The state of NZ IT support in 2026: cyber security, MSPs and the retainer trap
What's actually changed for New Zealand businesses buying IT support in 2026 — from CERT NZ's threat reports to the MSP contracts we keep tearing up.
Talk to any NZ business owner about IT in 2026 and one of two stories comes out. Either they've got a small internal team drowning in tickets, alerts and Microsoft licence admin — or they're paying a managed service provider (MSP) a flat monthly fee and quietly wondering what they actually get for it. Both stories have the same root cause: the landscape has moved faster than the contracts.
What changed in the NZ threat landscape
CERT NZ's quarterly reports have made one thing very clear: the volume of incidents affecting small and medium New Zealand businesses is now dominated by three categories — business email compromise (BEC), credential phishing tied to Microsoft 365, and ransomware delivered through unpatched edge devices (VPN concentrators, firewalls, remote-access appliances). The dollar losses are heavily concentrated in BEC: a single redirected invoice can cost more than a year of managed IT.
What's newer is the speed. Attackers now weaponise a fresh CVE in a common firewall or VPN within days, sometimes hours, of public disclosure. If your MSP's patching SLA is "monthly maintenance window", that's no longer good enough for anything internet-facing.
The MSP retainer trap
Most NZ MSP contracts we inherit look the same: a per-seat monthly fee that bundles helpdesk, endpoint management, a bit of Microsoft 365 admin and "cyber security" as a vague line item. On paper it's tidy. In practice, three things go wrong:
- Security is priced as an add-on, not a baseline. MFA, conditional access, endpoint detection and response (EDR), and immutable backups end up as upsells rather than the minimum viable configuration.
- Response times are averages, not commitments. "Average first response under 4 hours" hides a long tail. When your finance team can't send payroll, an average doesn't help.
- Off-boarding is deliberately painful. Admin accounts, tenant ownership and documentation live inside the MSP's tooling. Leaving means rebuilding.
A sensible 2026 baseline for NZ SMBs
You don't need an enterprise budget to be genuinely defensible. If we were setting up a 20 - 200 seat NZ business from scratch today, this is the floor we'd insist on:
- Microsoft 365 Business Premium (or equivalent) with conditional access on every account, phishing-resistant MFA for admins, and legacy auth blocked.
- An EDR product on every endpoint — not just "antivirus" — with 24/7 monitored response.
- Immutable, offsite backups of Microsoft 365 mailboxes, SharePoint, OneDrive and any line-of-business SaaS. Test restores quarterly.
- A documented incident response runbook: who to call, what to isolate, how to communicate. Rehearse it once a year.
- Patch SLAs that distinguish internet-facing devices (hours) from internal endpoints (days) from servers (scheduled).
- An asset and identity inventory that you own — not one locked inside your provider's PSA tool.
How to actually buy IT support in 2026
The MSP model isn't broken — the contracts are. When we quote work at nzit.help we push for three things that make the relationship healthy for both sides:
- Per-ticket or retainer, your call. Some months you need us weekly; some months you don't. Pay for what you use.
- Named engineers, not a queue. The person who fixed it last time picks it up this time.
- Your tenant, your data, your docs. Everything we set up is handed back in a form you can walk away with.
Where to start this quarter
If you do nothing else after reading this, do these three checks: confirm MFA is enforced on every Microsoft 365 account (including shared mailboxes and service accounts), confirm your firewall and VPN firmware are within one release of current, and confirm someone has successfully restored a file from backup in the last 90 days. Two of those three usually fail on the first honest look — and each is a common way NZ businesses lose real money in 2026.
Want a second opinion on your current MSP or an honest security baseline check? We do a free 30-minute review — no pitch deck, just a plain-English readout.
