Three Highly Significant Cyber Incidents in a Quarter: What the NCSC Data Shows

Share Article

Q1 2026 recorded three C2 'highly significant' incidents — the first at that severity since 2021/22. What changed, and what it means for ordinary businesses.

The National Cyber Security Centre reported three C2 or “highly significant” incidents in the first quarter of 2026 — the first occurrences at that severity level since the 2021/22 financial year.

For most New Zealand businesses that is context rather than a direct threat. But the surrounding data says something useful about where risk is moving.

What the numbers show

The NCSC received 1,249 incident reports in the third quarter of 2025, alongside a large increase in reported financial losses. In December 2025 it notified thousands of New Zealanders about potential malware infections on their devices.

In May 2026 a data breach affected the Canvas learning management system used by multiple New Zealand universities and tertiary institutions — a supply chain compromise where the entry point was a shared platform rather than each institution individually.

Separately, research published in April 2026 indicated fewer people are experiencing harm from cyber security incidents, which suggests the baseline defences are working even as high-severity incidents return.

Supply chain is where the NCSC is pointing

In August 2026 the NCSC published guidance on managing third-party suppliers, emphasising that managing a supplier is an ongoing process rather than a procurement event.

That framing matters. The Canvas breach is the pattern: attackers compromise a shared platform or a supplier and reach many organisations through one entry point. For a business, that means your security posture is only as good as the weakest supplier with access to your systems or data.

Practical steps for each significant supplier:

  • What access do they actually have, and is it still necessary?
  • What is their security posture, and can they evidence it?
  • What are their breach notification commitments, and how fast?
  • What happens to your data if they fail or you leave?

Expect your own customers to ask the same. Security questionnaires are now routine in enterprise procurement, and a business that cannot answer loses contracts on that basis alone.

The AI dimension

In June 2026 the Five Eyes cyber security agencies, including the NCSC, issued a coordinated alert on risks emerging from frontier artificial intelligence development.

For ordinary businesses the practical risk is not frontier models. It is staff entering customer data, contracts or financial information into AI tools without knowing where it goes or how long it is retained — and increasingly, agentic tools granted access to email, files and systems, which expands the attack surface meaningfully.

A short, clear position on which tools are approved and what may never be entered works better than a prohibition that will be ignored and removes your visibility.

The controls that still do most of the work

Severity of threat does not change the effectiveness of the basics:

  • Multi-factor authentication, email first. It defeats the most common attack path.
  • Patching, particularly internet-facing systems. The vulnerabilities used in successful attacks are usually known and patched elsewhere.
  • Tested backups, offline or immutable. Ransomware targets connected backups, and a backup nobody has restored from is a hypothesis.
  • Verify bank detail changes by phone, using a number you already hold. Invoice fraud remains the most financially damaging attack on New Zealand businesses, and this single procedural rule prevents most of it.
  • Remove access the day someone leaves.

The obligation that runs during the incident

Under the Privacy Act 2020, where a breach has caused or is likely to cause serious harm you must notify the Privacy Commissioner and affected individuals as soon as practicable.

Assume ransomware exfiltrated data rather than only encrypting it — most now does, which makes it a privacy breach as well as an availability incident.

Write the decision path down beforehand, and keep it somewhere not dependent on the systems that may be unavailable.

The NCSC and CERT NZ both publish free guidance for New Zealand organisations, and the Office of the Privacy Commissioner publishes breach notification guidance and an online tool.

Figures: National Cyber Security Centre incident reporting and publications, Q1 2026 and Q3 2025. General information only, not legal advice.

ads-2

Explore Business Topics

Whether you’re running a business, growing your career or simply staying informed, discover expert articles from New Zealand’s most important industries.

Accounting

Tax, bookkeeping, Xero, payroll and financial reporting.

Agriculture

Farming, agribusiness, horticulture, innovation and rural industry news.

Construction

Building, trades, regulations, projects and construction industry updates.

Engineering

Engineering innovation, infrastructure, manufacturing and technical expertise.

Finance

Business finance, investing, lending, insurance and economic insights.

Health

Healthcare, medical services, wellbeing, aged care and industry developments.

Law

Commercial law, employment law, property law and legal guidance.

Logistics

Supply chains, warehousing, fulfilment, freight and logistics solutions.

Property

Commercial property, real estate, investment and market trends.

Retail

Retail trends, eCommerce, customer experience and business growth.

Technology

Artificial intelligence, cybersecurity, software and digital transformation.

Transport

Road, rail, marine, aviation and transport industry developments.