{"id":13713,"date":"2025-05-28T10:56:18","date_gmt":"2025-05-27T22:56:18","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=13713"},"modified":"2025-05-28T10:56:18","modified_gmt":"2025-05-27T22:56:18","slug":"a-practical-guide-how-much-cyber-security-investment-do-i-really-need","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=13713","title":{"rendered":"A practical guide: How much cyber security investment do I really need?"},"content":{"rendered":"\n[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h2>Cyber costs seem to keep increasing every year.\u00a0<\/h2>\n<p>There is always something more that is needed.\u00a0 Organisations can\u2019t afford to over-invest but they can\u2019t afford to under-invest either.\u00a0 It\u2019s a tightrope so we thought it would be useful to prepare a simple guide.<\/p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&quot;2_5&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_button button_url=&quot;https:\/\/new.kinetics.co.nz\/june-report-cyber-threat-trends-in-2025\/&quot; button_text=&quot;Click to uncover the extent of cyber crime in 2025&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; custom_button=&quot;on&quot; button_text_color=&quot;#4CB84A&quot; button_border_width=&quot;2px&quot; button_border_radius=&quot;4px&quot; button_icon=&quot;=||divi||400&quot; box_shadow_style=&quot;preset1&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_button][\/et_pb_column][\/et_pb_row][et_pb_row disabled_on=&quot;off|off|on&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_column type=&quot;4_4&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_text _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; custom_padding=&quot;2px|2px|2px|2px|false|false&quot; border_width_all=&quot;1px&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<h3>A simpler time<\/h3>\n<p>Just a few years ago, the core fundamentals of security were simple. There were three things you really needed to do to protect yourself.<\/p>\n<ol>\n<li>Antivirus,<\/li>\n<li>Backups (daily) and<\/li>\n<li>Patching.<\/li>\n<\/ol>\n<p>Optionally we\u2019d add a tool to scan incoming emails for viruses<br \/>That was enough, and that was the underlying basis of our support plans.<\/p>\n<p><strong>But those days are long gone. Now you need a little more.<\/strong><\/p>\n<p>&nbsp;<\/p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;2px|2px|2px|2px|false|false&#8221; border_width_all=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h3>A minimum today<\/h3>\n<p>Today, anti-virus isn\u2019t enough. It\u2019s now been replaced with EDR, which is more sophisticated and more expensive.<br \/>Backups and Patching are as vital as ever.<\/p>\n<p>Then we need to add MFA (which might be annoying but it is also the one of the most effective tools, especially the more advanced versions.<br \/>We now have to scan emails for more than viruses. We\u2019re also checking any included weblinks.<\/p>\n<p>We\u2019re testing URLs before people browse to them, and with KARE, we also use AI heuristics to test the webpage as it\u2019s opened.<\/p>\n<p>We\u2019re limiting security access to corporate IT resources and even to administer the local PC (zero trust), scanning for \u2018shadow IT\u2019, and increasing cyber awareness with training, briefings and phishing test.<\/p>\n<p>(We have bundled this into a security plan called <a href=\"https:\/\/new.kinetics.co.nz\/kare-security-foundation\/\">KARE Foundation<\/a>)<\/p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;2px|2px|2px|2px|false|false&#8221; border_width_all=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h3>Stepping it up<\/h3>\n<p>The minimum isn\u2019t enough for many.<\/p>\n<p><strong>DATA RULES<\/strong><br \/>Optionally we\u2019re also setting up data rules in 365 (DLP) to limit what can be shared and we\u2019re using something called DMARC to promote safe email.<\/p>\n<p><strong>MOBILES<\/strong><br \/>When you consider how much email and browsing is done on mobiles, it makes sense that we are now starting to protect mobile devices, both Android and Apple with &#8216;MDM&#8217; tools.<\/p>\n<p><strong>PROTECTED DEVICES ONLY<\/strong><br \/>We\u2019re now developing plans to differentiate between corporate PCs and phones versus bring-your-own-device (BYOD), and we\u2019re using this to start to limit so that unprotected home or shared PCs and mobile devices can no longer access some, or even all, of the IT assets such as 365.<\/p>\n<p><strong>24\/7 ACTIVE MONITORING<\/strong><\/p>\n<p>We\u2019re moving EDR to MDR which means 24\/7 (because you and your people might work at any time, and the cloud is always on) SOC and SIEM solutions to monitor for unusual behaviours on devices.<\/p>\n<p>&nbsp;<\/p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(34,34,34,0.12)&#8221; custom_margin=&#8221;||||false|false&#8221; custom_padding=&#8221;2px|2px|2px|2px|false|false&#8221; border_width_all=&#8221;1px&#8221; box_shadow_style=&#8221;preset1&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h3>Reports matter!<\/h3>\n<p>No matter whart level of security is in place, you NEED reporting.\u00a0 Things change as PCs are added and removed, users come and go, and tools are refreshed.<\/p>\n<p><strong>We reckon detailed monthly reports (with plain english summaries) help you check your IT team is looking after and keeping your security in place, no matter what!<\/strong><\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&quot;1_3,1_3,1_3&quot; disabled_on=&quot;on|on|off&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_column type=&quot;1_3&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_blurb title=&quot;A Simpler Time&quot; image=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2024\/06\/1-circle-c.png&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<p>Just a few years ago, the core fundamentals of security were simple. There were three things you really needed to do to protect yourself.<\/p>\n<ol>\n<li>Antivirus,<\/li>\n<li>Backups (daily) and<\/li>\n<li>Patching.<\/li>\n<\/ol>\n<p>Optionally we\u2019d add a tool to scan incoming emails for viruses<br \/>That was enough, and that was the underlying basis of our support plans.<\/p>\n<p><strong>But those days are long gone. Now you need a little more.<\/strong><\/p>[\/et_pb_blurb][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(34,34,34,0.12)&#8221; custom_margin=&#8221;150px||||false|false&#8221; custom_padding=&#8221;5px|5px|5px|5px|false|false&#8221; border_width_all=&#8221;1px&#8221; box_shadow_style=&#8221;preset1&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h3 style=\"text-align: left;\">Reports matter!<\/h3>\n<p>No matter what level of security is in place, you NEED reporting.\u00a0 Things change as PCs are added and removed, users come and go, and tools are refreshed.<\/p>\n<p><strong>We reckon detailed monthly reports (with plain english summaries) help you check your IT team is looking after and keeping your security in place, no matter what!<\/strong><\/p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&quot;1_3&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_blurb title=&quot;Stepping up for 2025&quot; image=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2024\/06\/2-circle-c.png&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<p>Today, anti-virus isn\u2019t enough. It\u2019s now been replaced with &#8220;Endpoint Detection and Response&#8221; (EDR), which is more sophisticated and more expensive.<br \/>Backups and Patching are as vital as ever.<\/p>\n<p>Then we need to add MFA (which might be annoying, but it is also the one of the most effective protections, especially the more advanced versions)<\/p>\n<p>We now have to scan emails for more than viruses. It&#8217;s important to be checking any included weblinks.<\/p>\n<p>We\u2019re testing URLs before people browse to them, and with <a href=\"https:\/\/new.kinetics.co.nz\/proactive-it-service-and-support\/\">KARE Foundation<\/a>, we also use AI heuristics to test the webpage as it\u2019s opened.<\/p>\n<p>We\u2019re now further limiting security access to corporate IT resources and even to administer the local PC (zero trust), scanning for \u2018shadow IT\u2019, and increasing cyber awareness with training, briefings and phishing test.<\/p>\n<p>(Kinetics have bundled these into our <a href=\"https:\/\/new.kinetics.co.nz\/cybersecurity\/\">KARE Foundation<\/a> security plans)<\/p>[\/et_pb_blurb][\/et_pb_column][et_pb_column type=&quot;1_3&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_blurb title=&quot;What else should be on our radar?&quot; image=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2024\/06\/3-circle-c.png&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<p>The minimum isn\u2019t enough for many.<\/p>\n<p><strong>DATA RULES<\/strong><br \/>Optionally we\u2019re also setting up data rules in 365 (DLP) to limit what can be shared and we\u2019re using something called DMARC to promote safe email.<\/p>\n<p><strong>MOBILES<\/strong><br \/>When you consider how much email and browsing is done on mobiles, it makes sense that we are now starting to protect mobile devices, both Android and Apple with &#8216;MDM&#8217; tools.\u00a0 (You can include these in your <a href=\"https:\/\/new.kinetics.co.nz\/proactive-it-service-and-support\/\">KARE security<\/a> plans)<\/p>\n<p><strong>PROTECTED DEVICES ONLY<\/strong><br \/>We\u2019re now developing plans to differentiate between corporate PCs and phones versus bring-your-own-device (BYOD), and we\u2019re using this to start to limit so that unprotected home or shared PCs and mobile devices can no longer access some, or even all, of the IT assets such as 365.<\/p>\n<p><strong>24\/7 ACTIVE MONITORING<\/strong><\/p>\n<p>We\u2019re moving EDR to MDR (&#8220;Managed Detection and Response&#8221;) .\u00a0 MDR is 24\/7, because you and your people might work at any time, and the cloud is always on.\u00a0 It adds security experts actively monitoring and threat hunting, giving you &#8220;SOC&#8221; (Security Operations Centre) rand &#8220;SIEM&#8221; (&#8220;Security Information and Event Management&#8221;) solutions to monitor for unusual behaviours on devices.<\/p>[\/et_pb_blurb][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text disabled_on=&#8221;off|off|on&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<p>Clearly &#8220;stepping it up&#8221; is much more intensive and that comes at a cost. There are more layers of security, and readers might recognise the alignment with the <a href=\"https:\/\/new.kinetics.co.nz\/webinar-replay-what-are-the-nz-government-recommendations-for-sme-business-cyber-security\/\">Cert NZ 10 Critical Controls.<\/a><\/p>\n<p>Obviously, as you step up your cyber, your access becomes more restrictive and the cost of tools and support increases.\u00a0\u00a0 We wish we could say that was the end of it, but it won\u2019t be.\u00a0 We are absolutely certain that the minimum tools will only increase, and there will be new technologies next year that we haven\u2019t even heard of yet, despite our best efforts.\u00a0 That\u2019s because the hackers aren\u2019t standing still either.\u00a0 Cyber-crime is a big business for them, as we\u2019ve noted before in this blog.\u00a0 They continue to invest in new tech, and they aren\u2019t waiting for you to step your protection up.<\/p>\n<p><strong>They know they only need to through your defences once, whereas you have to repel them every hour of every day.<\/strong><\/p>\n<p>In fact, as we look overseas to observe what businesses like Kinetics are doing, we are seeing a move for them to only accept clients that invest in cyber-security, and that also have cyber-insurance.\u00a0 That make sense because if you can\u2019t get insurance to carry your cyber-risk, then why would you carry that risk yourself?<\/p>\n<p>&nbsp;<\/p>\n<h4>One thing is for certain \u2013 your business is already under attack.\u00a0 The question is, how long will your defences hold out for?<\/h4>[\/et_pb_text][et_pb_text disabled_on=&#8221;on|on|off&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<p>Clearly the last column is much more intensive and that comes at a cost. There are more layers of security, and readers might recognise the alignment with the <a href=\"https:\/\/new.kinetics.co.nz\/webinar-replay-what-are-the-nz-government-recommendations-for-sme-business-cyber-security\/\">Cert NZ 10 Critical Controls.<\/a><\/p>\n<h3>Obviously, as you step up your cyber, your access becomes more restrictive and the cost of tools and support increases.\u00a0\u00a0<\/h3>\n<p>We wish we could say that was the end of it, but it won\u2019t be.\u00a0 We are absolutely certain that the minimum tools will only increase, and there will be new technologies next year that we haven\u2019t even heard of yet, despite our best efforts.\u00a0 That\u2019s because the hackers aren\u2019t standing still either.\u00a0 Cyber-crime is a big business for them, as we\u2019ve noted before in this blog.\u00a0 They continue to invest in new tech, and they aren\u2019t waiting for you to step your protection up.<\/p>\n<p><strong>They know they only need to through your defences once, whereas you have to repel them every hour of every day.<\/strong><\/p>\n<p>In fact, as we look overseas to observe what businesses like Kinetics are doing, we are seeing a move for them to only accept clients that invest in cyber-security, and that also have cyber-insurance.\u00a0 That make sense because if you can\u2019t get insurance to carry your cyber-risk, then why would you carry that risk yourself?<\/p>\n<p>&nbsp;<\/p>\n<h4>One thing is for certain \u2013 your business is already under attack.\u00a0 The question is, how long will your defences hold out for?<\/h4>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n","protected":false},"excerpt":{"rendered":"<p>Cyber costs seem to keep increasing every year.\u00a0 There is always something more that is needed.\u00a0 Organisations can\u2019t afford to over-invest but they can\u2019t afford to under-invest either.\u00a0 It\u2019s a tightrope so we thought it would be useful to prepare a simple guide.A simpler time Just a few years ago, the core fundamentals of security [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":15185,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-13713","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/13713","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13713"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/13713\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}