Skip to main content

IT Services

Managed Security

Continuous monitoring, threat detection and incident response, delivered by our security team so you can focus on your business.

Most businesses can't afford a full-time security operations team. Our managed security service gives you the protection of a dedicated SOC without the overhead, with real analysts monitoring your environment and responding to threats around the clock.

What's included

Our managed security service covers the full detection-to-response lifecycle.

  • SIEM deployment and management (log collection, correlation and alerting)
  • Endpoint detection and response (EDR) via Sophos or ESET
  • Email security monitoring and anti-phishing controls
  • Vulnerability scanning and patch compliance reporting
  • Incident response: containment, investigation and remediation
  • Monthly security reporting and executive briefings

Compliance support

We produce the evidence and documentation your business needs for regulatory and insurance requirements.

  • Evidence packages for cyber insurance applications and renewals
  • Compliance reporting aligned to NZISM, ISO 27001 and ASD Essential Eight
  • Board-level security reporting and risk dashboards

Know what you are buying

Being told is not the same as being defended

Two services can both be called managed security, cost very different amounts, and differ in exactly one respect: whether anybody is authorised to act when the alert fires. That is the line worth finding in a quote before you compare the prices either side of it.

What arrives at 3am

Alerting only

An email or a ticket, addressed to you.

Detection and response

An analyst already working the incident, who tells you what they have done.

Who decides what to do

Alerting only

You do, once somebody reads the alert and works out what it means.

Detection and response

Agreed in advance and written down: a defined set of actions the provider may take without waking anybody.

Typical actions taken

Alerting only

None. The service has done its job when the alert is sent.

Detection and response

Isolate a machine from the network, disable an account, block a domain or file, stop a process, force a password reset.

What you still need in-house

Alerting only

Somebody on call, at any hour, who can read a security alert and act on it correctly.

Detection and response

Somebody reachable for the decisions that fall outside the agreed list, which is a far lighter on-call burden than reading every alert.

How it fails

Alerting only

Alerts arrive overnight and nobody is awake to read them. The detection worked and nothing happened.

Detection and response

Over-containment: a production server pulled off the network at month-end because something looked wrong. Worth agreeing exclusions for critical systems before you need them.

The vocabulary

Six acronyms, decoded

Every proposal in this market uses these, and they are not interchangeable. Knowing which layer a quote is actually pricing is most of the work of comparing two of them.

SIEM

Security information and event management

The log warehouse. It collects events from servers, firewalls, identity providers and cloud services into one place, and raises an alert when a combination of them looks wrong. Two things to know before signing: it is only as good as what you actually feed it, and licensing is usually priced by data volume, so scope drives cost.

EDR

Endpoint detection and response

Software on laptops and servers that watches how processes behave rather than matching files against a list of known bad ones. It can stop an action mid-flight and roll back what it changed. It is one of the controls cyber insurers ask about most consistently.

XDR

Extended detection and response

The same idea widened to take in email, identity and network signals as well as endpoints, so one coherent story gets assembled instead of three unrelated alerts landing in three places at once.

MDR

Managed detection and response

The people rather than the product. A team who watch the tooling above, decide which alerts matter, and act on the ones that do. This is the part that turns a detection into an outcome, and it is the part the cheaper quotes leave out.

SOC

Security operations centre

The team and the room they work in, physical or otherwise. When a provider says they run a 24/7 SOC, the question worth asking is whether that means a person is rostered overnight or a server is switched on overnight.

ATT&CK

The MITRE ATT&CK framework

A public catalogue of the techniques attackers actually use, maintained by MITRE. It matters commercially because it gives everyone the same vocabulary: a report that says which techniques were observed can be compared against another provider's, and against your own controls.

Why detection speed is a legal question

The clock starts when you find out

Breach notification is not discretionary on either side of the Tasman, and every deadline below runs from the moment you become aware, not from the moment the attacker got in. Mandiant put the global median dwell time at 14 days across its 2025 investigations, and 48 per cent of those intrusions were still first reported to the victim by somebody else. Detection time is the part of this you can shorten by spending money in advance.

The law

New Zealand

Privacy Act 2020, Part 6. Section 112 defines a notifiable privacy breach, section 114 sets the duty to report it.

Australia

Privacy Act 1988 and its Notifiable Data Breaches scheme. Ransomware payments sit separately, under the Cyber Security Act 2024.

What triggers it

New Zealand

A privacy breach you reasonably believe has caused, or is likely to cause, serious harm to someone.

Australia

An eligible data breach: unauthorised access to, unauthorised disclosure of, or loss of personal information, where serious harm to someone is likely.

The clock

New Zealand

Notify the Privacy Commissioner as soon as reasonably practicable, in the words of the Act. The OPC asks for it within 72 hours of becoming aware, and says explicitly that you should notify even if you are still investigating. Failing to notify without reasonable excuse is an offence carrying a fine of up to NZ$10,000.

Australia

Complete the assessment within 30 calendar days of becoming aware of grounds to suspect a breach. The OAIC treats that as a maximum, not a default.

Reporting the attack itself

New Zealand

Report to the National Cyber Security Centre, online at any hour or on 0800 114 115 between 7am and 7pm on weekdays. CERT NZ was absorbed into the NCSC on 23 July 2025 and its brand, website and 0800 number were all retired, so runbooks written before then send people to a number that no longer answers. Note the hours: the national line keeps business hours, and attacks do not.

Australia

Reporting an incident to the Australian Signals Directorate is voluntary for most businesses. Reporting a ransomware or extortion payment is not. Since 30 May 2025, a business turning over more than A$3 million a year, or responsible for a critical infrastructure asset, has 72 hours from making the payment to report it to the ASD.

General information, current at the time of writing, and not legal advice. Australian organisations should also note that the Australian Signals Directorate is consulting on replacing the Essential Eight with a broader Essentials series, grounded in the Information Security Manual, with Essentials for enterprise IT as its first chapter. The Department of Home Affairs moved from an education footing to active compliance and enforcement of the ransomware payment obligation in January 2026.

Before you sign anything

Six questions that separate the quotes

Every provider in this market describes itself in the same six words, so the brochure will not tell you much. These will, and they are worth asking of us as readily as of anybody else.

Who is actually awake?

Ask whether round-the-clock means an analyst rostered overnight, or automated alerting with somebody on call. Both are legitimate and they cost very different amounts, so the answer should be in the proposal rather than discovered during an incident.

What can you do without asking me?

Get the list in writing: isolate a machine, disable an account, block a domain. A service that cannot take any action without approval is an alerting service, whatever it is called on the invoice.

How fast, and measured from when?

A response time measured from when an analyst picks up the ticket is not the same as one measured from when the event happened. Ask which end of that gap the number refers to.

What is out of scope?

Ask which systems are not being watched, and write the list down. Unmonitored corners are where incidents get comfortable, and they are usually the oldest and least documented things you own.

How long is the evidence kept?

Logs roll over and get overwritten. Ask what the retention period is and whether it is long enough to reconstruct an incident for an insurer, a regulator or a dispute. Some intrusions sit undetected far longer than the median: Mandiant put its espionage and state-linked insider cases at 122 days.

Who writes the notification?

When the clock above starts running, somebody has to draft what goes to the regulator and to affected customers. Agree in advance whether that is you, us, or your lawyers, rather than negotiating it on the day.

FAQ

Questions we are asked most

Do we still need our own IT team?
Yes, and the two do different jobs. Managed security watches for hostile activity and responds to it. Your IT team, in-house or ours, runs the environment: joiners and leavers, patching, backups, the day-to-day. Most of what makes an attack easy is ordinary operational hygiene, so the two need to talk to each other, which is simpler when they are the same supplier. See Managed IT
How is this different from the antivirus we already have?
Traditional antivirus compares files against a list of known bad ones, which works until an attacker uses something not on the list, or uses no file at all. Attackers increasingly work with tools already installed on the machine, which no signature will ever flag. Behavioural detection catches the activity rather than the file, and the managed part means somebody is looking at what it produces.
What does 24/7 actually mean in practice?
It should mean a human being is rostered and reachable at three in the morning on a public holiday, with the authority to act. It is worth asking directly, because the phrase is also used for automated alerting that simply runs overnight. Neither answer is wrong, but they are different products at different prices, and the difference only becomes visible during an incident.
Will this satisfy our cyber insurer?
It addresses what insurers ask about most: multi-factor authentication, endpoint detection and response, tested backups and patching discipline. We produce the evidence pack for applications and renewals. What we will not do is tell you it guarantees cover, because insurers differ, questions change year to year, and the answers are given by you rather than by us.
What happens in the first thirty days?
We inventory what you have and find the gaps, connect log sources and deploy endpoint agents, then agree the response authority in writing: what we may do without asking, what needs a call, and who that call goes to. Alerting is tuned during this period, because an untuned service produces noise that everyone learns to ignore, which is worse than no service at all. See Cybersecurity overview

Protect your business around the clock

Talk to our security team about a managed security package for your organisation.