belton
Managed IT · Cyber Security · Cloud · AI
Company profile · Accounting

Managed IT for NZ accounting firms, built around your obligations.

AML/CFT and Privacy Act 2020 compliance. Xero, MYOB, and APS expertise. Audit-ready security designed around how chartered accountants actually work. Belton IT Nexus runs and protects the technology that 469 organisations across New Zealand and Australia depend on. Privately owned since 2004.

Established 2004 Newmarket, Auckland Run / Protect / Improve / Build 2026 edition
Contentsi

What is inside.

Accounting: the brief01

Technology that protects client trust and partner sanity

Accounting firms in New Zealand sit on a uniquely sensitive data set: tax returns, IRD interactions, AML/CFT verification records, financial statements, trust account positions. The Privacy Act 2020, the AML/CFT Act 2009, and Chartered Accountants Australia New Zealand professional standards all expect verifiable controls, not best efforts.

Most managed IT providers can install Microsoft 365 and call it a day. We configure it for the way accounting practices work: client matters partitioned, IRD myIR access locked down with MFA and session monitoring, document retention aligned to the seven-year statutory minimum, and audit trails that survive a CA ANZ practice review or a DIA AML/CFT inspection.

AML/CFT
aligned controls
7-year
statutory retention
CA ANZ
practice-review ready
Xero / MYOB
practice depth
Accounting: what you work under02

The rules NZ accounting firms work under

These are obligations, not best practices. Your technology either produces the evidence when someone asks for it, or it does not.

Privacy Act 2020

Sets the baseline for how personal information is collected, stored, used, and disclosed. The Office of the Privacy Commissioner expects breach notification within 72 hours of confirming a notifiable privacy breach. For accounting firms, almost everything you handle is in scope.

AML/CFT Act 2009

Has applied to chartered accountants since 2018 for client services covering trust accounts, real estate transactions, and certain tax structuring. Requires identity verification, transaction monitoring, suspicious activity reporting, and an annual report to the DIA. Your IT setup needs to support customer due diligence (CDD) record retention for the five-year statutory minimum, with evidence the DIA can inspect.

CA ANZ professional standards

Govern client confidentiality, record retention (typically seven years for working papers), and the quality framework expected of every chartered accounting practice. CA ANZ practice review covers IT controls, file security, and continuity of access.

The problem we keep meeting03

Most businesses do not have an IT problem. They have an ownership problem.

Bits and pieces managed by everyone and no one. Costs that arrive as surprises. Controls you are told are covered but cannot actually verify. We do not sell you another tool to add to that pile. We take the whole thing off your desk and put our name on it.

469
Organisations we run and protect
97%
CSAT, last 90 days, 597 responses
15 min
Critical response, business hours
10 yr+
Average client tenure
22 yr
Privately owned, no outside investors
40
Engineers and specialists
The firm, and how it got here04

Built in a spare room. Run on relationships.

Belton did not start with capital or a grand plan. In the early 2000s Jason Agnew was training as a pilot, and the industry downturn after 2001 closed that door. So he placed an ad in the East and Bays Courier, "PC Repair Services, call Jason", with the home phone number on it. He and Amy started fixing computers from the spare room, taking every job that rang.

The flying never happened. The checklists stayed.

A few years in came the bet that named the company: the chance to acquire a small firm called IT Nexus, without the capital to fund it outright. The risk paid off. By 2008 the business had its first million dollar year and a new name, and the spare room gave way to real offices.

From there came the Microsoft partnership and the cloud years, a 24/7 security operations capability built with global partners, expansion into Australia, and the forty strong Newmarket practice serving 469 organisations today. The core has not changed: relationships first, structured delivery, and honest advice even when it costs us.

We took every job we could to learn, grow and improve. The early years were not about profit. They were about understanding what good IT support actually looked like. Jason Agnew, Founder & CEO

Why "Nexus"?

A nexus is a connection point, a series of connections linking many things. That is the job as we see it. Connecting your business to the right technology, your team to the tools they need, and your organisation to security capability it could not build alone.

2004Founded from a spare room in Auckland
2008IT Nexus acquired, first million dollar year
2010sMicrosoft partnership and the cloud years
Then24/7 SOC capability with global partners
NowNewmarket practice, New Zealand and Australia
What we do: run and protect05

Four jobs. In this order, on purpose.

You cannot secure an environment nobody owns, and you cannot improve one that is not secure. So we work the sequence: get it running properly, make it provably safe, then make it cheaper and smarter, then build the things that put you ahead.

01

Run

We become your IT department and own the day to day. Not advice about it. It.

  • Managed IT
  • Managed Devices
  • Microsoft 365
  • Cloud & Azure
  • Connectivity
  • Business VoIP

What changes: one number to call, every call answered by a person, and one team accountable for the whole environment rather than a corner of it.

02

Protect

Security operations you can verify, and show to an insurer, a board or a client.

  • 24-Hour Cyber SOC
  • Identity & Access
  • Email Security
  • Endpoint Protection
  • Backup & Recovery
  • Security Bundles

What changes: "we think we are covered" becomes evidence with a date on it, including backups somebody has actually restored from.

What we do: improve and build06
03

Improve

Honest strategy and budgets you can plan around, a year ahead rather than a quarter.

  • IT Advisory & vCIO
  • Compliance & Governance
  • Procurement
  • Licensing
  • Asset Finance
  • Sovereign Hosting

What changes: spend becomes visible and defensible, licences get right sized, and the roadmap stops being a surprise every renewal.

04

Build

AI, automation and software, applied where they genuinely help and nowhere they do not.

  • AI & Copilot Rollout
  • AI Training
  • Copilot Workshops
  • Business Automation
  • Software Development
  • Client Portal

What changes: your team gets skills rather than licences, and the repetitive work that eats their week gets handed to the platform.

How we work07

Every engagement, the same way.

Good IT is not about heroics. It is about doing the fundamentals well, every time. Five steps, refined through hundreds of transitions, not because we lack flexibility but because consistency is what delivers reliable outcomes. You always know what happens next.

Step 01

Conversation

We start by listening. What is working, what is not, and what your business needs to achieve. Not a sales pitch, a genuine discussion about whether we are the right fit. Usually 30 to 45 minutes, no slides.

Step 02

Assessment

A thorough review of your environment: network, devices, cloud, security posture, backup and licensing. We document what we find and identify the gaps. You keep the review whether or not you proceed.

Step 03

Transition

Switching providers can feel daunting. We have done it hundreds of times. The first 90 days are intensive: gathering access, deploying monitoring, fixing accumulated issues and building the documentation that ensures continuity.

Step 04

Ongoing support

Partnership mode. Your team has direct access to engineers who know your name and your setup. We monitor continuously, patch promptly, and catch problems before they affect your work. Proactive, not break-fix.

Step 05

Continuous improvement

Quarterly business reviews keep us aligned with your goals. What has changed, what is coming, and where you should be investing. Strategic conversations about your roadmap, not checkbox meetings.

Who actually looks after you08

We do not run a ticket pool. We run pods.

Small, named teams, each assigned its own clients, each backed by specialists. You know exactly who has your environment, because it is the same people every time. You will know your team by name, not a ticket number.

01

Your pod

A small, named team that knows your environment, your systems and your people. The same faces, every time.

02

Your account manager

One dedicated account manager owns the relationship: your roadmap, your reviews, your questions. You always know who to call.

03

Specialist backing

Behind every pod sits a specialist cyber team and an operations team, so deep expertise is one step away, never outsourced.

04

Always moving forward

Your environment is on our mind before you call. Proactive reviews, honest advice, and a live roadmap in the client portal that never sits still.

Working alongside your team09

Not everyone wants to outsource everything.

Some organisations have capable internal IT who just need specialist support. We work both ways.

Augment

Augment your IT team

Your internal IT handles day to day operations. We bring specialist expertise when you need it: security assessments, cloud migrations, complex projects, or escalation beyond the usual scope.

Co-managed

Split the responsibilities

Your team might handle user support while we manage infrastructure, or you run endpoints while we handle security and monitoring. Clear boundaries, regular coordination, nothing falling through the cracks.

White-label

Our bench, your brand

For IT providers who need to extend their capabilities: white-label security operations, project delivery and specialist consulting. Your clients see your brand. We provide the expertise behind it.

The people10

The names on the door.

Senior engineers, not call centres. You speak to someone who knows your business and owns the issue until it is resolved, not a rotating triage script. The people you work with do not get outsourced.

Jason AgnewJason AgnewFounder & CEO
Amy AgnewAmy AgnewCo-Founder & Director
RuthRuthOperations Manager
ShaunShaunService Delivery Manager
WarrickWarrickCSO, APAC
What stays constant11
Principle 01

Clear ownership

One team responsible for your environment. No finger pointing between vendors. When something needs fixing, we fix it.

Principle 02

Transparent communication

You know what we are doing and why. No surprises on invoices. No changes without discussion. Status updates that actually inform.

Principle 03

Documentation as standard

Your environment is documented and kept current. If something happened to us tomorrow, you would have everything you need.

Principle 04

Honest advice

We recommend what is right for your situation, not what generates the most revenue. If we are not the right fit, we will tell you.

Proof, not promises12

If you cannot verify it, it is not security.

Anyone can say they take security seriously. We can show it. We do not run tools because they are popular. We run them because they are independently audited, so the controls protecting your business are accountable to someone other than us. Every platform in our stack was chosen through deliberate due diligence and mapped to recognised standards.

ISO 27001
Aligned controls
Essential 8
Mapped and measurable
SOC 2
Type II audited vendors
FedRAMP
High, where it applies
IRAP
Protected level platforms
Microsoft
Solutions Partner

Your data stays in sovereign data centres in Auckland and Christchurch, with capacity in Sydney, Melbourne, Brisbane and Perth. We do not publish our clients' names as a matter of policy. References are always available on request.

Ways to work with us13

Simple, honest pricing.

No black box, and no surprises on invoices. Pricing is scoped to your environment rather than guessed from a table, which is why you will not find a number on this page. Enterprise grade security without the enterprise price tag.

Plan 01

Essential

The reliable foundation: your IT kept running, patched and supported, with security baked in from day one.

  • Managed IT support and helpdesk
  • Device and endpoint management
  • Microsoft 365 administration
  • Endpoint protection
  • Tested backup and recovery
  • Patching and standards baseline
Plan 02 · Most chosen

Managed

We become your IT department: proactive management, 24 hour cyber you can verify, and a senior pod that knows your business.

  • Everything in Essential
  • Proactive monitoring and management
  • 24 hour cyber and SOC capability
  • Identity, MFA and email security
  • Cloud and Azure management
  • IT advisory and quarterly reviews
Plan 03

Complete

The full practice, for organisations that treat IT as a board level asset rather than an overhead.

  • Everything in Managed
  • vCIO and IT strategy roadmap
  • Compliance and Essential Eight alignment
  • Audit ready evidence
  • AI and Copilot where they genuinely help
  • Board and insurer reporting
AccountingLegalBusiness AdvisoryMortgage & FinanceInsuranceConstructionArchitectureQuantity SurveyingManufacturingHealthcareLogisticsRetail & WholesaleHospitalityTechnologyFranchiseGlobal Operations
Start here

Ninety minutes. Then you will know exactly where you stand.

A discovery and security session that maps your whole environment, every device, control and cost, on the record. We name the real risks in plain English. You keep the findings either way, whether you hand us the keys, hand them to your current provider, or do nothing at all. No obligation, and no pitch dressed up as an audit.

New Zealand09 974 2379Level 3, 101 Carlton Gore RdNewmarket, Auckland
Australia+61 3 4803 4915Sydney, Melbourne,Brisbane and Perth
HoursMon to Fri, 8:30am to 5pm NZTExtended 6:30am to 11pm24/7 emergency cover
Belton IT Nexus Limited · Company profile, 2026 edition · Privately owned since 2004