What CyberCrest delivers

One stack. One specification. One organisation accountable for it.

CyberCrest provides the IT support services New Zealand organisations need delivered as one engineered system rather than seven separate purchases: networks, wireless, security, surveillance, access control, voice, servers and ongoing operations. Most engagements span several of these at once, and that is deliberate — the interfaces between them are where the majority of faults live.

Start a conversation →
The stack

Every layer depends on the one beneath it.

A phone system is only as good as the network carrying it. Cameras are only as reliable as the power backing them. A backup only counts if someone has restored from it. Buy those pieces from four suppliers and every fault becomes a negotiation about whose responsibility it is, usually conducted while the site is not trading.

CyberCrest holds the specification for the whole stack, from the cable in the wall to the application on the desk. One design, one document set, one organisation to call, and no gap between where the cabling contractor's responsibility ends and the software vendor's begins.

Start a conversation →
Service stack — layered dependencyALL LAYERS IN SCOPE
APPLICATIONS3CX voice · UniFi Protect · UniFi AccessL6SYSTEMSServers · Microsoft 365 · cloud backup & recoveryL5SECURITYFirewall policy · IDS/IPS · DNS filtering · VPNL4CONNECTIVITYWiFi 6 / 7 · fibre · WAN failover · LTE backupL3NETWORKRouting · PoE switching · VLAN segmentationL2PHYSICALCat6 / 6A cabling · racks · UPS & metered powerL1MANAGED OPERATIONSMonitoring · patchingChange control · supportEACH LAYER DEPENDS ON THE ONE BELOW — SPECIFIED TOGETHER, DOCUMENTED TOGETHER
Services

Nine disciplines within the IT support services New Zealand sites actually need.

Take one discipline, take several, or hand over the whole environment. Every engagement opens with an assessment so the recommendation is shaped by the site rather than by a price list.

Network

Network design and infrastructure

Segmented, documented networks built on Ubiquiti UniFi and designed once, properly, so they carry whatever gets added to them over the following decade.

  • Topology design and VLAN segmentation
  • PoE switching with per-port policy and remote restart
  • Cat6 and Cat6A structured cabling to AS/NZS 3080, certified and tested
  • Racks, patching, comms cabinets and seismic restraint where required
  • Addressing plan, port schedule and as-built documentation as standard
Network →
Wireless

WiFi design and connectivity

Coverage modelled from a survey of the actual building, and an internet connection that does not take the site down when a circuit fails.

  • RF survey, interference scan and client density assessment
  • WiFi 6 and WiFi 7 design with WPA3 throughout
  • High-density, warehouse, outdoor and multi-building coverage
  • Fibre provisioning, WAN failover and automatic LTE cutover
  • Point-to-point links between buildings, yards and rural sites
  • Starlink provisioning where fixed-line service is impractical
Connectivity →
Security

Firewalls and network security

A genuine security appliance between the internet and everything that matters, with policy written for the site instead of left on the factory defaults.

  • Next-generation firewall policy and periodic rule review
  • Intrusion detection and prevention with live signature updates
  • DNS-layer and content filtering across every device, including those that cannot run endpoint software
  • WireGuard VPN and site-to-site tunnels, certificate-based
  • Zone-based segmentation with default-deny between zones
Security →
Surveillance

CCTV and access control

UniFi Protect camera systems engineered as network infrastructure, recording to hardware inside the building and isolated from the rest of the network.

  • DORI coverage modelling and camera selection per position
  • G6-series 4K cameras with on-device inference
  • Local NVR, storage sizing and retention policy
  • Licence plate capture at gates, driveways and car park entries
  • UniFi Access door control, credential management and audit trail
Surveillance →
Voice

3CX phone systems

Business telephony running on a network engineered to carry it, with call quality treated as a design output rather than a hope.

  • 3CX deployment, on-premises or hosted
  • SIP trunk provisioning and number porting
  • Handsets, softphones and mobile applications
  • Call routing, IVR, ring groups and out-of-hours handling
  • QoS prioritisation enforced end-to-end across the LAN and WAN
Enquire →
Systems

Servers, cloud and backup

Storage and systems specified to the workload, with a backup regime somebody has actually restored from.

  • Server specification, deployment and hardening
  • Microsoft 365 tenancy, identity and conditional access
  • Cloud backup and offsite replication
  • NAS and on-premises storage
  • Documented recovery procedure with scheduled restore testing
Enquire →
Resilience

Power and continuity

The difference between a site that rides out a fault and a site that stops trading until somebody drives across town.

  • UPS sizing with runtime specified against the critical load
  • Automatic WAN failover and LTE cutover
  • Metered PDUs and documented power budget
  • Rack builds, labelling, port mapping and seismic bracing to NZS 4219
  • Generator and standby interface where the site has one
Resilience →
Support

IT support and managed operations

Ongoing custody of the environment: monitoring, patching, change control and a defined escalation path with a response window in writing.

  • Helpdesk and fault resolution
  • Monitoring, alerting and scheduled health reporting
  • Firmware and patch management with a tested rollback position
  • Configuration backup and formal change control
  • Periodic security and policy review
Enquire →
Advisory

Assessment and architecture

Sometimes the useful deliverable is an independent view of what is already installed, or of what somebody else has quoted.

  • Current-state assessment and risk register
  • Target-state architecture and specification
  • Vendor and quotation review
  • Fit-out planning and cable schedules for new premises
  • Multi-site standardisation and technology roadmap
Enquire →
Sectors

Where these systems get deployed.

The engineering is the same everywhere. What changes is the load, the regulatory frame and what the site cannot afford to lose.

Commercial — retail and hospitality

Payment isolation to PCI DSS expectations, guest wireless kept away from the till, camera coverage at points of sale and back-of-house, and uptime through trading hours.

Office — corporate workspace

Density-modelled wireless, clean meeting-room performance, identity-aware access, and structured cabling that survives a churn of desk layouts.

Enterprise — data centre and core infrastructure

Redundant paths, documented change control, capacity headroom and a configuration baseline that can be audited.

Industrial — factories and manufacturing

Segregation of operational technology from business systems, hardened enclosures, PoE reach across a plant, and RF planning around metal and machinery.

Logistics — warehouses and distribution

Coverage over racking that changes shape, scanner roaming without session drops, yard and gate camera coverage, and licence plate capture at entries.

Education — schools and campuses

Content filtering, roll-based access, high-density wireless in teaching spaces, multi-building links and clear privacy handling for camera footage.

Healthcare — clinics and hospitals

Isolation of clinical systems, resilient connectivity, controlled physical access and strict retention discipline for anything capturing patients.

Agriculture — farms and rural sites

Long-range point-to-point links between sheds, yards and the house, Starlink where fixed-line service is impractical, power resilience where supply is unreliable, and cameras that survive dust, stock and weather.

Recreation — sports and leisure

High-density wireless under peak crowd load, outdoor coverage, entry control and camera coverage across grounds and car parks.

Residential — homes and home offices

Perimeter and approach coverage, segregated home-office traffic, whole-home wireless designed from a survey rather than a mesh kit, and recording held on the property.

Tell us about the site →
Standard platform

A deliberately narrow technology standard.

We specify a small number of platforms and know them to depth. Ubiquiti UniFi covers routing, switching, wireless, surveillance and access control under one management plane, which removes an entire class of integration fault and removes per-device licensing from the running cost. 3CX handles voice. Microsoft 365 handles identity and productivity. Where a requirement genuinely sits outside that standard, we say so rather than force it.

  • Ubiquiti UniFi
  • UniFi Protect
  • UniFi Access
  • WiFi 7
  • 3CX
  • Microsoft 365
  • WireGuard

CyberCrest is an accepted member of the Ubiquiti UniFi Partner Program.

Engagement

Three ways to engage.

Every engagement opens with a short conversation at no cost. If there is a fit we scope an assessment; if there is not, we say so early.

Project

Fixed scope

Defined deliverable, fixed price, documented acceptance criteria. Most installations and fit-outs run this way.

Retainer

Managed operations

Monthly agreement covering monitoring, maintenance, patching and a defined response window.

Advisory

Consulting

Architecture review, vendor assessment and independent second opinion, billed by time.

Next

Not sure which of these you need?

Most organisations are not, and that is what the first conversation is for. Describe what is not working and we will tell you which discipline it actually sits in — including when the answer is that it is not one of ours.