Question one
Are we adequately protected?
Every plan starts from a defined control set, not an opinion. SMB1001 gives you a named baseline and a documented position against it.
From small business to small enterprise
Assurance, not assumptions.
See risks earlier, make better-informed technology decisions and keep the evidence ready when customers, insurers or auditors ask.
Established
Wellington, since 2005
Certified
ISO/IEC 27001:2022
Aligned
SMB1001 Bronze, Silver and Gold
Monitored
24/7 SOC for covered customers
01
The governance gap
Most organisations do not have an IT problem. They have an accountability problem.
Tickets get closed. Patches get applied. Responsive IT support keeps people working. Leadership teams, customers, insurers and boards also need evidence that risks are understood, controls are operating and improvements are being made. Layer3 combines day-to-day IT support, security and governance to keep your technology position current, measurable and repeatable.
Question one
Every plan starts from a defined control set, not an opinion. SMB1001 gives you a named baseline and a documented position against it.
Question two
For SOC customers, analysts monitor identity, endpoint and email 24/7 and report on what they did not find as well as what they did.
Question three
Auditors, insurers and enterprise customers need evidence of security maturity. Layer3 operates an ISO/IEC 27001-certified ISMS and provides clear reporting decision-makers can act on.
The outcome
Layer3 gets day-to-day IT under control, then turns operational activity into a current view of risk, clear ownership and evidence your organisation can use.
Outcome 01
Recurring issues are addressed at the source, avoidable support noise is reduced, and devices, patches and backups are managed consistently. With day-to-day IT under control, security and governance have a reliable foundation to build on.
Outcome 02
Roadmaps, lifecycle planning and budgets are reviewed against business priorities, so leadership knows what needs action and why.
Outcome 03
Controls, actions, exceptions and test results are documented when customers, insurers or auditors ask.
Outcome 04
Progress is monitored and reported, with the next priorities based on what the evidence shows.
01
Responsive IT support, proactive management and complete device lifecycle services keep your people productive and your technology dependable.
02
Layered protection across endpoints, identities and email, backed by continuous patching and human risk management.
03
SASE and zero-trust access protect your people, devices and data wherever they work.
04
The complete service: managed IT, security and secure access, with 24/7 SOC monitoring and response, AI-powered email protection, and enterprise security maturity and governance.
Evidence
Operating since 2005
21 Years
Two decades supporting New Zealand organisations, from Wellington to nationwide coverage.
The team
20+ Staff
Engineers, analysts and advisers based in New Zealand, not an offshore queue.
Security operations
24/7 SOC for covered customers
Round-the-clock monitoring and response through our managed detection platform.
Independently audited

Layer3 is certified to ISO/IEC 27001:2022, with managed-plan controls aligned to SMB1001 Bronze, Silver and Gold targets.
Trusted by
Research institutes, national associations, airports, financial services and manufacturers.
Organisations that answer to boards, regulators and members – and need clear evidence that their IT is being managed well.
Client work
Start the conversation
A documented review of your current position against the SMB1001 baseline, what it would take to improve it, and what that means for your organisation. No obligation.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation