IT specialists

Practical information on keeping systems and data safe from attack.

CERT CAFE 180426 WEB 21

News

Businesses encouraged to trade smart online to avoid a nightmare before Christmas

Shoring up ecommerce website security can help businesses and their customers avoid a cyber nightmare before Christmas s

11 November 2020

Guide

Mitigating the impact of incidents in M365

CERT NZ has seen a lot of phishing attacks on Microsoft 365, due to it being a commonly used cloud platform. A percentag

CERT TEC 180518 WEB 245

Critical Controls

Implement and test backups

After an incident, restoring your data from backups is often the best way to return to business as usual. Performing and

Alert

Critical Windows Authentication Vulnerability in Netlogon

24 September 2020

CERT 180420 WEB 210

News

What is a CERT, anyway?

This week marks the anniversary of the Morris Worm, the first well-known internet ‘worm’. To mark the occasion, we’re ta

6 November 2020

Guide

Securing access to Microsoft 365

We see a large number of Microsoft 365 (formally known as Office 365) branded phishing attacks, due to it being such a c

CERT TEC 180518 WEB 83

Critical Controls

Principle of least privilege

The principle of least privilege means only having the access you need to do your job. Restricting the level access to o

Advisory

Emotet Malware being spread via email

7 September 2020

CERT TEC 180518 WEB 56

News

Complacency makes Kiwis more vulnerable to cyber attacks

The volume and sophistication of financially-motivated cyber attacks has increased over the last six months, so it is cr

19 October 2020

Guide

Manage authentication

Using a combination of authentication security controls can protect your organisation from a wide range of unauthorised

2019 05 30 MTP 1764

Critical Controls

Multi-factor authentication

You can authenticate with something you know, something you have, or something you are. Multi-factor authentication (MFA

Advisory

Critical vulnerability in Microsoft Windows Server

15 July 2020

CERT TEC 180518 WEB 8 v2

News

COVID-19: operating your business under Alert Levels 1 and 2

Auckland is at Alert Level 2 and the rest of New Zealand at Alert Level 1. It’s important you run your business in line

28 September 2020

Guide

Cloud-based identity providers and authentication

Using single sign-on with a large cloud identity provider allows your users to protect fewer passwords and your IT staff

2019 05 16 MTP 0632

Critical Controls

Application allowlisting

Application allowlisting (otherwise known as whitelisting) is a method of strictly controlling what programs can be run

Advisory

Active ransomware campaign leveraging remote access technologies

16 June 2020