Overview
The CERT NZ Top Ten Critical Controls is a cybersecurity best-practice framework developed by New Zealand's National Cyber Security Centre (NCSC) and CERT NZ to help organizations prioritize the security measures that are most effective at preventing, detecting, and containing cyber threats. The framework identifies ten critical controls, including patch management, multi-factor authentication, password management, logging and alerting, asset lifecycle management, backups, application control, least privilege, network segmentation, and secure macro configurations. Based on threat intelligence, incident reporting, and real-world cyber attack trends, the controls provide a practical, risk-based approach for strengthening organizational cyber resilience and protecting information systems, data, and business operations from common cyber threats.