Ransomware Now Hunts the NZ Mid-Market: The $10-to-$100 Million Bullseye

In March 2026, a lawyer stood in front of a room of New Zealand executives in Wellington and told them the safest assumption their boards had ever made was also the most expensive one. Anthony Cooke of Atmos, a firm whose incident-response caseload runs to more than three thousand matters across Australia and New Zealand over twelve years, put a single number on the screen. Forty-two percent of the ransomware incidents in that caseload deliberately target businesses with annual turnover between NZ$10 million and NZ$100 million.

Not because those firms are the richest possible targets. Because they are the richest targets that will not summon an intelligence agency.

Read that again, because it inverts the instinct most mid-market boards have been running on. For two years, directors of firms this size have reassured themselves with a comforting sentence: "We're too small to be a target." That sentence measures size the wrong way. It measures size in headline-grabbing potential, the kind that puts a company on the evening news and a national-security apparatus on the case. The people writing ransomware do not measure size that way. They measure it in extractable liquidity: large enough to pay a six-figure ransom without blinking, small enough that no one with a mandate is watching. On that measure, a NZ$40 million professional-services firm is not overlooked. It is optimal.

The data, and an honest word about where it comes from

The figures reached the New Zealand news cycle on 27 July 2026, when three trade outlets, Insurance Business New Zealand, SecurityBrief New Zealand and DefSec, each reported Cooke's Atmos analysis. Within the same dataset, two sectors stand out: financial and insurance services at 18.8% of incidents, and professional services and consulting at 17.5%. Together, just over a third of everything. If your firm advises, audits, insures, or manages other people's money or other people's data, you are not on the edge of this pattern. You are near its centre.

Before we build anything on those numbers, one caveat that this series exists to model. Three outlets reported the figures, and they agree on every decimal. That consistency tells us the reporting is an accurate transcription of what Cooke presented. It does not turn three journalists covering one presentation into three independent investigations of the underlying events. The evidence base is Atmos's own proprietary caseload, presented publicly and consistently reported, not an externally audited industry census. I am treating it exactly that way, and so should your board. A governance series that teaches directors to ask whether corroboration is real has to hold itself to the same test.

What a mid-market ransomware event actually costs

The economics in the Atmos data are specific enough to budget against, which is the point. The median opening ransom demand was NZ$1.2 million, peaking at NZ$3.5 million. The median final settlement, after negotiation, was NZ$430,000, with the worst reaching NZ$1.54 million. Those are the demands. They are not the bill.

The recovery costs sit alongside the ransom, not inside it. Legal fees, public-relations support, and technical containment averaged NZ$235,000 across the dataset and reached as high as NZ$2.1 million, before a single dollar of ransom is counted. A related but separate class, business email compromise, averaged NZ$26,000 in losses, with the high end above NZ$1.4 million. For a firm that has never carried a dedicated security budget line, this is the number that reframes the risk: even a contained incident lands somewhere between a serious capital expense and an existential one.

Two details in the data change how a board should think about response. The first is dwell time. The median gap between the attackers getting in and the ransomware firing was eight days, down from roughly two weeks historically, with extreme cases stretching to 163 days. For an IT team with no dedicated security operations function, an eight-day window to notice and act is not comfortable. It is closing. The second detail is what payment actually buys. Where victims paid, they received a working decryption key and no further leak in 80% of cases. In the other 20%, they received nothing at all. One in five payers, in this dataset, paid and got nothing back. Any board discussion that treats paying as a clean exit has to sit with that number first.

It is already happening here

The mid-market pattern is not abstract in New Zealand, though it has to be handled with care. In January 2026, McKay, described as the country's largest privately owned electrical contractor, headquartered in Whangārei with nine offices nationwide, detected unauthorised access to a single internal device, isolated it, and contained it. The company states its systems remained secure throughout, verified by an external specialist, and it notified affected individuals, the Office of the Privacy Commissioner, and the National Cyber Security Centre. A newly emerged ransomware group later listed McKay on its leak site. The confirmed exposure, on McKay's own account, was one device, contained. That is a materially smaller event than the word "ransomware" implies in a headline, and I am not going to inflate it into more than the company itself has disclosed.

That restraint is itself a governance lesson, because the alternative is on display too. In May 2026, an Auckland health-supplements company was listed on another group's dark-web leak site. No documents, no screenshots, no stated data volume, no company confirmation, and separate public evidence suggesting the firm may sit above this article's turnover bracket rather than within it. A leak-site listing is a claim by the attacker, not a verified breach. Treating it as fact is the single most common trap in this territory. The open-source trackers that aggregate these listings, the community-run tools that scrape what the criminals publish, record roughly sixty New Zealand-linked victim postings across all groups since 2020. That is a useful order-of-magnitude signal of sustained targeting. It is not a government-verified incident count, and it should never be quoted as one.

Why AI makes it worse, not just more common

Six days before the Atmos figures surfaced, Proofpoint published its 2026 AI-Era Ransomware Report, a survey of 953 security professionals across twelve markets and twenty industries, fielded in March and April 2026. The New Zealand-specific slice is not broken out, so I will not invent one. The Australian results, drawn from a large subset of that global sample, are the closest current read we have, and they are pointed. Among Australian organisations that had suffered a ransomware attack, 67% said artificial intelligence made the attack more effective, 26% describing the effect as significant and 41% as somewhat. Seventy percent confirmed data was stolen. Of those who paid, 51% then faced a second extortion demand.

Proofpoint's own framing, from its chief strategy officer, is that AI has not reinvented ransomware so much as sharpened the attacks that lead to it: more convincing phishing, better tooling, credential theft that exploits human trust at scale. Read the two datasets together and you get one picture from two angles. The Atmos analysis tells you who is being chosen. The Proofpoint data tells you how much sharper the instrument has become once the choice is made. Neither was designed to corroborate the other, which is precisely why their agreement on the direction of travel is worth noting.

The New Zealand baseline, and the coverage gap underneath it

Set the national numbers beside the mid-market ones. The National Cyber Security Centre's incident-reporting analysis for 2024/25 records NZ$26.9 million in direct financial loss, up from NZ$21.6 million the year before, across 331 incidents triaged for potential national significance, with an estimated NZ$47.9 million in harm prevented. Inside that total, the shape of the threat shifted: state-linked incidents fell while criminal, financially motivated incidents more than doubled, from 65 to 137. I am deliberately not quoting a single ransomware-specific count for the year, because the figures in public circulation do not agree with each other, and the total direct-loss figure is the clean one. In the first quarter of 2026 alone, the agency recorded NZ$5.6 million in direct loss across 1,164 incidents, a 76% jump on the previous quarter. The criminal economy is not a forecast. It is the current weather.

Now the part most mid-market boards have never tested. Cyber-insurance penetration among New Zealand small and medium clients sits at roughly 10%, against roughly 40% among large corporates, on one broker's book of business. The bracket most likely to be targeted is the bracket least likely to be covered. It gets worse at the seam between policies. Traditional management-liability cover frequently carries "silent cyber" wordings that exclude cyber exposure or fail to address it clearly, so a board can believe it is covered for governance and privacy claims arising from an incident when it is not, unless a separate dedicated cyber policy is also in force, which many firms in this bracket never buy. An estimate from Adelphi Insurance Brokers, reported by Insurance Business New Zealand, puts it starkly: it suggests 70% of uninsured small and medium firms across New Zealand and Australia that receive a ransom demand would not survive into the following year, business interruption doing most of the damage. Take that as an insurer's estimate, attributed, not as settled fact. It still describes the stakes with uncomfortable clarity.

What a board in this bracket should actually do

This is where the Cyber Guide's Fiduciary Risk Exposure argument stops being a chapter and becomes a Monday-morning question. Inadequate cyber governance is a live exposure under a director's duty of care, and a NZ$10-to-$100 million board that has never asked whether its arrangements are proportionate to its actual, rather than assumed, threat has an open gap. Not a technical gap. A governance one.

I have had versions of the following three conversations more times than I can count. The first is with a managing director of a professional-services firm turning over about forty million dollars, who says, reasonably, "We're not a bank, we're not a hospital, we're not critical infrastructure, so why would anyone bother with us?" The honest answer is that the reasoning is exactly what the data says the attackers are counting on. You cannot summon the enforcement response a listed multinational can, and you can pay a six-figure ransom without a board vote. You are not being overlooked because you are small. You are being selected because you are the right size.

The second conversation is with a chief financial officer reviewing insurance renewals, who says, "We have a cyber policy, isn't that the box ticked?" Having a policy and having a policy that actually responds to a ransomware event, alongside your management-liability cover, are different questions. This is the Audit of Intent applied narrowly: not whether a document exists, but whether anyone has verified what it does. The question is not whether a policy sits in a drawer. It is whether it has ever been tested against what a NZ$1.2 million opening demand and a NZ$235,000-plus recovery bill would require it to pay.

The third conversation is the one worth having before an incident rather than during one. A board member asks, "If this happened to us tomorrow, what would we actually do?" If the honest answer is "start looking for an incident-response firm's phone number," that is the gap. With median dwell time now measured in days, there is very little runway to arrange help after the fact. This is what the Cyber Guide's Crisis Compass points a mid-market board toward: two bounded, near-term decisions, not a large capital programme. One, commission an honest audit of whether existing cover and its limits are proportionate to the numbers this data describes, not merely whether a policy exists. Two, confirm that an incident-response retainer, an insurer's approved panel, and a communications plan are in place before they are needed.

There is a stewardship dimension here that a listed multinational does not carry in the same way. Many firms in this bracket are privately owned, multi-generational, or woven into a single region, McKay in Whangārei being one illustration of the type. Kaitiakitanga, the principle of guardianship and stewardship, fits this segment precisely: a ransomware event at a firm of this scale is not a line item in an annual report, it is a threat to jobs, supplier relationships, and standing built over decades. Guardianship at this scale is personal in a way it is not at the top of the market.

The direction the rules are travelling

None of this sits still. New Zealand's Cyber Security Action Plan, accompanying the Cyber Security Strategy 2026-2030, directs the Ministry of Justice to advise on options that could include a civil pecuniary penalty regime under the Privacy Act 2020, which at present has no such mechanism. A separate proposed critical-infrastructure regime is described in law-firm summaries as carrying corporate penalties reported at NZ$5 million or 2% of turnover, and director personal liability reported at up to NZ$500,000 for the most serious breaches, with one summary setting out a tiered structure of up to NZ$100,000 for a serious breach and up to NZ$500,000 for a critical one. Both are proposals, not enacted law; public consultation on the discussion document closed on 19 April 2026 and the material remains under consideration. I am describing what has been proposed and its status, and going no further than that. Separately, and already in force, legal commentary notes that a notifiable privacy breach is expected to be reported to the Privacy Commissioner within about 72 hours, with failure to notify itself carrying a fine of up to NZ$10,000. The floor exists today, whatever the ceiling becomes.

There is a Skynet-side observation in all of this that I will make once and leave. The ransomware syndicates are running better actuarial analysis on which New Zealand companies are worth extorting than many of those companies' own boards are running on their own exposure. A criminal enterprise is treating this data more rigorously than its intended victims. That asymmetry is the whole argument.

Executive takeaway. If your firm turns over between ten and one hundred million dollars, you are inside the bracket this data describes, not adjacent to it. Do two things before the next board meeting closes. Verify what your cyber and management-liability cover actually pays out against a NZ$1.2 million demand and a six-figure recovery bill, not merely that a policy exists. Confirm an incident-response retainer is in place now, while the median warning window is eight days and shrinking.

There is an open-source dimension worth naming before the sovereignty question, because it is doing quiet work in this story. Almost everything we know about which New Zealand firms are being listed by ransomware crews comes from open-source intelligence: community-maintained leak-site trackers, ransomware dot live among them, that scrape what the criminals publish and count it in the open. The defensive baseline an under-resourced firm actually runs on is open too, from the public Common Vulnerabilities and Exposures programme, the CVE catalogue that names the flaws attackers reuse, to the software bill of materials, the SBOM, that tells you which components sit inside the products you bought. The lesson the XZ Utils backdoor taught in two thousand and twenty-four still holds. An unpaid dependency can carry a compromise straight into systems no board ever inspected. Provenance is not a developer nicety. It is board-level visibility.

The same exposure looks different from a national-security vantage point. A firm turning over between ten and one hundred million dollars is rarely only itself. It is a supplier, a processor, or a maintenance contractor sitting inside the supply chains that energy, telecommunications, finance, and defence operators depend on. That is why allied critical-infrastructure regimes now draw their governance boundary wider than the operators themselves. Australia's Security of Critical Infrastructure Act, in force since two thousand and eighteen, was extended in two thousand and twenty-six by the Enhanced Critical Infrastructure Risk Management Program Rules, which name unpatched and legacy systems and the hostile use of advanced technology, including artificial intelligence, as core cyber risks operators must manage, with staged twelve-month and twenty-four-month grace periods. The criminal economy that has priced the mid-market has already found the soft edge of that chain.

So here is the question I would put to any board in the ten-to-one-hundred-million-dollar bracket reading this. If a ransom demand landed in your finance team's inbox on Monday, would your first call be to a retainer you already hold, or to a search engine? I would like to hear which one it is, and what it would take to change the answer.


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


References

[1] Insurance Business New Zealand. "Ransomware actors are avoiding big business, on purpose." 28 July 2026. insurancebusinessmag.com/nz/news/cyber/ransomware-actors-are-avoiding-big-business--on-purpose-583787.aspx

[2] SecurityBrief New Zealand. "Which New Zealand companies are most likely to be targeted by ransomware hackers." 27 July 2026. securitybrief.co.nz/story/which-new-zealand-companies-are-most-likely-to-be-targeted-by-ransomware-hackers

[3] DefSec New Zealand. "Which New Zealand companies are being targeted by ransomware." 27 July 2026. defsec.net.nz/2026/07/27/which-new-zealand-companies-targeted-by-ransomware/

[4] Proofpoint. "Two-thirds of Australian organisations affected by ransomware say AI made attacks more effective." 23 July 2026. proofpoint.com/au/newsroom/press-releases/two-thirds-australian-organisations-affected-by-ransomware-say-AI-made-attacks-more-effective

[5] Proofpoint. "2026 AI-Era Ransomware Report." 23 July 2026. proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report

[6] SecurityBrief Australia. "AI makes ransomware more effective in Australia, study finds." 2026.

[7] Cyber Daily (Australia). "Exclusive: Kiwi electrical contractor confirms cyber attack." 4 May 2026.

[8] ransomware.live. "New Zealand victim listings." Accessed July 2026. ransomware.live/map/NZ

[9] National Cyber Security Centre (New Zealand). "Incident Reporting Analysis 2024/25." 2026. ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2025/incident-reporting-analysis/

[10] National Cyber Security Centre (New Zealand). "Quarter one sees significant cyber incidents." 22 June 2026. ncsc.govt.nz/news/quarter-one-sees-significant-cyber-incidents/

[11] Insurance Business New Zealand. "Cyber exclusions in management liability left small firms exposed." 23 June 2026.

[12] Bell Gully. "Privacy penalties and personal liability: a new world for NZ cyber laws." 11 March 2026.

[13] Simpson Grierson. "New Zealand's next cyber era: higher standards, harder consequences." 2026.

[14] Clayton Utz. "Australia's Enhanced CIRMP Rules: what critical infrastructure operators need to know." 23 June 2026.

[15] Federal Register of Legislation (Australia). "Security of Critical Infrastructure (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (F2026L00701)." In force 9 June 2026. legislation.gov.au/F2026L00701/latest/text

[16] Department of the Prime Minister and Cabinet (New Zealand). "New Zealand Cyber Security Strategy 2026-2030 and Cyber Security Action Plan 2026-2027." 2026.

Next
Next

The Systemic Risk Has a Name: When the Reserve Bank Called a Frontier Model a Threat to Financial Stability