Forget the abstract AI scare stories. The number that should unsettle every board in the country is four. The National Cyber Security Centre handled 369 incidents of potential national significance in 2025/26, up from 331, with four rated C2 Highly Significant, as many as the entire previous decade combined. They are also the first cybercrime incidents of that severity in five years.
This is not a forecast. These attacks have already landed on New Zealand organisations, and the NCSC is explicit about whose job it is to respond.
Fewer attacks, harder hits
On the surface, the headline figure looks like progress. Total incident reports fell to 4,673 in 2025/26 from 5,995 the year before, while 66 incidents involved reputational loss and 32 caused operational impact. Read together with the rise in nationally significant cases, the pattern is plain. Attackers are hitting less often, but when they hit, they hit properly.
That is the severity paradox boards need to understand. A falling count of phishing reports from the public tells a director almost nothing about whether their own organisation is exposed to the kind of breach that takes systems offline or leaks customer data for weeks before anyone notices.
The names are already on the list
The NCSC’s Cyber Threat Report 2026 cites the theft of more than 99,000 patient records from Manage My Health and the breach of the Canvas learning platform used by the country’s largest educational institutions, and warns that frontier AI models capable of finding zero-day vulnerabilities and automating attacks that currently need human control could be in malicious hands by early 2027.
The most instructive case, though, involved no clever code at all. A North Korean operative posing as an IT contractor was hired by a New Zealand business. That is a recruitment failure, a vetting failure and a governance failure before it is a technical one. NCSC deputy director-general Catriona Robinson said in response that it is up to chief executives and senior leaders to manage cyber security inside their organisations.
It is hard to see how anyone could still argue this belongs in the server room. When the attack vector is a hiring decision, the risk sits with whoever signs off the hiring process.
AI changes the clock speed
The AI element matters because it compresses the time organisations have to react. Newsroom reports that in June a rogue AI agent managed by OpenAI attacked an Australian health website, and the Australian government reportedly did not learn of the breach for two months. Robinson describes the threats in the report as a tangible risk of business disruption.
She flagged the same trajectory in June, when New Zealand joined its Five Eyes partners in warning leaders about AI-driven risk. Speaking to RNZ at the time, she said the speed, scale and sophistication of threats would get “faster and faster” and that “it’s going to be faster than most organisations are prepared for”. She also noted that organisations which once needed to apply tens of software patches now face hundreds.
That patching point is the practical nub. If a frontier model can find and exploit a vulnerability in hours, a quarterly patch cycle is not a security posture. It is an invitation.
The fix is management, not regulation
What is refreshing about the NCSC’s prescription is how unglamorous it is. Reduce your attack surface, accelerate patching and get the fundamentals right. There is no call for a new regulator, a compliance regime or another layer of reporting paperwork. The agency is essentially telling business that competent management and clear accountability will do more than any statute.
That puts the onus squarely on boards. Directors should be asking a short list of pointed questions now. How fast do we patch critical systems, measured in days, not quarters? Who verifies the identity of remote contractors with privileged access? If a breach went undetected for two months, what would we lose? And does our cyber insurance actually cover operational disruption and reputational damage, or mainly the direct financial loss that the newer attack types are least likely to cause?
That last question deserves particular attention. As attacks shift towards AI-enabled social engineering and automated exploitation, the damage looks less like a stolen invoice payment and more like weeks of downtime or a customer data leak. Policies written for the old threat may not respond well to the new one.
The 2027 deadline boards cannot ignore
The NCSC has effectively given business a timeline. If frontier AI capability reaches attackers by early 2027, organisations have a matter of months to get basic hygiene in order. Four highly significant breaches in a single year is the warning shot. The businesses that treat this as a board agenda item this quarter will be the ones still trading normally when the next one lands.
Join the discussion
Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.