The NCSC is handling roughly one incident per day of potential national significance.
82 of those incidents are linked to suspected state-sponsored actors, 137 to criminal or financially motivated actors. The October 2025 minimum cybersecurity baseline for public sector agencies takes effect for PSR reporting in April 2026.
Why New Zealand organisations are in the crosshairs
Five shifts shaping the New Zealand threat environment — what the NCSC is saying publicly, and what it means for local organisations.
"Not big enough" is the most dangerous assumption in NZ cyber risk
NCSC COO Michael Jagusch has called this out in the clearest possible terms. A few successful incidents can cause outsized disruption in an economy of New Zealand's size — and because the sector mix concentrates critical services in a relatively small number of organisations, attackers do not need to scale targeting to generate material national impact.
Five Eyes membership puts NZ inside the same threat environment as Australia
The 82 FY2024/25 incidents linked to suspected state-sponsored actors reflect sustained interest from state-affiliated actors. Salt Typhoon compromised at least eight US telcos and an unnamed Canadian telco in February 2025. ASIO DG Mike Burgess has publicly confirmed Salt Typhoon and Volt Typhoon attempts against Australian critical infrastructure including telecommunications — New Zealand is part of the same intelligence-sharing and targeting landscape.
Finance, energy, health, and telecommunications are named priorities
The NCSC's Cyber Threat Report 2025 explicitly names these four sectors as attractive targets for AI-amplified attacks. That maps to the global pattern — Scattered Spider in finance and insurance, Salt Typhoon in telecoms, INC and Qilin in healthcare — and tells local organisations exactly where the NCSC sees the highest demonstrated exposure.
Supply chains and hidden dependencies are the NCSC's named 2025 judgement
The NCSC's first strategic judgement for 2025 is that "threat actors are exploiting supply chains, hidden dependencies and organisational blind spots to cause impact." This mirrors Verizon's 2025 DBIR finding that third-party involvement in breaches has doubled globally, and maps directly to New Zealand's reliance on shared MSPs, outsourced IT, and Australian-headquartered providers operating trans-Tasman.
The regulatory floor is rising
The NCSC's minimum cybersecurity baseline standards for public sector agencies took effect on 30 October 2025, with PSR implementation reporting due April 2026. The baseline sits between the NZISM and the NCSC Cyber Security Framework. Combined with ongoing CERT NZ / NCSC consolidation and joint ACSC/NCSC advisories, the direction is demonstration of effective controls, not documentation alone.
What regulators and experts are saying
Many New Zealand businesses and organisations make the mistake of assuming they are not big enough, not wealthy enough or not critical enough to be a target. In the changing geostrategic environment there are a range of reasons – from financial motivation to espionage and hacktivism – why an organisation in New Zealand may be targeted.
Over recent years, the National Cyber Security Centre has dealt with about one incident per day that has the potential to cause harm at the national level. Such incidents don't just involve large corporates or big government agencies – some smaller organisations also play a crucial role in our economy and society and can be affected.
Large New Zealand companies – such as those in finance, energy, health, and telecommunications – may hold valuable data and provide critical services, making them attractive targets. The scale and speed of AI-driven attacks could overwhelm traditional security teams, especially if basic cyber hygiene is lacking.
NZ cyber incidents are escalating
The Waikato DHB ransomware led to a $16.5M insurance claim. The Mercury IT compromise cascaded across government agencies and health bodies. NZX trading was disrupted for four days. Autonomous pentesting makes persistent compliance validation achievable.
New Zealand government agencies and organisations handling government information must comply with the New Zealand Information Security Manual (NZISM), maintained by the GCSB. The NZISM is a comprehensive standard covering 20+ chapters of security controls. The Essential Eight, while an Australian framework, is increasingly adopted by New Zealand organisations as a practical cyber security baseline. Private sector entities may also be subject to sector-specific requirements — RBNZ's Guidance on Cyber Resilience for financial services, the Health Information Privacy Code for health data, and the Telecommunications (Interception Capability and Security) Act for carriers. The Privacy Act 2020 applies to all organisations handling personal information.
New Zealand's information security standard maintained by the GCSB. Applies to government agencies and organisations handling government information. Chapters covering governance, personnel security, physical security, media security, and communications security are outside the scope of autonomous penetration testing.
Increasingly adopted by New Zealand organisations as a practical cyber security baseline. Coverage mapping is identical to the Australian Essential Eight analysis.
All NZ agencies handling personal information must comply with the Information Privacy Principles and mandatory breach notification requirements.
Where NodeZero appliesWidely adopted across NZ government and private sector as a recognised information security standard, particularly for organisations with international operations.
Where NodeZero appliesApplies to NZ organisations that store, process, or transmit payment card data — including government agencies accepting online payments.
Where NodeZero appliesRelevant for NZ technology providers and managed service providers serving government or regulated industry customers.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
Privacy Act 2020 — Mandatory breach notification
In effectOrganisations must notify the Privacy Commissioner and affected individuals of breaches causing serious harm. Notifications have risen every year since mandatory reporting began — over 1,000 in 2024/25 alone. NodeZero provides continuous evidence that controls prevent "serious harm" threshold events.
RBNZ Guidance on Cyber Resilience
In effectRBNZ's principle-based Guidance on Cyber Resilience expects regulated entities to test their cyber resilience regularly and keep boards accountable, with periodic self-assessment reporting against the guidance. Evidence-based testing turns that self-assessment into demonstrable capability.
NZISM and PSR — Government security baseline
In effectNZISM is mandatory for government agencies handling classified information. PSR is mandatory for Public Service departments and core agencies (NZDF, Police, NZSIS), and is adopted as best practice by local authorities and contractors. Agencies increasingly demand evidence-based compliance, not just documentation.
Te Whatu Ora cyber uplift
In progressHealth NZ consolidated 20 DHBs with highly variable security postures. Post-Waikato DHB ransomware, significant investment in security uplift across the consolidated health system — including a NZD 75.7 million multi-year cybersecurity investment.
Find your organisation
See how the changes affect you specifically
Government & local authorities
Central government agencies and 78 local authorities. NZISM and PSR compliance requirements, largely self-assessed rather than tested.
View details →Critical infrastructure & Crown entities
Meridian Energy, Transpower, Spark, Chorus, KiwiRail, Air NZ — Crown entities and private operators running NZ's essential services.
View details →Finance & health
ANZ NZ, Westpac NZ, BNZ, ASB, Kiwibank, Te Whatu Ora — RBNZ-regulated banks and the unified health system with the largest security buyer in NZ.
View details →The only autonomous pentesting platform that is:
Move from self-assessment to proven compliance
See how NodeZero provides affordable, continuous security validation for your NZ organisation
