CYBER SECURITY
Cyber security protection for your practice
Keeping your patient data safe and out of the hands of cyber criminals is now an essential role in general practice and is required as part of the data-sharing and use agreement.
With the rise in cyber incidents and increasingly connected information systems across the sector, practices need to have strong cyber security in place. This protects your systems and information, and gives confidence to your team, your patients, and your partners.
The level of expertise required to properly assess cyber risk and how to act on it is highly specialised. It sits beyond the scope of our day-to-day IT support – many providers are not equipped to carry out in-depth cyber testing.
We have partnered with PenTest NZ to provide support to healthcare practitioners across Aotearoa.
PenTest NZ provides independent cyber security testing for your website, email, online systems and networks. Their specialists test your systems the same way a real attacker would, to identify weaknesses that could be exploited and recommends how to fix them.
The recommended package and add-ons
Discounted package and add-ons:
We recommend practices start with the core assessment bundle, which includes:
External network test – tests your internet-facing systems (such as your website, portals, and remote access) to identify vulnerabilities that could be exploited from outside your practice
Dark web risk assessment – checks whether your practice’s email addresses, passwords, or other sensitive information have been exposed or sold on the dark web
Cyber risk self-assessment – helps you understand your current security position against best practice and identify gaps in policies, processes, and controls.
This package is now $2,985 (25% off) until 31 July 2026
Additional add-ons
Practices can also choose further assessments to strengthen their protection:
| Add-on | Purpose | Cost |
|---|---|---|
| Cloud risk assessment | Reviews your cloud systems (e.g. Microsoft 365, file storage, access controls) to ensure data is secure and permissions are appropriately configured. | $2,242.50 (save $747) |
| Phishing simulation | Tests how staff respond to realistic phishing emails and identifies training needs to reduce human risk | $367.50 (save $122) |
| Firewall security configuration assessment | Reviews your firewall settings to ensure your network is properly protected and not unnecessarily exposed. | $1,117.50 (save $372) |
| Internal network pentest | Simulates an attacker inside your network (e.g. after gaining access) to find weaknesses in internal systems and data access. | $4,492.50 (save $1,497) |
What you’ll get from these assessments
At the end of the process, you’ll receive a clear, practical report that outlines:
What vulnerabilities were found
Why they matter
What actions to prioritise
The information you receive will be able to support governance discussions, audits, risk registers, and conversations with your PHO or partners. You’ll get information that gives you a clear roadmap to improve your cyber security, without needing to interpret technical findings yourself.
Find out more:
-
PenTestNZ is a New Zealand‑based cyber security company that specialises in penetration testing — commonly known as “pen testing”. Penetration testing means safely attempting to break into systems to see what a real attacker could access, without causing harm. PenTestNZ works with health, education and critical public‑sector organisations and has experience testing environments similar to general practices. They operate independently, which means the findings are objective and trusted by external stakeholders. PenTest is a brand of AlterSec: Managed Security Service Provider
-
Outlined below are the four current standards, set by the National Cyber Security Centre, focused on the basics and to create visibility and uptake of good cyber security practices. We expect Health New Zealand to share new standards and guidance soon.
1. Managing cyber risk (standard 1)
Do you know your risks, and can you show you’ve taken reasonable steps to mitigate them?
The offer gives you:
Independent experts look for real weaknesses that attackers could actually use
External testing of your website, internet connections, and (if chosen) Microsoft 365
A clear report you can put into your risk register or board papers
Have confidence that your cyber risks are understood and documented — but you’ll need to decide who owns cyber security and what actions to take.
2. Staff awareness and phishing (standard 2)
Are you confident in staff practices to protect information you store?
The offer gives you:
A safe, controlled test to see how staff respond to phishing attempts
Reporting on whether staff click, ignore, or report suspicious emails
Evidence that training and reminders are (or aren’t) working.
Understand how staff behave in real situations and have considerations for planning ongoing training.
3. Protecting practice systems and data (standard 3)
Could your systems be exposed or poorly set up which could create a security breach?
The offer gives you:
Checks that your internet facing systems are not accidentally open or misconfigured
A review of Microsoft 365 to confirm access, email, and security settings (add-on)
Identification of weak settings, old configurations, or risky exposure
Have more certainty that your systems are not exposed; and knowing the importance of ongoing IT servicing.
4. Secure setup of systems (standard 4)
Do you know whether your systems are set up properly, or are they on default settings?
The offer gives you:
Independent review of firewall and system security settings (if chosen)
Testing to confirm unnecessary access and services are turned off
Written evidence that systems meet common best practice expectations
Gain confidence that systems are securely configured and make a process for continuing to keep settings up to date and approving this in your systems.
-
This service does not replace practice leadership, internal policies, staff training, IT support, incident response planning, or cyber security insurance. It identifies risks and provides independent advice. Decisions about what to fix, when, and how remain with the practice.
-
Using this PenTestNZ GP cyber offer shows that a practice has taken sensible, independent steps to understand and reduce cyber risk. It provides evidence that external threats, staff phishing risk and system security have been reviewed by specialists, while recognising that overall responsibility still sits with the practice.
Last updated 16 June 2026