Cybersecurity
Cyber Security in 2026: The Controls That Actually Reduce Risk for NZ Businesses
The threat picture in 2026
New Zealand recorded its first 'highly significant' (C2) cyber incidents since 2021 in the first quarter of 2026, and the attacks were not aimed at obscure systems - they hit data-rich services holding some of the most sensitive information in the country. The pattern is familiar everywhere: attackers follow the data, and they increasingly reach it through third parties and cloud services rather than head-on.
The hopeful part is that the same handful of controls keep deciding the outcome. In penetration tests we still find weak and reused passwords and missing multi-factor authentication - the cheapest attacks to defend against and the most damaging to ignore.
1. Multi-factor authentication, everywhere it is supported
MFA remains the single highest-impact control available. It stops the majority of account-takeover attacks we see, including the phishing and credential-stuffing attempts that open most incidents. Roll it out on email, cloud and remote access first, then everywhere else - and back it with conditional access so it applies by rule, not by memory.
2. Incident response you have actually rehearsed
A survey by Kordia and Aura Information Security found that around half of New Zealand organisations over 50 seats had never practised their incident response plan, and only about half of boards had discussed cyber security at all. Those two facts are linked: unexercised plans and uninvolved leadership are what turn an incident into a crisis.
A practical rehearsal is small: walk through a realistic scenario, test the call tree, confirm who decides on ransom and communications, and check that your evidence-preservation steps are understood. Do it before you need it, and repeat it when the business changes.
3. Backups you have restored, not just scheduled
Ransomware and destructive attacks target backups deliberately, so the protection is immutable, offline copies that attackers cannot reach or modify. And a backup only counts once you have restored from it and verified the data opens and makes sense. Know your recovery time objective (RTO) and recovery point objective (RPO) for each critical system - if you cannot state both numbers, the plan is unfinished.
4. Patch and shrink the attack surface
Unpatched software, unsupported devices and misconfigured cloud services remain common entry points. Run a vulnerability assessment to see your real exposure, prioritise by business impact rather than severity score alone, and fix the internet-facing gaps first. Cloud configuration deserves specific attention - it is where many 2026 incidents, including supplier-related ones, begin.
5. Governance that meets, decides and funds
None of the above sticks without someone accountable. That means a named owner, regular reporting to leadership, and a budget that reflects risk rather than reacting to the last scare. Where clients, tenders or insurers demand evidence, a structured framework such as ISO/IEC 27001 turns those good intentions into provable, auditable practice.
Quick answers
Enable multi-factor authentication everywhere it is supported, then verify your backups restore. Those two controls stop the most common attacks and give you a way back if something still gets through.
Attackers automate and target small organisations precisely because controls are often weaker and data is just as valuable. The basics above scale down to any size and cost far less than responding to an incident.
Need help putting this into practice?
The Click IT team is based in Tauranga and helps businesses across New Zealand act on advice like this.
Last updated: 2026-10-01. This article is general information, not specific advice for your situation - talk to us about your circumstances.