Cybercrime is in the news but what does that mean for your business?

High‑profile cyber incidents make the news because they’re disruptive, visible and unsettling. But for most businesses, the real value in these stories isn’t the headline, it’s the reminder that cyber risk is not theoretical… it’s here, it happens and it hurts.

Time to read: 6 mins

Below, our Taranaki Business Computing Services Team answers the most common questions business owners ask when incidents like these occur, and outline how a practical, managed approach to your IT can reduce both risk and impact. 

What do recent cyber incidents tell us?

They reinforce a simple truth: Even well‑established organisations can be affected. Cyber incidents don’t always stem from poor intent or negligence. They can arise from third‑party providers, legacy systems, misconfigurations or gaps that only become visible under pressure.

We’ve seen them in the news – organisations like Manage my Health, Waikato DHB, Mainfreight, Lamberts Business Systems, Latitude Financial, Qantas, Nissan or the James Pascoe Group (Farmers, Whitcoulls, Pascoes The Jewellers and Stewart Dawsons) – that experienced a significant cyberattack disrupting operations across stores. This impacted critical business systems like phones, payments and point of sale. Some of them were forced into cash-only mode, which is not ideal in today’s digital world.

The lesson for all of us isn’t blame – it’s preparedness. 

Do these types of risk apply to my business?

Yes, regardless of size or sector. Most cyber events are not targeted attacks. The attackers don’t actively choose you; they are opportunistic and use automated tools to scan, find and exploit known weaknesses. Smaller and mid‑sized organisations are often affected precisely because they rely on trusted systems and suppliers; and assume that those systems are “taken care of” or have a “she’ll be right” attitude.

Cyber risk sits quietly in the background… until it doesn’t. 

Is cyber risk just about my data?

No. Data is only one part of the picture. A cyber incident can affect:

  • Business operations and availability of systems
  • Customer trust and brand reputation
  • Regulatory or contractual obligations
  • Insurance coverage and claims processes

From a risk perspective, cyber events are increasingly viewed in the same category as fire, flood, or business interruption and not just an IT inconvenience. 

What needs to be protected? 

  • Customer information. This includes contact details, personal information, bank details and medical information.
  • Company records such as banking records, invoices and access to billing platforms.
  • Intellectual Property. This covers company and trade secrets, R&D projects and plans for growth that may give a competitor the edge if they were to get hold of your information. 

Where do businesses tend to be most exposed?

In our experience, exposure often sits in areas that feel quite routine:

  • User/staff access to systems that have never been reviewed
  • Reliance on passwords without added protections in place
  • Limited visibility over who monitors IT systems and any alerts
  • Assumptions by the wider team or management that “someone else” is responsible for maintaining the IT systems

These are not dramatic failures; they’re normal operational gaps that accumulate over time as people, systems and business focuses change. 

What role do people play in cyber risk?

A significant one. Many incidents begin with everyday actions: Clicking a link, opening an attachment, reusing the same (or a weak) password. This isn’t about blaming staff; it’s about recognising that hackers change their approach all the time with newer technologies and techniques. Therefore, your people need systems that support safe day-to-day behaviours and don’t rely on constant vigilance.

Training, testing, and simple safeguards like two-factor authentication (often called 2FA or MFA – Multi Factor Authentication) and password protectors like LastPass or Single Sign On (SSO) systems can reduce the likelihood that a single mistake becomes a major event.

Managed IT support services are not 100% foolproof, but if your business and livelihood sit squarely in the hands of someone who isn’t tech-savvy; then it’s an investment worth thinking about.

What does a ‘practical’ cyber approach look like?

A practical approach focuses on:

  • Reducing the likelihood of a cyber incident with tools and training
  • Limiting the impact of any incidences through having robust checks and systems in place
  • Ensuring recovery is quicker and clearer with protections and back-up controls

This doesn’t mean over‑engineering or over-investing. It means baseline controls, visibility and accountability; the same way businesses manage financial or operational risk. 

How do managed IT services help reduce cyber risk?

Managed services bring cyber risk into your day‑to‑day operations, rather than treating it as a one‑off project. It’s like having your very own in-house IT experts on hand 24/7, but without the staffing overheads.

Managed services teams can provide:

  • Consistent monitoring and maintenance of your systems
  • Day-to-day support for the big or small IT issues
  • Early identification of issues, and reporting of breaches or training requirements
  • Clear ownership of responsibility
  • Recommendations for cyber insurance options

Instead of reacting when something breaks, managed services help businesses stay ahead of cybersecurity issues that would otherwise go unnoticed. Instead of being an ambulance at the bottom of a cliff (cyber breach crisis), they’re a personal health trainer keeping you fit and healthy at all times. 

Where can our team add value?

Our Business Computing Services team (based in Taranaki but supporting clients nationwide) works with businesses that want clarity, not complexity.

Our role is to:

  • Assess where risk actually sits in your IT environment
  • Help prioritise what matters most
  • Support you with practical improvements over time
  • Be that regular voice to answer IT questions and concerns
  • Provide ongoing managed services that reduce reliance on ad‑hoc fixes

We understand that cyber risk must be balanced with cost, usability and business reality; not handled in isolation. 

Is cyber risk ever ‘finished’?

No, sadly not, but that’s okay. Cyber risk changes as businesses change. New staff, systems and suppliers all shift your risk profile. The goal isn’t perfection; it’s ongoing management, visibility and readiness. 

A calm next step

You don’t need to wait for a news headline to take cyber risk seriously.~If you want a clearer view of where your business stands and what a managed IT approach could look like, our Business Computing Services team can help.

From cyber assessments through to fully managed services, we focus on reducing risk before it becomes disruption. Reach out to Greg Taylor or Louis Fourie for a no-obligation chat about your unique cybersecurity or Managed IT Services needs.

DISCLAIMER No liability is assumed by Baker Tilly Staples Rodway for any losses suffered by any person relying directly or indirectly upon any article within this website. It is recommended that you consult your advisor before acting on this information.

Find a cybersecurity specialist

Sign up to our newsletter

Thanks for signing up!

Our website uses cookies to help understand and improve your experience. Please let us know if that’s okay by you.

Cookies help us understand how you use our website, so we can serve up the right information here and in our other marketing.