NCSC NZ Critical Controls
Assess and improve the practical cyber controls prioritised by New Zealand’s National Cyber Security Centre, previously known as CERT NZ.
Current NCSC guidance
Technical control assessment
Prioritised improvement roadmap
Evidence-led implementation
Practical Cyber Controls Based on Current NCSC NZ Guidance
The NCSC NZ Critical Controls, previously published under the CERT NZ name, identify practical protections that can prevent, detect or contain many common cyber attacks. ITFR helps organisations assess the technology behind those controls, identify material gaps and turn the guidance into an achievable improvement plan.
✓Systems and software coverage
Review assets, supported versions, patching, application control and lifecycle management.
✓Identity and privileged access
Assess multi-factor authentication, password management and least-privilege access.
✓Logging and detection visibility
Review centralised logging, alert coverage, retention and investigation readiness.
✓Backup and recovery controls
Assess backup separation, protection, monitoring and evidence of restoration testing.
✓Network security boundaries
Review segmentation, separation, administrative access and important service dependencies.
✓People, ownership and evidence
Connect technical controls to awareness, owners, exceptions, records and ongoing review.
The result: a current view of control coverage, prioritised technical improvements and practical evidence showing how important cyber risks are being addressed.
Benefits at a glance
Prioritised Control Gaps
Clear Technical Actions
Stronger Cyber Resilience
Reusable Assurance Evidence
GOVERN IT · FRAMEWORKS & MATURITY
Choose the Right NCSC NZ Critical Controls Engagement
Choose a focused assessment and roadmap or ongoing implementation support that helps improve and evidence the controls over time.
NCSC NZ Critical Controls Assessment
Scoped Assessment
Current controls, gaps and priorities
Understand current technical control coverage
For organisations that want a practical baseline against the current NCSC NZ Critical Controls and a prioritised improvement roadmap.
✓Scope & Environment Review
Confirm relevant users, identities, devices, applications, networks, cloud services and data.
✓Current Control Assessment
Assess the implementation and coverage of the current NCSC NZ Critical Controls.
✓Technical Evidence Review
Review configurations, reports, policies, records and other available evidence.
✓Gap & Risk Analysis
Identify missing, partial or inconsistent controls and the risks they create.
✓Priority Roadmap
Sequence practical improvements according to exposure, impact, effort and dependencies.
✓Findings & Leadership Briefing
Document results, priorities, owners and decisions for business leadership.
BEST FOR
Businesses that want an evidence-led baseline and a clear starting point for improving the NCSC NZ Critical Controls.
Critical Controls Implementation Support
Ongoing Improvement
Current controls, gaps and priorities
Turn priority control gaps into managed improvement work
For organisations that need technical support to implement, coordinate and evidence agreed control improvements.
✓Everything in the Controls Assessment
Scope, control review, evidence, gap analysis, roadmap and leadership briefing.
✓Identity & Access Improvements
Coordinate MFA, password management, privileged access and least-privilege actions.
✓System & Endpoint Improvements
Support patching, application control, asset lifecycle and secure configuration actions.
✓Logging & Detection Improvements
Improve centralised logging, alerts, retention and investigation visibility.
✓Backup & Recovery Improvements
Strengthen backup protection, monitoring, separation and restoration testing.
✓Network Security Improvements
Implement proportionate segmentation, separation and administrative access controls.
✓Evidence & Progress Reporting
Maintain implementation records, exceptions, owners, progress and future priorities.
BEST FOR
Businesses that want accountable technical help to implement and maintain priority control improvements.
Use the Framework as Guidance, Not a Certification Badge
The NCSC NZ Critical Controls are practical cyber guidance and are reviewed against current incident insights.
ITFR assesses implementation evidence and helps improve technical controls, but does not present the engagement as official NCSC certification.
Your organisation receives a practical improvement pathway without overstating assurance.
CURRENT NCSC NZ CONTROL AREAS
What Technology Areas Do the Critical Controls Cover?
The current controls span prevention, detection, people, recovery and containment across the technology environment.
Identity & Access
Multi-factor authentication, password management and the principle of least privilege.
Systems & Applications
Patching, application control and supported asset lifecycle management.
Detection & People
Centralised logging, actionable alerts and security awareness across the organisation.
Recovery & Network
Tested backups plus network segmentation and separation to limit disruption and movement.
$
Scale the engagement to current control coverage and improvement capacity.
Choose a focused assessment or ongoing implementation support according to environment complexity, evidence quality, priority gaps and internal resources.





