Mon – Fri  9AM – 5PM|Client Portal
ITstuffed

Cyber security you can count on

We use a layered 7+2 approach to keep threats out and recover quickly if anything gets through: day-to-day protection, 24/7 monitoring, plus incident response and recovery.

4.8/5(84 Google reviews)
0800 487 883

Want to know how your security stacks up?

Tell us what prompted the conversation and we'll talk through where things stand.

Please complete verification before submitting.

Seven layers of protection. Two layers of recovery.

Cyber threats don't stop at one thing, so we don't rely on one control. Our 7+2 layered model blocks attacks at multiple points and makes sure we can recover quickly if something still gets through.

The nets get finer on purpose. If something slips through one layer, it meets another designed to catch what the first one missed.

ITstuffed 7+2 cyber security model showing seven progressively finer protection layers followed by incident response and backup recovery.

1. People and awareness

Security awareness is practical and regular. We use short training and phishing simulations so your staff see the kinds of requests they are likely to receive and know what to do when one looks wrong.

2. Identity and access

Multi-factor authentication is one part of this layer, not the whole of it. We also manage permissions, Conditional Access and identity monitoring so access is limited to the people who need it, under the conditions we expect, and unusual sign-in activity can be investigated.

Access also changes as people join, leave or move within the organisation. Keeping permissions current is part of the ongoing management of the environment rather than something that only gets reviewed after an account causes a problem.

3. Email and collaboration

Email is still where a lot of attacks begin, including phishing, fake invoices and requests to change bank details. We filter malicious messages, links and attachments before they reach the inbox and review quarantined mail where there is any doubt about releasing it.

Some messages will still look legitimate enough to require human judgement, which is where the awareness layer comes back in.

If a malicious email does get through and somebody clicks the link, the next control is the web layer.

4. Web and network protection

DNS filtering can stop the browser reaching a known malicious destination, while the network controls around the business provide another barrier for traffic entering and leaving the environment.

For businesses with higher security requirements, additional network controls can be added through Security Plus.

5. Device security

Once activity reaches a computer, we want visibility of what is happening there. Endpoint protection watches for suspicious processes, changes and other behaviour on the device, and our security team can investigate and contain activity without waiting for the user to notice it first.

6. Patch and vulnerability management

Some attacks do not need a convincing email at all. They exploit weaknesses in software that are already known and, in many cases, already have a fix available. We patch operating systems and supported applications, scan for vulnerabilities and follow up what remains exposed.

New vulnerabilities are discovered all the time, which means this layer needs ongoing maintenance rather than an occasional security project.

The less known exposure left sitting in the environment, the fewer easy opportunities there are for an attacker to use.

7. 24/7 monitoring and detection

Even with all the controls before it, we assume something can still get through. Security activity is monitored through our SOC partners around the clock, with alerts investigated and escalated when something needs action. For higher-severity events, predefined rules can automatically contain or shut down affected systems rather than leaving the threat active until the next morning.

And if something still gets through?

No security setup is perfect, which is why we have two recovery layers. We respond fast to contain threats and recover your data and systems so you can get back to business.

White line art of a fishing net scooping up a threat, representing incident response.

8Incident response

We investigate the technical issue, contain what we can and coordinate the response with your insurer and other specialists where needed.

White line art of a secure protected case holding recovered data, representing backup and recovery.

9Backup and recovery

We follow the 3-2-1 backup principle and carry out a manual restore test every month, so recovery is checked before you ever need it.

Security is built into the service

Security is part of the managed service because we cannot sensibly take responsibility for an environment while leaving the basic controls optional. Every managed client gets the core protection, monitoring and recovery layers shown above.

Security Plus is for businesses that need additional controls beyond that baseline.

  • Included in every managed service, not sold separately
  • 24/7 SOC monitoring
  • Annual cyber-insurance review
  • Monthly backup restore testing
SMB1001 Gold CertifiedITstuffed holds SMB1001 Gold certification and uses the framework to manage our own cyber security.

When somebody else asks about your security

Your insurer may ask about controls at renewal, or a client may include security questions in a supplier review. Because we manage the environment, we can help establish what's in place.

  • Insurance and compliance questionnaires
  • Evidence you can rely on
  • Clear, jargon-free reporting

What happens when the recovery layers are needed

A healthcare organisation that later became a client experienced a Microsoft 365 compromise involving two accounts. We were brought in during the incident, contained it within hours and coordinated the response with their insurer and forensic specialists while the organisation remained operational.

Read the case study

The controls behind the layers

Each of the nine layers runs on proven controls, managed as part of the service.

1. People and awareness

Security-awareness training, phishing simulations

2. Identity and access

MFA, access controls, Identity Threat Detection and Response

3. Email and collaboration

Email filtering, malicious-link protection, manual release review

4. Web and network protection

DNS and web filtering, additional network protection with Security Plus

5. Device security

Endpoint Detection and Response, device monitoring

6. Patch and vulnerability management

Patch management, vulnerability scanning, remediation

7. 24/7 monitoring and detection

24/7 SOC monitoring, alert investigation, escalation

8. Incident response

Investigation, containment, remediation, insurer coordination

9. Backup and recovery

Backup monitoring, 3-2-1 approach, monthly restore testing, disaster recovery

Want another view on your cyber security?

You may have a specific concern, an insurer or client asking questions, or want to know whether the layers around your business are being managed well. Tell us what has prompted the conversation.

Start the conversation

* Required

Please complete verification before submitting.

Based in Christchurch and working with businesses across Canterbury and the wider South Island.

Frequently asked questions

Is cyber security included in your managed service?

Yes.

The core security and recovery layers are deliberately included rather than being treated as a collection of optional add-ons.

Security Plus adds further controls for businesses with higher security requirements.

Do you monitor security outside business hours?

Yes.

Our SOC partners monitor for security activity around the clock and escalate events that need action.

Do you test backups?

Yes.

We monitor backup status and carry out a manual restore test every month so recovery isn't being assumed from a successful backup status alone.

Do you use the 3-2-1 backup rule?

Where the environment allows it, yes.

The principle is to maintain three copies of the data across two different types of storage, with one kept offsite.

The exact design depends on what is being backed up and the systems involved.

Do you provide staff security training?

Yes.

Ongoing security-awareness training and phishing simulations form part of the service.

Do you manually check quarantined email release requests?

Yes.

We review release requests because malicious messages can be convincing enough that a user may believe they should be released.

Can you help with cyber insurance?

Yes.

We review cyber-insurance declarations with clients and can help establish which controls are in place before those declarations are made.

Can you guarantee we won't be breached?

No.

No responsible security provider can make that promise.

We reduce avoidable exposure, maintain the protection layers around the environment, monitor for suspicious activity and keep recovery and incident-response capability in place if something does happen.