Auckland | Waikato | Bay of Plenty
IT Risk Management

Are you across all your IT risks?

Most businesses can name one or two. An ageing server, a backup nobody has tested, the person who set everything up and has since left. The trouble is never the risks you can name. It's the ones nobody has written down.
IT strategy and support discussion around digital roadmap
Business server rack setup for SMB IT infrastructure in Auckland
Our Approach

IT risk management for New Zealand businesses

We keep a written, scored register of the technology risks in your business, review it with you, and work through it in priority order.

The risks that hurt are the dull ones

Almost nothing on a real register is dramatic. A server past its warranty. A backup that reports success every night and has never been restored. A domain nobody remembers renewing. One person who knows how the phone system is wired.

None of them are urgent, right up until the morning they are.

Every business in the country takes health and safety risk seriously enough to write it down, review it and put a name beside each item. Technology risk rarely gets the same treatment, even though it can stop the business just as quickly.

What we do about it

We keep the list. Everything we can see across your environment, scored so the serious items are obvious at a glance, each with an owner and a date.

It gets reviewed with you rather than filed. Items get closed, new ones appear as hardware ages and circumstances change, and the register tells you what changed since last time.

The point isn't the document. It's that you can answer the question at the top of this page without having to guess.

What Our Clients Say
“We trust Elite with our businesses technology needs because they have experienced people, and products that we know we can rely on.”
Mason Elliot
IT Manager, Fairview Ford & Mazda
What we track

Where the risks actually come from

Six areas that generate most of what ends up on a register, monitored continuously rather than reviewed once a year.

Equipment past its supported life

Workstations on an operating system that has stopped receiving updates, servers running beyond end of life, network gear the manufacturer no longer patches. It is the most common thing we log, and it looks completely fine right up until it doesn't.

Network, firewall and wireless

Firewalls without filtering or inspection switched on, network ports anyone can plug into, wireless passwords that have not changed in years, and guest devices sharing the same network as your servers. Common, and among the quicker things to put right.

Identity, access and passwords

Multi-factor authentication missing on remote access, staff carrying administrator rights they were never meant to keep, shared logins that make it impossible to tell who did what, and passwords living in a document or on a label stuck to the monitor.

Your people

No security awareness training running, or training that everybody quietly stopped completing. Nearly every serious incident we see begins with somebody doing something that seemed entirely reasonable at the time.

Backup and recovery

Backups that complete every night and have never been restore-tested, and cloud data that most businesses assume is backed up when it isn't. Microsoft keeps your data available. Getting it back after a mistake is a separate job.

Where your sensitive information sits

The most common single item we log is working out where personal and sensitive information is actually stored and who can reach it. Most businesses are surprised by the answer, and the responsibility for protecting it sits with them either way.
What a register actually looks like

Real examples from registers we maintain, with identifying detail removed. Every item gets a plain description, a consequence and a rating, so the conversation is about priorities rather than technology.

Risk What happens if it isn't addressed Rating
Devices still running Windows 10 Support has ended, so any vulnerability found from here on stays open on those machines permanently High
No multi-factor authentication on remote access A password on its own is enough to reach the network from anywhere in the world High
Microsoft 365 data not backed up Microsoft keeps the service running, not your data. Files deleted or encrypted may not be recoverable beyond a short window High
Wireless password unchanged for years and shared with guests Former staff and every visitor ever given the password can still reach the same network as your servers Medium
No security awareness training in place The most common way in is somebody doing something reasonable, and nobody has shown them what to look for Medium
Worth knowing

If nobody has shown you a list, that doesn't mean there isn't one

Most of this information already exists. It sits inside the monitoring and management tools used by whoever looks after your technology. The gap is usually not visibility. It's that nobody has assembled it into something you can read.

Monitored is not the same as reported

Tools raise alerts when something breaks. Very few of them produce a prioritised list of what is likely to break next, and fewer still put it in front of the business owner.

A quiet quarter is not evidence

Nothing going wrong is pleasant but it proves very little. Ageing hardware and untested backups look exactly the same as healthy ones until the day they don't.

You are entitled to ask for it

Ask whoever manages your technology for your current risk register. How quickly it arrives, and how much of it you understand, tells you a good deal.

How it works

01

Schedule an Appointment

A conversation about what you already know, what you have been putting off, and which parts of the business simply cannot stop.
02

Evaluate Your Environment

We look at hardware and software age, whether backups restore, security configuration, expiry dates, documentation, and where things depend on one person or one device.
03

Develop a Growth Plan

You get the register. Everything we found, scored, with what to do about each item and roughly what it costs. It's yours to keep whether you take it further with us or not.

Find out what's on your list

A review of your environment and a written register you can keep, whatever you decide to do next.

Schedule an Appointment

We have offices in Auckland, Hamilton and Tauranga.
FAQ

Need more info? We’re here to help

Anything that could interrupt the business or cost money if it isn't dealt with. In practice that means hardware and software approaching end of life, backups that haven't been proven, gaps in security configuration, accounts with more access than they need, expiring domains and certificates, licence positions that have drifted, undocumented systems, and anywhere a single device or a single person is holding something up. Each entry gets a plain-language consequence and a rating, because a list without priorities is just a list.

An audit is a snapshot. Useful, but it starts going out of date the day it's delivered, and most businesses have one sitting in a folder somewhere. A register is maintained. Items close, new ones appear as equipment ages and the business changes, and you can see what moved since the last review. The value is in it being current rather than thorough once.

Some do it well. The straightforward way to find out is to ask for your current register and see what comes back. If it arrives quickly, is written so you can follow it and has ratings you can act on, you are in good hands. If it takes a fortnight or turns up as a list of alerts, that is worth knowing either way.

Quarterly suits most businesses, with the underlying monitoring running continuously rather than only at review time. It's also worth revisiting after anything significant, such as an office move, a system replacement or someone with a lot of knowledge leaving, since all three tend to create new entries at once.

Yes, though it depends what they're asking. Insurers and larger customers increasingly want evidence that risks are identified and being managed rather than a yes or no answer, and a current register with dates and owners is exactly that kind of evidence. We are not compliance specialists, so if you need to meet a formal standard we will say so and work alongside someone who does.

Yes. What we produce is yours regardless of what you decide afterwards. We would rather you had an accurate picture of your own business than feel you had to sign something to see it.

Schedule an appointment

We have offices in