The National Cyber Security Centre released its latest quarterly snapshot of New Zealand cyber security on 22 June, covering January to March 2026. The headline number: $5.6 million in reported direct losses, up 76% on the quarter before.
The more useful detail sits below the headline. For the first time since the 2021/22 financial year, the NCSC recorded incidents in its second-highest severity category. Three of them. Sensitive data was accessed in all three, and thousands of New Zealanders were affected.
The NCSC’s own assessment is the part every business owner should read twice: the basics would have made the difference. Here are three lessons worth taking from the report.
The New Zealand cyber security numbers
The NCSC recorded 1,164 incidents between January and March, slightly up on the quarter before. Phishing and credential harvesting was the most reported category with 437 incidents. Scams and fraud came second by volume but cost the most, at around $3.8 million.
Direct losses reached $5.6 million for the quarter, and 77 incidents needed specialist technical support because of their potential national significance.
Lesson one: the worst incidents came down to basics
NCSC chief operating officer Mike Jagusch said measures like multi-factor authentication, control over who holds full network access, and protection of network edges “could have helped to defend against these incidents”. He also pointed out that organisations have a legal obligation to protect customer information, not just a commercial one.
That matches what the Privacy Commissioner found in May when the inquiry into the Manage My Health and Health NZ breach wrapped up. Patient records were stolen and offered for sale after a December 2025 ransomware attack. The inquiry found no single point of failure, rather a combination of gaps in access control, MFA that wasn’t required for all users, and weak incident detection.
None of that is exotic. It’s the work a competent IT provider does in the first month.
Lesson two: AI is shortening the time you have to patch
On 18 June the NCSC published guidance on frontier AI models for people who defend networks. The short version: AI now helps attackers find and exploit software vulnerabilities faster than before, so the gap between a flaw becoming public and someone using it against you keeps shrinking.
For a small business, that changes the maths on updates. Patching servers and computers whenever someone gets around to it was always risky. Now it’s an open door. Patching needs to be scheduled, monitored and someone’s actual job.
Lesson three: one bad incident carries almost all the cost
Of everything reported last quarter, just 42 incidents of $10,000 or more produced $5.4 million in losses. That’s 97% of the total.
So cyber risk for a business isn’t a steady drip of small annoyances. It’s one bad day. And the NCSC’s figures only count direct loss. Downtime, recovery work, legal advice and awkward client conversations sit on top. That’s why prevention is the cheap option, even when it doesn’t feel like it on the invoice.
What this means for your business
You don’t need an enterprise security budget to stay out of the NCSC’s next report. The gaps it keeps identifying are fixable with disciplined basics.
Start with MFA on every account that supports it, especially email and anything holding customer data. Review who has admin rights, because many businesses have more people with full access than anyone can explain. Get patching onto a schedule with reporting, so you know it’s happening rather than assuming. And harden your email setup, since phishing remains the most reported incident type in the country.
If Microsoft 365 runs your business, start there. Our Microsoft 365 and Security service covers MFA rollout, security hardening and ongoing monitoring, and managed IT clients get scheduled patching as part of the standard per-seat service.
Common questions
Who are the NCSC?
The National Cyber Security Centre is part of the GCSB. It tracks cyber incidents across New Zealand, publishes free guidance, and runs a reporting service any business can use. Its quarterly Cyber Security Insights reports are free on ncsc.govt.nz.
We’re a small firm. Would attackers really bother with us?
Yes. Phishing and credential harvesting, the most reported category, is sent in bulk and doesn’t care who opens it. Size isn’t protection. Working basics are.
What should we do if we’re hit?
Contain it first: disconnect affected machines and change passwords from a clean device. Report it to the NCSC. If personal information was accessed and serious harm is likely, you must notify the Privacy Commissioner, and the expectation is within 72 hours. And call your IT provider before deleting anything, because evidence matters.
If you’re not sure how your business measures up against the basics the NCSC keeps pointing to, it’s worth finding out before someone else does. Book an IT Review and we’ll go through it with you.