IT Services
Managed Security
Continuous monitoring, threat detection and incident response, delivered by our security team so you can focus on your business.
Most businesses can't afford a full-time security operations team. Our managed security service gives you the protection of a dedicated SOC without the overhead, with real analysts monitoring your environment and responding to threats around the clock.
What's included
Our managed security service covers the full detection-to-response lifecycle.
- SIEM deployment and management (log collection, correlation and alerting)
- Endpoint detection and response (EDR) via Sophos or ESET
- Email security monitoring and anti-phishing controls
- Vulnerability scanning and patch compliance reporting
- Incident response: containment, investigation and remediation
- Monthly security reporting and executive briefings
Compliance support
We produce the evidence and documentation your business needs for regulatory and insurance requirements.
- Evidence packages for cyber insurance applications and renewals
- Compliance reporting aligned to NZISM, ISO 27001 and ASD Essential Eight
- Board-level security reporting and risk dashboards
Know what you are buying
Being told is not the same as being defended
Two services can both be called managed security, cost very different amounts, and differ in exactly one respect: whether anybody is authorised to act when the alert fires. That is the line worth finding in a quote before you compare the prices either side of it.
Alerting only
Detection and response
What arrives at 3am
Alerting only
An email or a ticket, addressed to you.
Detection and response
An analyst already working the incident, who tells you what they have done.
Who decides what to do
Alerting only
You do, once somebody reads the alert and works out what it means.
Detection and response
Agreed in advance and written down: a defined set of actions the provider may take without waking anybody.
Typical actions taken
Alerting only
None. The service has done its job when the alert is sent.
Detection and response
Isolate a machine from the network, disable an account, block a domain or file, stop a process, force a password reset.
What you still need in-house
Alerting only
Somebody on call, at any hour, who can read a security alert and act on it correctly.
Detection and response
Somebody reachable for the decisions that fall outside the agreed list, which is a far lighter on-call burden than reading every alert.
How it fails
Alerting only
Alerts arrive overnight and nobody is awake to read them. The detection worked and nothing happened.
Detection and response
Over-containment: a production server pulled off the network at month-end because something looked wrong. Worth agreeing exclusions for critical systems before you need them.
The vocabulary
Six acronyms, decoded
Every proposal in this market uses these, and they are not interchangeable. Knowing which layer a quote is actually pricing is most of the work of comparing two of them.
SIEM
Security information and event management
The log warehouse. It collects events from servers, firewalls, identity providers and cloud services into one place, and raises an alert when a combination of them looks wrong. Two things to know before signing: it is only as good as what you actually feed it, and licensing is usually priced by data volume, so scope drives cost.
EDR
Endpoint detection and response
Software on laptops and servers that watches how processes behave rather than matching files against a list of known bad ones. It can stop an action mid-flight and roll back what it changed. It is one of the controls cyber insurers ask about most consistently.
XDR
Extended detection and response
The same idea widened to take in email, identity and network signals as well as endpoints, so one coherent story gets assembled instead of three unrelated alerts landing in three places at once.
MDR
Managed detection and response
The people rather than the product. A team who watch the tooling above, decide which alerts matter, and act on the ones that do. This is the part that turns a detection into an outcome, and it is the part the cheaper quotes leave out.
SOC
Security operations centre
The team and the room they work in, physical or otherwise. When a provider says they run a 24/7 SOC, the question worth asking is whether that means a person is rostered overnight or a server is switched on overnight.
ATT&CK
The MITRE ATT&CK framework
A public catalogue of the techniques attackers actually use, maintained by MITRE. It matters commercially because it gives everyone the same vocabulary: a report that says which techniques were observed can be compared against another provider's, and against your own controls.
Why detection speed is a legal question
The clock starts when you find out
Breach notification is not discretionary on either side of the Tasman, and every deadline below runs from the moment you become aware, not from the moment the attacker got in. Mandiant put the global median dwell time at 14 days across its 2025 investigations, and 48 per cent of those intrusions were still first reported to the victim by somebody else. Detection time is the part of this you can shorten by spending money in advance.
New Zealand
Australia
The law
New Zealand
Privacy Act 2020, Part 6. Section 112 defines a notifiable privacy breach, section 114 sets the duty to report it.
Australia
Privacy Act 1988 and its Notifiable Data Breaches scheme. Ransomware payments sit separately, under the Cyber Security Act 2024.
What triggers it
New Zealand
A privacy breach you reasonably believe has caused, or is likely to cause, serious harm to someone.
Australia
An eligible data breach: unauthorised access to, unauthorised disclosure of, or loss of personal information, where serious harm to someone is likely.
The clock
New Zealand
Notify the Privacy Commissioner as soon as reasonably practicable, in the words of the Act. The OPC asks for it within 72 hours of becoming aware, and says explicitly that you should notify even if you are still investigating. Failing to notify without reasonable excuse is an offence carrying a fine of up to NZ$10,000.
Australia
Complete the assessment within 30 calendar days of becoming aware of grounds to suspect a breach. The OAIC treats that as a maximum, not a default.
Reporting the attack itself
New Zealand
Report to the National Cyber Security Centre, online at any hour or on 0800 114 115 between 7am and 7pm on weekdays. CERT NZ was absorbed into the NCSC on 23 July 2025 and its brand, website and 0800 number were all retired, so runbooks written before then send people to a number that no longer answers. Note the hours: the national line keeps business hours, and attacks do not.
Australia
Reporting an incident to the Australian Signals Directorate is voluntary for most businesses. Reporting a ransomware or extortion payment is not. Since 30 May 2025, a business turning over more than A$3 million a year, or responsible for a critical infrastructure asset, has 72 hours from making the payment to report it to the ASD.
General information, current at the time of writing, and not legal advice. Australian organisations should also note that the Australian Signals Directorate is consulting on replacing the Essential Eight with a broader Essentials series, grounded in the Information Security Manual, with Essentials for enterprise IT as its first chapter. The Department of Home Affairs moved from an education footing to active compliance and enforcement of the ransomware payment obligation in January 2026.
Before you sign anything
Six questions that separate the quotes
Every provider in this market describes itself in the same six words, so the brochure will not tell you much. These will, and they are worth asking of us as readily as of anybody else.
Who is actually awake?
Ask whether round-the-clock means an analyst rostered overnight, or automated alerting with somebody on call. Both are legitimate and they cost very different amounts, so the answer should be in the proposal rather than discovered during an incident.
What can you do without asking me?
Get the list in writing: isolate a machine, disable an account, block a domain. A service that cannot take any action without approval is an alerting service, whatever it is called on the invoice.
How fast, and measured from when?
A response time measured from when an analyst picks up the ticket is not the same as one measured from when the event happened. Ask which end of that gap the number refers to.
What is out of scope?
Ask which systems are not being watched, and write the list down. Unmonitored corners are where incidents get comfortable, and they are usually the oldest and least documented things you own.
How long is the evidence kept?
Logs roll over and get overwritten. Ask what the retention period is and whether it is long enough to reconstruct an incident for an insurer, a regulator or a dispute. Some intrusions sit undetected far longer than the median: Mandiant put its espionage and state-linked insider cases at 122 days.
Who writes the notification?
When the clock above starts running, somebody has to draft what goes to the regulator and to affected customers. Agree in advance whether that is you, us, or your lawyers, rather than negotiating it on the day.
FAQ
Questions we are asked most
Do we still need our own IT team?
How is this different from the antivirus we already have?
What does 24/7 actually mean in practice?
Will this satisfy our cyber insurer?
What happens in the first thirty days?
Protect your business around the clock
Talk to our security team about a managed security package for your organisation.