DrochaidHorizon3.ai
NodeZero/Industries/New Zealand
The state of play — New Zealand, 2026

The NCSC is handling roughly one incident per day of potential national significance.

82 of those incidents are linked to suspected state-sponsored actors, 137 to criminal or financially motivated actors. The October 2025 minimum cybersecurity baseline for public sector agencies takes effect for PSR reporting in April 2026.

5,995
cyber reports received by the NCSC in FY2024/25 — 4,343 from individuals and 1,321 from organisations.
NCSC Cyber Threat Report 2025
331
incidents identified as of potential national significance in FY2024/25 — 82 linked to suspected state-sponsored actors, 137 to criminal or financially motivated actors.
NCSC Cyber Threat Report 2025
$12.4M → $3.2M
direct financial loss reported to NCSC shifted sharply between Q3 and Q4 2025 — a handful of major incidents drive the quarterly numbers in an economy of New Zealand's size.
NCSC Quarter Four Cyber Security Insights 2025
The trend

Why New Zealand organisations are in the crosshairs

Five shifts shaping the New Zealand threat environment — what the NCSC is saying publicly, and what it means for local organisations.

"Not big enough" is the most dangerous assumption in NZ cyber risk

NCSC COO Michael Jagusch has called this out in the clearest possible terms. A few successful incidents can cause outsized disruption in an economy of New Zealand's size — and because the sector mix concentrates critical services in a relatively small number of organisations, attackers do not need to scale targeting to generate material national impact.

Five Eyes membership puts NZ inside the same threat environment as Australia

The 82 FY2024/25 incidents linked to suspected state-sponsored actors reflect sustained interest from state-affiliated actors. Salt Typhoon compromised at least eight US telcos and an unnamed Canadian telco in February 2025. ASIO DG Mike Burgess has publicly confirmed Salt Typhoon and Volt Typhoon attempts against Australian critical infrastructure including telecommunications — New Zealand is part of the same intelligence-sharing and targeting landscape.

Finance, energy, health, and telecommunications are named priorities

The NCSC's Cyber Threat Report 2025 explicitly names these four sectors as attractive targets for AI-amplified attacks. That maps to the global pattern — Scattered Spider in finance and insurance, Salt Typhoon in telecoms, INC and Qilin in healthcare — and tells local organisations exactly where the NCSC sees the highest demonstrated exposure.

Supply chains and hidden dependencies are the NCSC's named 2025 judgement

The NCSC's first strategic judgement for 2025 is that "threat actors are exploiting supply chains, hidden dependencies and organisational blind spots to cause impact." This mirrors Verizon's 2025 DBIR finding that third-party involvement in breaches has doubled globally, and maps directly to New Zealand's reliance on shared MSPs, outsourced IT, and Australian-headquartered providers operating trans-Tasman.

The regulatory floor is rising

The NCSC's minimum cybersecurity baseline standards for public sector agencies took effect on 30 October 2025, with PSR implementation reporting due April 2026. The baseline sits between the NZISM and the NCSC Cyber Security Framework. Combined with ongoing CERT NZ / NCSC consolidation and joint ACSC/NCSC advisories, the direction is demonstration of effective controls, not documentation alone.

On the record

What regulators and experts are saying

Many New Zealand businesses and organisations make the mistake of assuming they are not big enough, not wealthy enough or not critical enough to be a target. In the changing geostrategic environment there are a range of reasons – from financial motivation to espionage and hacktivism – why an organisation in New Zealand may be targeted.
Michael Jagusch
Chief Operating Officer, NCSC
December 2025·NCSC
Over recent years, the National Cyber Security Centre has dealt with about one incident per day that has the potential to cause harm at the national level. Such incidents don't just involve large corporates or big government agencies – some smaller organisations also play a crucial role in our economy and society and can be affected.
NCSC
Cyber Threat Report 2025 foreword
December 2025·NCSC
Large New Zealand companies – such as those in finance, energy, health, and telecommunications – may hold valuable data and provide critical services, making them attractive targets. The scale and speed of AI-driven attacks could overwhelm traditional security teams, especially if basic cyber hygiene is lacking.
NCSC
Cyber Threat Report 2025
December 2025·NCSC
What is now required

NZ cyber incidents are escalating

The Waikato DHB ransomware led to a $16.5M insurance claim. The Mercury IT compromise cascaded across government agencies and health bodies. NZX trading was disrupted for four days. Autonomous pentesting makes persistent compliance validation achievable.

New Zealand government agencies and organisations handling government information must comply with the New Zealand Information Security Manual (NZISM), maintained by the GCSB. The NZISM is a comprehensive standard covering 20+ chapters of security controls. The Essential Eight, while an Australian framework, is increasingly adopted by New Zealand organisations as a practical cyber security baseline. Private sector entities may also be subject to sector-specific requirements — RBNZ's Guidance on Cyber Resilience for financial services, the Health Information Privacy Code for health data, and the Telecommunications (Interception Capability and Security) Act for carriers. The Privacy Act 2020 applies to all organisations handling personal information.

Frameworks that apply
NZISM — New Zealand Information Security Manual

New Zealand's information security standard maintained by the GCSB. Applies to government agencies and organisations handling government information. Chapters covering governance, personnel security, physical security, media security, and communications security are outside the scope of autonomous penetration testing.

ASD Essential Eight Maturity Level 2

Increasingly adopted by New Zealand organisations as a practical cyber security baseline. Coverage mapping is identical to the Australian Essential Eight analysis.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

Privacy Act 2020 — Mandatory breach notification

In effect

Organisations must notify the Privacy Commissioner and affected individuals of breaches causing serious harm. Notifications have risen every year since mandatory reporting began — over 1,000 in 2024/25 alone. NodeZero provides continuous evidence that controls prevent "serious harm" threshold events.

RBNZ Guidance on Cyber Resilience

In effect

RBNZ's principle-based Guidance on Cyber Resilience expects regulated entities to test their cyber resilience regularly and keep boards accountable, with periodic self-assessment reporting against the guidance. Evidence-based testing turns that self-assessment into demonstrable capability.

NZISM and PSR — Government security baseline

In effect

NZISM is mandatory for government agencies handling classified information. PSR is mandatory for Public Service departments and core agencies (NZDF, Police, NZSIS), and is adopted as best practice by local authorities and contractors. Agencies increasingly demand evidence-based compliance, not just documentation.

Te Whatu Ora cyber uplift

In progress

Health NZ consolidated 20 DHBs with highly variable security postures. Post-Waikato DHB ransomware, significant investment in security uplift across the consolidated health system — including a NZD 75.7 million multi-year cybersecurity investment.

Platform credentials

The only autonomous pentesting platform that is:

NZISM
Control-by-control
GCSB-aligned
NZ Privacy Act 2020
Reachability proof
NDB scheme
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Move from self-assessment to proven compliance

See how NodeZero provides affordable, continuous security validation for your NZ organisation