Guide & Govern
Someone owns cyber risk and staff know what good security looks like.
NCSC NZ-aligned · ISO/IEC 27001-informed
Cybertool turns recognised cyber-security guidance into ten plain-English questions for New Zealand SMEs, tradies and contractors. See what is working, what is missing and what to fix first—without needing to be an IT expert.
✓ NCSC five-function view ✓ ISO/IEC 27001:2022 risk thinking ✓ Designed for SMEs
BUILT FOR REAL-WORLD BUSINESS
The NCSC view—made practical
The NCSC Cyber Security Framework can be used by organisations in any sector. Cybertool turns its five functions into questions an owner can answer and actions a small team can manage.
Someone owns cyber risk and staff know what good security looks like.
Know the information, devices, accounts and services your business relies on.
Use secure settings, updates, MFA and sensible access controls.
Notice unusual activity early and know who will investigate it.
Have a short incident plan and backups you know can be restored.
What we do
You don’t need an enterprise-sized IT team to take cyber security seriously. We turn recognised good practice into clear, manageable actions for SMEs.
FREE ONLINE TOOL
Answer ten straightforward questions mapped to the NCSC NZ framework and informed by ISO/IEC 27001:2022. Receive a score and plain-language priority actions.
Start the free analysisADVISORY
A deeper, consultant-led review of your information security system, evidence and risks—with a practical improvement plan.
Discuss a reviewIMPLEMENTATION
Help to build the policies, risk register, asset controls, incident planning and staff awareness your business actually needs.
Get practical supportWhat you receive
The free check gives you an immediate score and practical starting priorities. It does not claim to certify your business or guarantee protection from an incident.
No technical knowledge or sensitive system details are needed.
Understand whether your foundations are strong or important protections need attention.
Start with practical controls such as MFA, backups, updates and an incident plan.
A sensible place to start
Cyber security can feel complicated. Our approach keeps it practical: understand what you have, identify the most important gaps and improve in manageable steps.
Complete the free Cybertool check to see where your business stands today.
Focus first on the gaps that could have the greatest impact on your operation.
Put sensible controls, policies and staff practices in place.
Check progress and keep your security current as the business changes.
Free 10-question check
Each question represents one of the NCSC's ten minimum security areas, simplified for an SME. It takes about three minutes and gives you an immediate place to start.
SELECT YES OR NOT YET — 0 OF 10 ANSWERED
Two frameworks · one simple pathway
The NCSC framework organises the practical cyber work. ISO/IEC 27001:2022 helps a business manage that work through risk ownership, objectives, evidence, review and continual improvement.
Cybertool uses the five functions—Guide and Govern, Identify and Understand, Prevent and Protect, Detect and Contain, and Respond and Recover—and simplifies the ten Minimum Cyber Security Standards for an SME starting point.
View the NCSC frameworkISO/IEC 27001 helps protect information from being seen by the wrong people, changed incorrectly or unavailable when needed. A deeper review can help an SME build risk, policy, evidence and improvement practices, but the free check is not certification.
View the ISO overviewNCSC's Minimum Cyber Security Standards were developed for GCISO-mandated government agencies, although other organisations may adopt them. Cybertool uses their ten practical topics as guidance; it does not claim government mandate, NCSC approval or full standards compliance.
The ten-point owner checklist
These ten topics mirror the NCSC minimum security areas in plain language. You do not need to implement government-level detail to begin—start with the risks and systems that matter most to your business.
Plain-English advice for SME owners
Scam prevention · 15 September 2026
A Kiwi scam-prevention pilot offers a practical lesson: check unusual payments before money moves, protect business email and know who to call if something goes wrong.
Read the articleAbout Cybertool
Cybertool is a New Zealand SME-focused service developed to make recognised information-security thinking easier to understand and act on. It combines the NCSC NZ framework's practical structure with ISO/IEC 27001:2022 management-system thinking.
Our goal is not to bury you in paperwork. It is to help you identify important information, assign responsibility, reduce common risks, prepare for incidents and review improvements over time.
Contact: safety1stconsultants@gmail.com · 021 222 5246
Privacy & data handling
Before you submit the contact form, the answers remain in your browser. If you choose to unlock the report, Cybertool stores your name, business, email, phone number, score and question responses so the result can be recorded and relevant support can be offered.
The check does not ask for passwords, account credentials or detailed system configurations. Do not send confidential access information by email. Using Cybertool does not make an organisation compliant with the Privacy Act, NCSC standards or ISO/IEC 27001.
Take the first step
Run the free check, or contact us for a deeper NCSC- and ISO/IEC 27001-informed review with a practical improvement plan.