Careline Trust Talk to us

An example

Six moments.
Five of them
are avoidable.

Nothing here is exotic. This is the ordinary shape of an incident at a New Zealand organisation of forty to four hundred people, and at every stop there is something we could have done first.

  1. 08:42 Tuesday

    A message arrives that looks like payroll.

    The sender name is right. The domain is one hyphen away from yours. It says a migration went wrong overnight and bank details need re-confirming by four o'clock. It is well written, because it was written by someone whose whole job is writing these.

    If we had been here first

    Your staff would have seen four of these from us already, and the reporting button would be muscle memory rather than a decision.

  2. 08:44 Two minutes later

    One person out of ninety clicks it.

    Not the careless one. Usually somebody competent and busy who was already expecting a payroll email that week. The page they land on is a faithful copy of the login screen they use every morning, and they type their password into it without a flicker.

    If we had been here first

    A second factor would mean the password on its own is worth nothing, and the click would be a data point in your next training session rather than the start of an incident.

  3. 09:10 Half an hour on

    Somebody signs in as them, from somewhere else.

    The credential works, so nothing looks wrong. Mail rules get quietly added. Old files get read. If that account can reach a shared drive or a finance system, so can the person holding it now, and they will spend a fortnight looking around before they do anything you would notice.

    If we had been here first

    The assessment would already have flagged that this account could reach more than it needed to, and the reach would have been cut months ago.

1 in 5

of New Zealand's highest-impact cyber incidents last year hit public administration and safety. Agencies, councils, public order, defence. Which is to say: organisations that look a lot like yours.

National Cyber Security Centre, Cyber Threat Report 2025, covering the 2024/25 financial year

  1. Day 2 and counting

    Someone notices something odd, and hesitates.

    A supplier rings about an invoice nobody sent. A colleague mentions their inbox is behaving strangely. The gap between noticing and telling somebody is where most of the damage is done, and it is almost always caused by not knowing who to tell or worrying about looking silly.

    If we had been here first

    You would have rehearsed this in a workshop with your technical, legal, communications and privacy people, and the first call would already have a number attached to it.

  2. Week 2

    The clean-up, which is longer than anyone expects.

    Every password the account touched. Every mail rule. Every session token. Then the harder questions: what did they read, does the Privacy Act require you to notify anyone, and can you actually prove either answer. This is the part that costs the fortnight.

    If we had been here first

    Logging would already answer the questions you now need answered, and the clean-up would be a checklist rather than an archaeology project.

  3. Week 3

    The board asks what happened, and what now.

    They are not asking for a vulnerability list. They are asking three things: how bad was it, whose fault was the gap, and what does it cost to make sure it does not happen again. Answering those in plain English, with numbers attached, is the whole job.

    If we had been here first

    They would have read this document a year ago, with a ranked plan attached and a figure beside each line, and this meeting would be a progress update.

You can start at any of those six.

Most people come to us at stop four, when something already looks odd. The cheapest place to start is stop one, and the best time was last year. Tell us where you actually are.