Cybersecurity

Managed detection and response for New Zealand organisations

IT Works Shield watches your environment around the clock, so a problem at 2am is handled at 2am rather than discovered the next morning.

Why this matters

Attacks do not wait for Monday

Most organisations have some form of antivirus or endpoint protection in place, and most of it works well enough during the day when someone is watching. The gap opens after hours, on weekends and over the Christmas break, when an alert fires and nobody sees it until the next working day.

That gap is where the damage happens. An attacker who gets in on a Friday evening has the whole weekend to move through an environment before anyone notices.

Shield closes that gap. Detection and response run continuously, and the alerts that matter reach a person who can act on them.

What Shield covers

Endpoints and identities, watched together

Two things get attacked most: the devices your people work on, and the accounts they sign in with. Shield covers both, because protecting one without the other leaves an obvious way in.

Endpoint detection and response

Continuous monitoring across Windows, macOS and Linux. Threats are isolated before they spread, and we find the persistent footholds that traditional antivirus consistently misses.

Identity protection

Monitoring of your Microsoft 365 environment for stolen session tokens, compromised accounts, rogue applications and hidden inbox rules. These are the attacks that walk straight past multi-factor authentication.

24/7 monitoring and threat hunting

Your environment is watched around the clock by a dedicated security operations centre, with analysts actively hunting for attacker behaviour rather than waiting for an alarm to go off.

Alerts you can act on

Every alert is validated before it reaches anyone, so you hear about real threats and not about noise.

The threats that matter

The attacks that get past everything else

Most organisations already have antivirus and multi-factor authentication in place, and assume that covers it. These are the things that get through anyway.

Session hijacking

Attackers steal the session token that keeps someone signed in, then load it into their own browser. No password needed, and multi-factor authentication never gets asked. Shield detects the takeover and shuts it down.

Rogue applications

A malicious app quietly connected to your Microsoft 365 tenant can extract data and keep access long after a password change. Shield finds them and removes them.

Hidden inbox rules

Silent forwarding rules are a hallmark of business email compromise, often set up weeks before the invoice fraud lands. Shield spots them and reverses them.

Persistent footholds

The mechanisms attackers leave behind so they survive a reboot or a password reset. This is the gap traditional antivirus leaves open, and it is where Shield spends most of its attention.

Ransomware in its first minutes

Decoy files placed quietly across your environment trigger the moment encryption begins, so containment starts in minutes rather than after the damage is done.

Your internet facing gaps

Your external footprint is checked for the exposures attackers look for first, before they find them.

Choosing your level

Three levels, depending on what you need to prove

Not every organisation needs the same depth of coverage. A twenty person business and a council with insurance and audit obligations are solving different problems, so Shield comes in three levels.

Most organisations start at Advanced. It is the level we recommend by default because it covers the things that come up most often.

IT Works Shield

Foundational protection for organisations that need reliable cover without complexity.

  • Endpoint detection and response across Windows, macOS and Linux
  • Identity protection for Microsoft 365
  • 24/7 monitoring and threat hunting
  • Automated containment of confirmed threats
  • Managed Microsoft Defender antivirus
  • Ransomware canaries for early warning
  • Monthly reporting
  • Onboarding and baseline setup included
Recommended

IT Works Shield Advanced

Active defence for organisations where downtime or a breach would cause real disruption.

  • Everything in Shield
  • Endpoint and identity security posture management
  • Ongoing tuning and policy review, so protection keeps pace with how your organisation actually works
  • Priority handling and escalation through IT Works
  • Support for your people during an incident
  • Monthly reporting with commentary and recommendations
  • Quarterly security reviews

IT Works Shield Complete

Full visibility for organisations with compliance, insurance or audit obligations to satisfy.

  • Everything in Shield Advanced
  • Log collection across endpoints, firewalls, VPNs and identity systems
  • Log retention for one or seven years, depending on your obligations
  • Security event correlation across your environment
  • Compliance reporting and audit ready evidence
  • Quarterly reviews with a forward roadmap
How pricing works

You pay for what you protect

Shield is priced on the number of people and systems you need covered, so the cost scales with the size of your organisation rather than sitting at a fixed rate that suits nobody. A team of fifteen pays for fifteen. A team of two hundred pays for two hundred, at a better rate per person.

Shield Complete also takes into account how many systems feed logs into the platform, since log volume varies a lot between organisations.

It scales with you

Add people and the cost moves with you. There is no step change or renegotiation when you grow.

It gets better with volume

Larger environments cost less per person. If you are over a hundred users, that difference is meaningful.

There are no surprises

One monthly figure, agreed up front, covering the level you have chosen. Onboarding and baseline setup are included, not billed separately.

We will give you a firm number once we know how many people you need to cover and which level suits your obligations. That is usually a fifteen minute conversation.

When something happens

Who actually responds

This is the question worth asking any security provider, and the answers vary more than you would expect.

Shield includes 24/7 monitoring and automated containment as standard, delivered through a dedicated security operations centre that runs around the clock. When a threat is confirmed it is isolated immediately, whatever the hour, and a clear incident report follows.

IT Works is your local team. We configure the environment, tune it to how your organisation actually works, review the reporting with you and handle anything that needs a conversation rather than a ticket.

Where organisations differ is what happens in the hours after containment. Some are comfortable picking things up the following morning, knowing the threat is already contained. Others want someone from IT Works engaged immediately, at any hour, working the incident and keeping them informed.

That second option is available as an addition to any level. We keep it separate and priced separately so you can see exactly what it costs and decide whether you need it, rather than paying for it quietly inside a bundle.

Why IT Works

Monitoring is only half of it

Plenty of providers can sell you a security product. The difference shows up in what happens around it.

We already know your environment

For managed clients, the team reviewing your security is the same team that supports your people and manages your systems. There is no handover and no explaining your setup to a stranger mid incident.

We work to recognised standards

IT Works holds SMB1001:2025 Gold certification and is working through SOC 2 Type II. When your insurer, auditor or board asks how your provider is assessed, there is a documented answer.

Reporting you can hand upward

Monthly reporting written to be read by people who are not technical, so you can take it into a board meeting without translating it first.

Shield is built on the Huntress managed security platform, chosen because it was designed for organisations of your size rather than scaled down from an enterprise product. See the technologies we work with.

Next step

Find out where you stand

If you are not sure what you currently have in place, start with our free Security Health Check. Twelve questions, no obligation, and a clear picture of where your gaps are.

If you already know you need 24/7 cover, talk to us and we will size it for your organisation.