Cyber Governance: New Zealand's C2 Incidents Are Back After Five Years
On the twenty-second of June 2026, the National Cyber Security Centre, the NCSC, published its Quarter 1 2026 Cyber Security Insights report. Buried inside the quarterly numbers was a finding that should hold the attention of every New Zealand board: the return of C2 "highly significant" cyber incidents. Not one. Three, in a single quarter. The last time New Zealand recorded an incident at this severity was the 2021/22 financial year. For nearly five years, the count at this level was zero.
The NCSC does not use the C2 label loosely. Its severity scale runs from C1, a national cyber emergency, down to C6 at the routine end. C2 sits second from the top. It is reserved for incidents that expose key sensitive data or disrupt essential services at organisations of national significance, the kind of event that takes substantial time and resources to address and that reaches thousands of New Zealanders beyond the victim organisation itself. Three of those in ninety days is not noise. It is a signal.
This article makes one argument. C2 incidents do not arrive suddenly. They accumulate.
What a C2 incident actually means
To read the Q1 2026 number, you need the last time the category was used in anger. That was the Waikato District Health Board ransomware attack of May 2021. It paralysed services at five hospitals, brought down six hundred and eleven servers, forced manual workarounds at some facilities for more than three months, and ended with private data from more than four thousand patients and employees published on the dark web about six weeks after the initial intrusion. A later review found the board was up to date with patching; software vulnerabilities did not play a role. That attack is the benchmark against which the category was last understood in this country: national health-service disruption.
The 2021/22 financial year recorded two C2 incidents. The first quarter of 2026 has already recorded three. More in ninety days than in any full financial year since the Waikato attack.
Two points of precision matter here, because they shape how a board should read the report. First, the NCSC and the Office of the Privacy Commissioner are different agencies doing different jobs. The NCSC, which sits within the Government Communications Security Bureau, gives advice, assistance, and incident response to organisations of national significance. It does not impose penalties. Financial accountability for data-protection failures sits with the Privacy Commissioner under the Privacy Act 2020. The two agencies looked at the same incident for different reasons; their findings are complementary, not ranked one above the other. Second, only one of the three Q1 2026 C2 incidents has been publicly identified. The NCSC does not name affected organisations as a matter of practice. The total is confirmed. Two of the three remain unnamed, and there is no basis for guessing who they are.
The quarter in numbers
Across the quarter, the NCSC handled one thousand, one hundred and sixty-four cyber incidents, slightly more than the previous quarter. Of those, seventy-seven required specialist technical support, down fourteen per cent, while the rest were handled without specialist intervention.
The financial picture is where the governance lesson hides. Direct losses for the quarter reached five point six million New Zealand dollars, a seventy-six per cent rise on the previous quarter. Individuals bore the overwhelming share, about five point two million dollars, while organisational losses came to roughly three hundred and forty thousand. The concentration is the part worth sitting with: forty-two incidents with losses of ten thousand dollars or more accounted for ninety-seven per cent of all the money lost. The remaining couple of hundred incidents with a financial figure attached contributed three per cent between them.
That is the shape of cyber risk for a board. It is not evenly distributed. Most incidents are minor. A small number are severe, and those few drive almost the entire outcome. Phishing and credential harvesting was the largest single category by volume, at four hundred and thirty-seven incidents. Scams and fraud were second by volume and accounted for most of the loss.
One attribution figure deserves careful reading. Of the seventy-seven incidents that received specialist triage, the NCSC assessed seventeen per cent as state-sponsored, fifty-two per cent as ordinary cybercrime, and the remainder as not attributable on the evidence available. That seventeen per cent is seventeen per cent of the nationally significant subset, not of all one thousand, one hundred and sixty-four incidents. The broader pool of state-sponsored activity is almost certainly a smaller proportion. Precision here is a governance discipline, not pedantry.
The NCSC's Chief Operating Officer, Mike Jagusch, gave boards the one-line version. Basic measures, he said, such as multi-factor authentication, managing who holds full access to the network, and protecting the network edges, could have helped defend against these incidents. Read that against the one C2 case we can examine in detail, and it stops being generic advice.
The anatomy of an accumulated breach
The publicly known C2 incident is the December 2025 ransomware breach of the ManageMyHealth platform, MMH, the case this series has followed since February. The Privacy Commissioner's Phase 1 inquiry, released on the twenty-seventh of May 2026, found that both MMH and Health New Zealand had breached Rule 5 of the Health Information Privacy Code. The Commissioner's central finding is worth quoting because it is the heart of this article: "this security breach was not the result of a single failure. Instead, it involved a combination of factors."
That sentence is Architectural Debt described in the language of a regulator. The breach was characterised as "neither technically sophisticated, nor particularly uncommon." A threat actor used stolen credentials to reach a health-documents module, and the data of ninety-nine thousand, four hundred and sixteen patients was accessed and taken. Yet it cleared the C2 threshold, because the sensitivity of the data, the scale of the affected population, and the national significance of the organisations involved put it there.
Look at the combination the Commissioner named. On the MMH side: multi-factor authentication available but optional for users of the affected module; ineffective web security controls; identity and access management weak enough that one set of stolen credentials reached thousands of other accounts; recurring access-control and application-security risks raised in earlier testing and not adequately addressed; insufficient data-leak protection settings; and a detection failure so complete that MMH learned of the breach only when Health New Zealand alerted it, not from its own monitoring. No single item on that list, fixed on its own, would necessarily have stopped the attack. All of them together created a posture that could not detect or contain a credential-based intrusion.
The Health New Zealand failures are a separate category, and boards should not skip them, because most organisations sit on this side of the relationship. Health New Zealand did not build the platform. It bore governance responsibility for how its patients' data was handled by a third-party vendor, and the Commissioner found that responsibility was not met: insufficient due diligence before engagement, poor-quality privacy risk assessments, an inadequate understanding of how the system was technically managed, over-reliance on the vendor's own security assurances rather than independent verification, a project steering group with no direct privacy or security representation, and contracts that lacked appropriate protections for patient information. That is a checklist for the board of any organisation that trusts a third party with sensitive data.
Then there is the part that turns this from a failure into an accountability question. In November 2022, an independent security researcher identified application-programming-interface vulnerabilities in MMH's systems. On the seventeenth of November 2025, thirty-four days before the attack, the Health Ministry passed MMH a formal warning about similar flaws found by the same researcher, noting the similarities were "enough to have raised serious concerns" about attack potential. The Commissioner found no evidence the vulnerabilities were adequately addressed before the twenty-first of December, when they were exploited. This is the Once-Only Resilience principle inverted: an organisation gets one chance to build its resilience before the incident, and here that chance was declined twice. The factual frame matters, and I will hold to it. The Commissioner found a breach of Rule 5. The Commissioner did not find deliberate concealment, and I am not inferring intent the inquiry did not establish. The governance point stands on the facts as published: a C2 outcome was forecast, with specifics, more than a month out, by the victim organisation's own principal.
The governance environment the report lands in
The Q1 2026 data does not arrive in a vacuum. The New Zealand Cyber Security Strategy 2026 to 2030, published in February, sets the backdrop. It puts the annual cost of cybercrime to New Zealand at more than one point six billion dollars, predominantly cyber-enabled fraud. It is worth using that figure as what it is, the government's own published estimate, rather than as a fully attributed econometric study, because the methodology behind it is not set out in the public summaries. The Strategy also reports that fifty-nine per cent of nearly three hundred surveyed large businesses experienced a cyber incident in the past year, and that the NCSC disrupted four hundred and seventy-three point four million malicious cyber events in the 2024/25 year, against ten point three million the year before. That last jump reflects far better detection and disruption, not a forty-six-fold rise in attacks; what it establishes is the scale of attempted activity sitting beneath the visible incident count.
The Strategy states plainly that "cyber security is now firmly established as a matter of governance, not a back-office IT function." Its proposed critical-infrastructure framework would, if enacted, apply minimum standards, mandatory incident reporting on a twenty-four-hour and seventy-two-hour timeline, and financial penalties across seven sectors including health. I want to be precise about status. These obligations are proposed. The consultation closed in April 2026 and submissions are still under analysis. None of this is enacted law as at the date of writing. The accurate reading is that the C2 return gives the proposed framework a current domestic context it did not have when consultation opened, not that any particular legislative timing would have prevented this breach.
On enforcement, the picture is the one this series set out in CN#10. For a Rule 5 breach, the Commissioner's strongest available tool today is a compliance notice, and that is what the Commissioner intends to issue to both MMH and Health New Zealand. I will not re-litigate the enforcement-gap argument here; CN#10 covered why a C2-level breach in New Zealand produces a compliance notice while a comparable breach in Australia would attract a penalty in the high seven figures under the reformed Australian regime. The point for this article is narrower: the breach itself, and what it shows about how these events accumulate.
One human dimension belongs in any honest account. The Commissioner found that about ninety-one per cent of the affected patients were based in Northland, many of whom, in the Commissioner's words, are "likely to be Māori." That concentration came from a specific data arrangement that surfaced hospital discharge information for Northland patients only. Who bears the harm from a security failure is a governance question, not only a technical one, and a governance arrangement concentrated this harm on a population already facing barriers to healthcare access. The Commissioner attributes the concentration to that data arrangement, not to any discriminatory intent, and neither do I.
Why the gaps are becoming more expensive
Four days before the quarterly report, on the eighteenth of June 2026, the NCSC published a separate advisory on frontier artificial intelligence. Its core warning: AI reduces the time between a vulnerability being discovered and being exploited, leaving organisations with less time to patch. Frontier models can find flaws in software at scale, some of them difficult to detect or prevent. The recommended response is unglamorous and familiar: disciplined vulnerability management, defence in depth, an assume-compromise posture, fewer internet-exposed systems, and supply-chain management including software bill-of-materials tooling.
Read the two NCSC publications together and the sequencing tells you something. The advisory frames the threat environment; the quarterly report demonstrates it. The COO's second public statement closes the loop: frontier AI models, he said, will change the cyber threat landscape because malicious actors can find and exploit vulnerabilities at unprecedented speed and scale. The international backdrop is consistent. The same week the quarterly report landed, a major laboratory shipped a security-specialist model under vetted access, roughly ten days after a competitor's model had been suspended on national-security grounds for enabling autonomous vulnerability discovery. The capability is real, it is contested, and it is moving.
For a board, the implication is direct and uncomfortable. The thirty-four-day window MMH had between warning and breach is the kind of window that is closing. When the time from "a flaw exists" to "a flaw is being used against you" shrinks, the cost of leaving a known issue unaddressed rises. The basic measures the COO listed are not becoming less relevant as attackers get more sophisticated. They are becoming more relevant, because the attackers do not need to be sophisticated when the targets leave the front door unlatched.
What this means for your board on Monday
None of this requires a board to become a security operations centre. It requires a board to treat a short list of questions as standing governance, not as an annual tick-box.
Ask whether multi-factor authentication is mandatory, not merely available, on every system that touches sensitive data. Optional was the single most quoted failure in the MMH inquiry. Ask who holds full access to your networks and whether that list has been reviewed this quarter. Ask how you would learn of a breach: from your own monitoring, or from a partner's phone call, as MMH did nine days after the fact. Ask, for every third party that holds your data, whether you accepted a self-assessment or required independent verification, and whether your contract actually obliges that vendor to protect the information. And ask whether the people in the room when those decisions are made include anyone whose job is privacy or security. The MMH steering group had no such voice.
There is a constructive reading here, and it is the one I hold to. Every gap the Commissioner named was addressable before the breach. Governance done properly is not a brake on the organisation; it is the thing that makes the difference between an incident and a catastrophe. The forty-two costly incidents that drove ninety-seven per cent of the quarter's losses are the few that matter most, and they are exactly the ones that disciplined governance is built to catch.
What this means for sovereign capacity
There is a further question the C2 return raises, and it sits in the defence and sovereignty register. Allied governments now treat health data and health-system continuity as critical national infrastructure. The European Union's Network and Information Security Directive, known as NIS2, places hospitals and health providers inside its highest-duty tier, and the United States Cybersecurity and Infrastructure Security Agency, the CISA, lists healthcare among its sixteen critical-infrastructure sectors. New Zealand's own critical-infrastructure framework is still in consultation. The deeper point is one of sovereign defensive capability. When frontier artificial intelligence compresses the time between a vulnerability being discovered and being exploited, as the National Cyber Security Centre warned four days before this report, a small nation's ability to defend data of national significance becomes a sovereignty question, and not only a procurement one. The institutions that defend the data and the institutions that own it are not always the same, and that gap is where accountability is decided.
The C2 category exists precisely because some incidents are categorically different from the daily background. Three of them in one quarter, the first in nearly five years, is the regulator's way of telling boards that the posture at the national-significance level has degraded. The MMH case shows how: not through a single dramatic failure, but through a combination of small decisions not taken, warnings not acted on, and assurances not verified, accumulating quietly until the bill arrived all at once.
When your board last reviewed a vendor that holds your most sensitive data, did you accept their assurance, or did you ask for independent proof, and what did that choice cost or save you when it mattered?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
References
[1] National Cyber Security Centre (NZ). "Cyber Security Insights, Quarter 1 2026." 22 June 2026. https://www.ncsc.govt.nz/insights
[2] Insurance Business New Zealand. "NCSC reports return of highly significant cyber incidents." 26 June 2026. https://www.insurancebusinessmag.com/nz/
[3] SecurityBrief New Zealand. "Three C2 incidents recorded in NCSC Q1 2026 report." 26 June 2026. https://securitybrief.co.nz/
[4] IT Brief New Zealand. "NCSC Q1 2026 insights: losses, attribution and the C2 return." 26 June 2026. https://itbrief.co.nz/
[5] Office of the Privacy Commissioner (NZ). "Inquiry into the ManageMyHealth breach: Phase 1 executive summary." 27 May 2026. https://www.privacy.org.nz/
[6] 1News. "Privacy Commissioner finds combination of failures behind ManageMyHealth breach." 27 May 2026. https://www.1news.co.nz/
[7] Radio New Zealand. "ManageMyHealth breach: Northland patients bear the concentration of harm." 27 May 2026. https://www.rnz.co.nz/
[8] National Cyber Security Centre (NZ). "Frontier AI and the vulnerability landscape: advisory." 18 June 2026. https://www.ncsc.govt.nz/
[9] Department of the Prime Minister and Cabinet (NZ). "New Zealand's Cyber Security Strategy 2026 to 2030 and Action Plan 2026 to 2027." 27 February 2026. https://www.dpmc.govt.nz/
[10] Kordia. "New Zealand Cyber Security Report 2026." March 2026. https://www.kordia.co.nz/
[11] Radio New Zealand. "Waikato DHB cyber attack: the 2021 incident in review." 2021 and later coverage. https://www.rnz.co.nz/
[12] MinterEllisonRuddWatts and Russell McVeagh. "Analysis: New Zealand's Cyber Security Strategy 2026 to 2030 and the proposed critical infrastructure regime." 2026. https://www.minterellison.co.nz/

