started · updated
Cybersecurity focus shifts toward resilience and SME protection
The cybersecurity landscape is shifting from a focus on pure prevention to a priority on cyber resilience. As attacks become more sophisticated, organizations are increasingly concerned with their ability to maintain operations and recover quickly during and after an incident.
Small and medium-sized enterprises (SMEs) face unique challenges, often lacking the enterprise-level budgets and specialist teams required for complex governance. Experts suggest that SMEs can significantly reduce risk by implementing fundamental controls, such as multi-factor authentication (MFA) and consistent patch management, rather than attempting to adopt expensive, complex tooling.
In the insurance sector, cyber insurance is becoming a key metric for business preparedness. Insurers are increasingly looking for evidence that companies understand their critical systems and have tested their incident response capabilities. For SMEs, automated underwriting is making insurance more accessible, but a lack of basic security controls may restrict coverage options.
In New Zealand, consultancy Revolution InfoSec has highlighted a “forgotten middle” of medium-sized businesses that face growing regulatory and governance responsibilities without adequate specialist resources. This concern is heightened by potential legal changes that could hold directors personally liable for critical breaches.
Entities
Alistair Ross · Elmore Insurance Brokers · Kaspersky · Lancashire Police · National Cyber Security Centre · New Zealand · Revolution InfoSec · Simon Gilbert · Verizon · World Economic Forum