The National Cyber Security Centre reported three C2 or “highly significant” incidents in the first quarter of 2026 — the first occurrences at that severity level since the 2021/22 financial year.
For most New Zealand businesses that is context rather than a direct threat. But the surrounding data says something useful about where risk is moving.
What the numbers show
The NCSC received 1,249 incident reports in the third quarter of 2025, alongside a large increase in reported financial losses. In December 2025 it notified thousands of New Zealanders about potential malware infections on their devices.
In May 2026 a data breach affected the Canvas learning management system used by multiple New Zealand universities and tertiary institutions — a supply chain compromise where the entry point was a shared platform rather than each institution individually.
Separately, research published in April 2026 indicated fewer people are experiencing harm from cyber security incidents, which suggests the baseline defences are working even as high-severity incidents return.
Supply chain is where the NCSC is pointing
In August 2026 the NCSC published guidance on managing third-party suppliers, emphasising that managing a supplier is an ongoing process rather than a procurement event.
That framing matters. The Canvas breach is the pattern: attackers compromise a shared platform or a supplier and reach many organisations through one entry point. For a business, that means your security posture is only as good as the weakest supplier with access to your systems or data.
Practical steps for each significant supplier:
- What access do they actually have, and is it still necessary?
- What is their security posture, and can they evidence it?
- What are their breach notification commitments, and how fast?
- What happens to your data if they fail or you leave?
Expect your own customers to ask the same. Security questionnaires are now routine in enterprise procurement, and a business that cannot answer loses contracts on that basis alone.
The AI dimension
In June 2026 the Five Eyes cyber security agencies, including the NCSC, issued a coordinated alert on risks emerging from frontier artificial intelligence development.
For ordinary businesses the practical risk is not frontier models. It is staff entering customer data, contracts or financial information into AI tools without knowing where it goes or how long it is retained — and increasingly, agentic tools granted access to email, files and systems, which expands the attack surface meaningfully.
A short, clear position on which tools are approved and what may never be entered works better than a prohibition that will be ignored and removes your visibility.
The controls that still do most of the work
Severity of threat does not change the effectiveness of the basics:
- Multi-factor authentication, email first. It defeats the most common attack path.
- Patching, particularly internet-facing systems. The vulnerabilities used in successful attacks are usually known and patched elsewhere.
- Tested backups, offline or immutable. Ransomware targets connected backups, and a backup nobody has restored from is a hypothesis.
- Verify bank detail changes by phone, using a number you already hold. Invoice fraud remains the most financially damaging attack on New Zealand businesses, and this single procedural rule prevents most of it.
- Remove access the day someone leaves.
The obligation that runs during the incident
Under the Privacy Act 2020, where a breach has caused or is likely to cause serious harm you must notify the Privacy Commissioner and affected individuals as soon as practicable.
Assume ransomware exfiltrated data rather than only encrypting it — most now does, which makes it a privacy breach as well as an availability incident.
Write the decision path down beforehand, and keep it somewhere not dependent on the systems that may be unavailable.
The NCSC and CERT NZ both publish free guidance for New Zealand organisations, and the Office of the Privacy Commissioner publishes breach notification guidance and an online tool.
Figures: National Cyber Security Centre incident reporting and publications, Q1 2026 and Q3 2025. General information only, not legal advice.








