Cybersecurity Made Simple: Real Attacks and How to Prevent Them
It all starts with something small - an ordinary looking email or a routine invoice. But for these NZ SMEs, small oversights led to devastating consequences.
$45,000 vanished: A convincing email looked like it came from their supplier - same logo, same tone, even the same email signature. But it wasn’t. And within 24 hours, $45,000 was gone….
A Million Dollar Invoice: It was a regular weekday when the monthly Microsoft invoice arrived. The bill was normally a few thousand dollars for this mid-size NZ business. But this invoice was different…. with an extra $1,000,000 of charges. A hacker had gained access to their setup and used it to mine cryptocurrency. The alerts had been ignored, leaving the business with the bill to pay…..
Files for Ransom: Without warning, staff couldn’t open any of their files or systems. A hacker had gained access to their environment using a leaked password and remained undetected for 10 days. Over a weekend, the hacker locked down all files and applications, and demanded a ransom payment…
These aren’t hypothetical scenarios; these are real life incidents that have hit New Zealand small and medium-sized enterprises (SMEs) hard.
These cases are not isolated incidents. Cybercriminals are increasingly targeting SMEs, viewing them as easier targets due to perceived weaker defences. According to NZ’s National Cyber Security Centre (NCSC),
Small businesses are the target for nearly half of all cybercrimes in New Zealand,
Incidents are costly, and the estimated cost of a data breach, for example, is $173,000
Few are ready, and less than half of small to medium businesses (SMEs) are prepared for a cyber incident
Total reported losses in NZ for Q4 2024 totalled NZD $6.8m.
“There’s a Kiwi issue of too much trust” says Mark Dyer, Managing Director of Mohawk Technology. “Some business owners think, “it won’t happen to us” while others see cyber security as optional. Businesses need to know that they are actively targeted, and the impact can be devastating”.
Without protection, businesses are wide open. And once a criminal is in, they take control and lock you out.
Reported Financial Loss in NZ from Cybercrime:
Quarter Four Cyber Security Insights 2024 | CERT NZ
PREVENTION
If your business uses Microsoft tools, you’re already in a strong position - provided they’re set up correctly. Microsoft M365 has over 1400 settings to safeguard your business, but these need to be properly configured to be effective. Many businesses mistakenly assume they’re automatically protected when, in reality, they are not.
To really understand your cyber risk, an independent security assessment is essential. Every business has weak spots - whether it’s a single minor issue or 25 critical risks, and an assessment helps you see exactly where you stand. And these assessments don’t have to cost a fortune. For small businesses, a quick check-up can be as affordable as a few hundred dollars.
Dyer explains just how often serious security problems go unnoticed: “We love helping small businesses understand their risk and improve their security. Many are shocked when we uncover critical risks unfixed for 18 years, CEOs with accounts being actively targeted but left unprotected, and basic security measures missing entirely. But once these risks are found and dealt with, the peace of mind is priceless.”
Fixing security problems not only protects your business - it can also help with cyber insurance. Insurers expect businesses to have safeguards like strong passwords, virus protection, and backup systems, which are easy steps that make a big difference.
Cybersecurity isn’t just about technology; it's about protecting your reputation, finances, and future. Dyer stresses the importance of regular security reviews. “Every business owner, board and executive team should understand their Cyber risk position. While eliminating risk entirely is impossible, managing it is essential",” he says. “Assuming you are safe is no different from waiting to be breached”.
Ready to protect your business? Start here
Mohawk Technology specialises in IT services for mid-size NZ companies, helping to simplify systems, reduce costs, and protect you against cyber threats. Discover seamless, secure technology that you can trust at www.mohawk.co.nz.