NCSC NZ-aligned · ISO/IEC 27001-informed

Five clear areas.
One practical starting point.

Cybertool turns recognised cyber-security guidance into ten plain-English questions for New Zealand SMEs, tradies and contractors. See what is working, what is missing and what to fix first—without needing to be an IT expert.

✓ NCSC five-function view   ✓ ISO/IEC 27001:2022 risk thinking   ✓ Designed for SMEs

✓
GOVERNOwn the risk
IDENTIFYKnow what matters
PROTECTReduce exposure
Detect · respond · recover

BUILT FOR REAL-WORLD BUSINESS

NCSC NZ-alignedFive functions and ten security basics
ISO/IEC 27001-informedRisk, ownership and continual improvement
Plain-English outputNo certification claim or technical overload

The NCSC view—made practical

Cyber security in five business conversations.

The NCSC Cyber Security Framework can be used by organisations in any sector. Cybertool turns its five functions into questions an owner can answer and actions a small team can manage.

01

Guide & Govern

Someone owns cyber risk and staff know what good security looks like.

02

Identify & Understand

Know the information, devices, accounts and services your business relies on.

03

Prevent & Protect

Use secure settings, updates, MFA and sensible access controls.

04

Detect & Contain

Notice unusual activity early and know who will investigate it.

05

Respond & Recover

Have a short incident plan and backups you know can be restored.

What we do

Cyber security that fits your business.

You don’t need an enterprise-sized IT team to take cyber security seriously. We turn recognised good practice into clear, manageable actions for SMEs.

01

FREE ONLINE TOOL

Cybertool Starter Check

Answer ten straightforward questions mapped to the NCSC NZ framework and informed by ISO/IEC 27001:2022. Receive a score and plain-language priority actions.

Start the free analysis
YOUR READINESSClear next steps
02

ADVISORY

ISO/IEC 27001 Gap Review

A deeper, consultant-led review of your information security system, evidence and risks—with a practical improvement plan.

Discuss a review
03

IMPLEMENTATION

Policies & Risk Support

Help to build the policies, risk register, asset controls, incident planning and staff awareness your business actually needs.

Get practical support

What you receive

A useful result—not a sales mystery.

The free check gives you an immediate score and practical starting priorities. It does not claim to certify your business or guarantee protection from an incident.

01

Answer 10 plain-English questions

No technical knowledge or sensitive system details are needed.

02

See your readiness result

Understand whether your foundations are strong or important protections need attention.

03

Act on the gaps

Start with practical controls such as MFA, backups, updates and an incident plan.

A sensible place to start

From uncertainty to a clear action plan.

Cyber security can feel complicated. Our approach keeps it practical: understand what you have, identify the most important gaps and improve in manageable steps.

  1. 01

    Assess

    Complete the free Cybertool check to see where your business stands today.

  2. 02

    Prioritise

    Focus first on the gaps that could have the greatest impact on your operation.

  3. 03

    Improve

    Put sensible controls, policies and staff practices in place.

  4. 04

    Review

    Check progress and keep your security current as the business changes.

Free 10-question check

How ready is your business?

Each question represents one of the NCSC's ten minimum security areas, simplified for an SME. It takes about three minutes and gives you an immediate place to start.

No passwords or system secrets.Your answers remain in your browser until you choose to submit your details for the report.

SELECT YES OR NOT YET — 0 OF 10 ANSWERED

1. A named person reviews our main cyber risks and records what needs to be improved.Guide & Govern · Risk management
2. Staff know how to recognise and report suspicious emails, requests and login activity.Guide & Govern · Security awareness
3. We keep a current list of the important information, devices, accounts and online services the business relies on.Identify & Understand · Assets and their importance
4. New devices and online services are set up securely, with default passwords and unused accounts or features removed.Prevent & Protect · Secure configuration
5. Security updates for devices, apps and online services are installed promptly.Prevent & Protect · Patching
6. Multi-factor authentication is turned on for email, banking, cloud storage and administrator accounts.Prevent & Protect · Multi-factor authentication
7. Someone checks or receives alerts about unusual logins, malware and other suspicious activity.Detect & Contain · Detect unusual behaviour
8. People receive only the access they need, and access is changed promptly when roles change or someone leaves.Prevent & Protect · Least privilege
9. Important business data is backed up, protected from attackers and tested to make sure it can be restored.Respond & Recover · Data recovery
10. We have a one-page cyber incident plan with responsibilities, contact details and first actions.Respond & Recover · Response planning

Two frameworks · one simple pathway

New Zealand priorities with international discipline.

The NCSC framework organises the practical cyber work. ISO/IEC 27001:2022 helps a business manage that work through risk ownership, objectives, evidence, review and continual improvement.

NCSC Cyber Security Framework

Cybertool uses the five functions—Guide and Govern, Identify and Understand, Prevent and Protect, Detect and Contain, and Respond and Recover—and simplifies the ten Minimum Cyber Security Standards for an SME starting point.

View the NCSC framework

ISO/IEC 27001:2022

ISO/IEC 27001 helps protect information from being seen by the wrong people, changed incorrectly or unavailable when needed. A deeper review can help an SME build risk, policy, evidence and improvement practices, but the free check is not certification.

View the ISO overview

Important boundary

NCSC's Minimum Cyber Security Standards were developed for GCISO-mandated government agencies, although other organisations may adopt them. Cybertool uses their ten practical topics as guidance; it does not claim government mandate, NCSC approval or full standards compliance.

The ten-point owner checklist

Cyber basics you can discuss with your IT provider.

These ten topics mirror the NCSC minimum security areas in plain language. You do not need to implement government-level detail to begin—start with the risks and systems that matter most to your business.

✓ Named cyber-risk owner✓ Staff security awareness✓ List of critical assets✓ Secure system settings✓ Prompt security updates✓ Multi-factor authentication✓ Unusual-activity alerts✓ Least-privilege access✓ Protected, tested backups✓ One-page incident planRun the free starter check

Plain-English advice for SME owners

From the Cybertool blog

About Cybertool

NZ-based support for smaller teams.

Cybertool is a New Zealand SME-focused service developed to make recognised information-security thinking easier to understand and act on. It combines the NCSC NZ framework's practical structure with ISO/IEC 27001:2022 management-system thinking.

Our goal is not to bury you in paperwork. It is to help you identify important information, assign responsibility, reduce common risks, prepare for incidents and review improvements over time.

Contact: safety1stconsultants@gmail.com · 021 222 5246

Privacy & data handling

The free check is designed to minimise data collection.

Before you submit the contact form, the answers remain in your browser. If you choose to unlock the report, Cybertool stores your name, business, email, phone number, score and question responses so the result can be recorded and relevant support can be offered.

The check does not ask for passwords, account credentials or detailed system configurations. Do not send confidential access information by email. Using Cybertool does not make an organisation compliant with the Privacy Act, NCSC standards or ISO/IEC 27001.

Take the first step

Start with clarity.
Build with confidence.

Run the free check, or contact us for a deeper NCSC- and ISO/IEC 27001-informed review with a practical improvement plan.