickly the issue is detected and how prepared you are to respond.
Most cyber attacks don't announce themselves. They happen quietly. The longer they go unnoticed, the greater the impact can be on your customers, staff, reputation, and operations.
Once the immediate threat has been contained, the focus shifts to recovery. For many businesses, the greatest cost is not the cyber attack itself. It's the disruption that follows. The inability to access systems, serve customers, process payments, or continue normal operations can have a significant impact on revenue and customer trust. That's why preparation is critical.
If you're unsure where to begin, start by asking three simple questions:
The answers will often reveal your biggest priorities.
Business Mentors New Zealand and CodeBlue invite you to a practical, jargon-free discussion designed specifically for business owners and business leaders.
You'll learn:
Register now here to secure your place.