In February, the Government released New Zealand’s Cyber Security Strategy 2026-2030 alongside a two-year Action Plan and a discussion document proposing tougher rules for critical infrastructure operators. Consultation on those proposals closed in April. For boards in finance, energy, telecommunications, water, health, transport and defence, the direction of travel is now clear: higher minimum standards, real penalties, and personal liability for getting it wrong. For everyone else, the temptation is to file this under “not my problem.” That would be a mistake.
A higher bar for critical infrastructure, with teeth
The discussion document sets out a new cyber security regime built around seven essential services: communications and data, defence, energy, finance, health, transport and water. It proposes a minimum level of cyber risk management for every entity in those sectors, backed by financial penalties for non-compliance and the prospect of personal criminal liability for directors who fail to meet their obligations. This is a genuine shift. Cyber risk oversight has been a soft expectation for NZ boards for years. Under the new regime, for entities caught by it, it becomes a statutory duty with consequences attached.
Privacy Act penalties are coming too
Running alongside the infrastructure reforms is a quieter but arguably more far-reaching change. The Cyber Security Action Plan 2026-2027 directs the Ministry of Justice to advise on introducing a civil pecuniary penalty regime to the Privacy Act 2020, something New Zealand has lacked compared with Australia and other comparable jurisdictions. A new offence is also being considered for anyone who knowingly views, holds or distributes personal information they know has been unlawfully obtained. Unlike the critical infrastructure rules, the Privacy Act sits over every organisation in the country, regardless of sector or size. If a pecuniary penalty regime lands as proposed, the cost of a poorly handled breach changes materially, and not just for the big end of town.
Why mid-market Directors should care now
None of this requires you to be a regulated critical infrastructure entity to feel the effects. Three flow-on risks are worth putting in front of your board this year. First, supply chain due diligence. Regulated entities will be pushed to demonstrate a minimum standard of cyber risk management across their own supply chains, and that scrutiny lands on the mid-market businesses that supply them. Expect more security questionnaires, audit rights and contractual cyber clauses from customers who are themselves caught by the new regime. Second, the Privacy Act exposure applies regardless of sector. Any organisation holding customer or employee personal information carries this risk the moment a pecuniary penalty regime is legislated. Third, insurer and lender expectations tend to track regulatory direction. As the standard for “reasonable” cyber risk management rises for critical infrastructure, it shifts the benchmark insurers and capital providers use to assess everyone else.
What good governance looks like from here
Waiting for legislation to land before acting is the wrong instinct, but so is over-correcting. Most mid-market organisations do not need, and cannot justify the cost of, full accreditation against a standard like ISO 27001. What they need is a clear, defensible picture of where they actually stand, and a plan to close the gaps that matter most.
This is the gap our GRC product, Minimum Viable Protection (MVP), is built to close. It scores both a board’s cyber risk appetite and the organisation’s actual cyber posture against controls aligned to ISO 27001:2022, the NIST Cybersecurity Framework and CIS Controls v8, then turns that into a pragmatic remediation plan weighted to your specific exposure across revenue, reputation, regulatory and personal information risk. The aim deliberately isn’t full standards-based accreditation where it isn’t cost-justified. It’s reaching your organisation’s minimum viable protection state: enough control, in the right places, proportionate to what you actually have to lose.
The takeaway
The Strategy and Action Plan are a signal of where New Zealand’s cyber regulation is heading over the next four years, not a one-off announcement to note and move past. Stricter standards are coming, for critical infrastructure directly and for everyone else indirectly through supply chains, insurers and an eventual Privacy Act penalty regime. The organisations that act now, in a measured and proportionate way, will be ahead of the curve. The ones that wait tend to face one of two outcomes: expensive remediation done under urgency once a customer or regulator demands it, or a breach they weren’t sufficiently prepared for. If you want a clear view of where your organisation sits against this direction of travel, that is a conversation worth having with your virtual CISO or vCIO now.

