August 13, 2026

Does your company hold assets a foreign state would pay to steal

Senior executives discussing strategies in a modern boardroom setting.

Not a Wellington problem anymore

When NZSIS Director-General Andrew Hampton released the agency’s latest threat assessment on 13 August 2026, calling the environment “the most challenging of recent times”, the natural reading was national security. Terrorism levels, foreign interference, the usual geopolitics. That reading misses the point.

The assessment is aimed squarely at the private sector. Hampton warned that the “public and private sectors are being targeted by foreign states and their proxies to gain access to critical assets including intellectual property, innovative technology and other non-public information.” He was blunt about the shopping list, saying “non-public information is increasingly sought, including policy insights, intellectual property or data sets” and that states are “unsentimental in their pursuit of this information.”

That is not a description of a government network breach. It is a description of what sits inside New Zealand boardrooms, R&D labs and CRM databases.

The space sector gets a direct mention

The most specific commercial call-out is the space industry. Hampton warned that “homegrown technological innovation, particularly that which has potential military uses like our rapidly expanding space sector, is also under threat from state-sponsored espionage.” For an industry built around Rocket Lab and a growing cluster of dual-use startups, that is a named target, not a hypothetical.

The agency also named the People’s Republic of China as the “country of most concern” for foreign interference and espionage, while stressing it is not the only actor. And in a line that goes straight to commercial behaviour, the SIS said influential New Zealanders were “self censoring to stay onside with a foreign state,” warning that such behaviour “harms our democracy and our economy.”

The uncomfortable finding

The SIS is not speculating about future risk. Its Security Threat Environment 2025 report used deliberately strong language, judging it “almost certain” that undetected foreign espionage has already occurred in New Zealand. In intelligence terms, that is high confidence.

The implication for directors is awkward. If the agency believes espionage has happened and gone unnoticed, then a company confident it has never been a target may simply not know yet. The 2025 report described a “whole of state” model in which businesses, universities, think tanks and cyber actors all become instruments of state intelligence gathering. A firm dealing with a foreign supplier, investor or research partner could be interacting with a node in that network without any idea.

One case study offered the flip side. A company running due diligence on a prospective customer uncovered undisclosed links to Iran and headed off a probable espionage attempt, evidence that good security practice is a commercial protection, not just a compliance cost.

Boards are not paying attention

Hampton’s central criticism is that corporate New Zealand is underprepared. Speaking to the Aspen-Otago National Security Forum in October 2025, he argued that boards and executives do not give espionage enough attention and often fail to recognise they hold assets foreign states want. His scale reference was stark, citing an ASIO calculation that espionage cost Australia NZ$13.7 billion in a single year.

He also flagged a target that most firms overlook. Many companies hold large customer datasets, names, addresses and phone numbers, which are highly sought by foreign state actors. That puts retailers, insurers and any consumer-facing business in scope, not just deep-tech.

This has been building. In 2024, Hampton delivered a dedicated economic espionage address to the Institute of Directors, advising boards to appoint a security lead at board level. The IoD published his warning that “business as usual security measures, while good, will probably not be enough.” Back in 2023, the SIS’s first public threat assessment found 118 of 350 major cyber incidents, 34 percent, were linked to foreign states, up from 28 percent the year before. At a 2023 Five Eyes meeting, intelligence chiefs warned New Zealand tech firms they could be targets, victims or accidental abettors.

What directors should do now

The regulatory backstop is thin. MFAT’s 2024 export controls report shows 1,068 permit applications processed, up 2.2 percent, with 34 full assessments and 6 declined. But that only catches goods companies voluntarily submit. The espionage risk sits before and around that process, in investment, supply chains and cyber intrusion.

The SIS framework is practical. Understand what assets a foreign state might want. Appoint a board-level security lead with clear ownership of risk. Vet investors and supply-chain partners for undisclosed foreign state links. Build security into products by design. And guard against insider exploitation, because the lucrative job offer to a well-placed employee is a documented tactic.

The question for any New Zealand director is no longer whether the company is a target. On the SIS’s own assessment, it is how you would know if it already was.

Sources

Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required