Skip to main content

New Zealand’s light-touch era of cyber regulation is ending. The Government’s Cyber Security Strategy 2026-2030, its two-year Action Plan and the critical infrastructure consultation released alongside them signal a decisive shift: higher standards, real penalties, and for the first time, personal criminal liability for directors. Boards that treat cyber security as an IT line item should read the direction of travel carefully. The rules are still being written, but the expectations are already clear.

What the Government has proposed

Three developments matter most for directors.

First, the critical infrastructure consultation proposes mandatory cyber security obligations for operators of seven essential services: communications and data, defence, energy, finance, health, transport, and water. Entities caught by the regime would need to maintain a risk management programme aligned with an internationally recognised framework, report significant cyber incidents, and meet prescribed minimum requirements.

Second, the penalties have teeth. The discussion document proposes fines of up to NZD 5 million or 2 per cent of annual turnover for the most serious entity-level breaches. Directors of critical infrastructure entities would be personally responsible for compliance with certain minimum requirements, with personal criminal liability of up to NZD 100,000 for a serious breach and NZD 500,000 for a critical breach.

Third, the Action Plan revives a long-standing proposal to introduce a civil pecuniary penalty regime under the Privacy Act 2020. The Office of the Privacy Commissioner has argued for years that New Zealand’s enforcement settings lag comparable jurisdictions. Recent high-profile health data breaches have strengthened that case. If adopted, financial penalties for privacy failures would apply well beyond critical infrastructure, reaching most organisations that hold personal information.

Public consultation on the critical infrastructure framework closed on 19 April 2026. The Government is now weighing submissions, and legislation is expected to follow.

Why this matters outside the seven sectors

Most mid-market businesses will not be designated critical infrastructure. That is not a reason to relax.

The proposals set a public benchmark for what adequate cyber governance looks like. Once Parliament defines minimum requirements and attaches personal liability to them, that standard will inform how courts, insurers, customers and regulators assess every organisation’s conduct after an incident. Directors’ existing duties of care under the Companies Act 1993 do not change, but the yardstick against which they are measured does.

There is also a supply chain effect. Designated operators will be required to manage risk across their suppliers. If your business sells into finance, health, energy or telecommunications, expect security questionnaires, contractual security clauses and incident notification obligations to become conditions of doing business.

What boards should do now

The practical response does not require waiting for legislation.

Put cyber risk on the board agenda as a standing item, owned by the board rather than delegated wholesale to IT. Directors need enough fluency to ask the right questions: what are our critical systems and data, what would a serious incident cost, and how quickly would we know about it?

Embed cyber security in the enterprise risk framework with defined appetite, controls and reporting. Align the security programme to a recognised framework so that maturity can be measured and evidenced. Tighten the controls that consistently determine incident outcomes: access management, multi-factor authentication, encryption, and third-party supplier oversight.

Test the incident response plan properly. A plan that has never been exercised will not survive contact with a real breach, and the proposed reporting obligations will compress the time available to make good decisions.

Finally, document the board’s engagement. If personal liability arrives in the form proposed, the ability to evidence informed, active governance will be the difference between a defensible position and an indefensible one.

The takeaway

New Zealand is moving from encouragement to enforcement on cyber security. Directors of critical infrastructure entities face the sharpest exposure, but the governance expectations now taking shape will apply, formally or informally, to every board. The organisations that start now will meet the new regime as a formality. Those that wait will meet it as a crisis.

This is exactly the gap Unisphere’s Minimum Viable Protection (MVP) framework is designed to close. MVP gives boards a structured assessment of cyber risk appetite at governance level, measures current cyber posture against ISO 27001:2022, the NIST Cybersecurity Framework (NIST CSF) and CIS Controls v8, and delivers a prioritised roadmap for remediation. The result is a defensible, evidence-based picture of where the organisation stands and a clear sequence for closing the gaps that matter most. Boards that complete this work now get a head start on inevitable legislation, rather than being caught lacking once it is invoked.

Learn more at mvp.kiwi, or talk to Unisphere Solutions about board-level cyber governance at unisphere.co.nz.

Discover more from Unisphere Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading