Skip to content

5 Steps to Avoiding a Serious Cyber Incident

A lighthouse in a storm protecting against a serious incident

At the time of writing this article New Zealand is in the throes of a real-life ransomware incident on Manage My Health (MMH) – NZ’s largest patient portal.

In late December MMH detected unauthorised access. Independent forensics indicate a specific module (Health Documents) was affected, not the entire platform, with 6–7% of ~1.8 million users potentially having documents accessed. MMH has stated that the incident is contained, that login protections and storage have been strengthened, and notifications are being sent to practices and individuals, with a dedicated helpline being established. Health NZ has announced an urgent review to ensure lessons are learned and shared across the sector.

Events such as this are becoming all too common. An NCSC Cyber Threat Report issued in Q4 last year, shows that cyber attacks are evolving rapidly in New Zealand, and no business is too small or “unimportant” to be a target. Financially motivated criminals, state-sponsored actors, and hacktivists are all active – and the risks are growing as global conflicts escalate and cybercrime tools become more accessible.

For MMH and all the patients affected by this incident, this fact is now a very unfortunate reality. Responding over the holiday period, coordinating multi‑party notifications, and dealing with active extortion are uniquely challenging. But the lesson is universal – fast detection and disciplined response can change outcomes.

In this article, we’ll cover how these incidents typically happen and how Managed Detection & Response (MDR) and a Security Operations Centre (SOC) reduce the risk and impact.

How incidents like this can unfold

While every incident is unique, patterns recur:

  • Initial access via exposed web components, weak credentials, phishing, or an unpatched dependency
  • Privilege escalation & lateral movement if identity controls and segmentation aren’t strict
  • Data staging & exfiltration from document stores or specific modules
  • Extortion pressure, often with a deadline, demanding payment to prevent release

None of the above implies specific failings in any one organisation. These are common attacker playbooks across sectors, especially where high‑value data lives.

5 practical steps organisations can take now:

  1. Enforce MFA everywhere that matters and add login rate limits and lockouts
  2. Segment sensitive data and limit who can access it
  3. Patch known vulnerabilities and maintain secure defaults on internet‑facing components
  4. Deploy MDR/SOC coverage to monitor continuously and respond in minutes
  5. Test the plan: Run tabletop exercises and verify notification workflows in advance
Let’s look at what MDR/SOC is, why it matters, and what it looks like in practice.

Managed Detection & Response (MDR) and a Security Operations Centre (SOC) combine broad telemetry (endpoint, cloud, identity, network) with 24/7 expert (human) analysts to find and stop threats quickly. Instead of relying on static prevention alone, MDR/SOC coverage investigates alerts, hunts anomalies and executes response actions fast. In sectors where attacks don’t wait for business hours, MDR/SOC coverage is the difference between minutes and days of dwell time.

What that looks like in practice:
  • Continuous monitoring & threat hunting: Detects suspicious behaviours even when signatures don’t exist
  • Rapid containment: With customer‑approved authorisations, a SOC can kill/quarantine malicious processes and isolate infected endpoints to cut off movement
  • Human + AI triage: Analysts validate context so true positives rise and noise falls – critical when minutes matter
  • Unified visibility: Logs are pulled from endpoints, Azure/M365, identity providers, and network devices so staged exfil or unusual access stands out
  • Playbooks & readiness: Incident Response (IR) retainers and IR plan development for immediate expert support, plus tabletop exercises, mean teams aren’t improvising under pressure

Fast detection, stronger resilience

Perfect prevention doesn’t exist, but fast detection and response radically change outcomes. MDR/SOC gives the vigilance, speed, and discipline required to turn threats from crises into contained events.

If you’re looking for a plain‑English conversation about MDR/SOC, how it fits your environment, and improves your resilience we’re here to help.

Facebook
Twitter
LinkedIn

Related Posts

Ask ten business leaders what their AI governance strategy is and you’ll probably get ten very different answers. Find out where your organisation sits.
We often talk about “the cloud” as if business data simply disappears into the internet. In reality, cloud services depend on very physical foundations. At the heart of Advantage Cloud is our data centre.
When users complain that systems are slow, the immediate response is often to question the internet connection. But increasingly, organisations are discovering that the real bottleneck sits much closer to home – the firewall.