The Accountability Reckoning: Seven Governance Commitments Every New Zealand Board Should Make Before the Window Closes
Three hundred and sixty-two.
That is the number of documented AI incidents recorded globally in 2025, according to the Stanford AI Index 2026, published this month. Up fifty-five percent in a single year, from 233 in 2024. The incidents are not hypothetical. They are data breaches, governance failures, safety events, and trust failures in organisations that deployed AI systems faster than they built the governance structures to manage them.
The ManageMyHealth breach is not among that count. It was a credential exploitation incident, not an AI-driven one. It belongs to a different database and a different inquiry. But the governance lesson is identical: the attack surface expanded, the governance did not keep pace, and the cost was borne by the people the organisation existed to serve.
This is where the Cyber Sunday series closes. Not because the story is over. The Ministry of Health independent review is due in the days following publication. The Mandatory Cyber Security Standards first reporting results will establish the documented compliance baseline for mandated organisations. IPP 3A enforcement begins on 1 May, twelve days from now. The governance mechanisms that nine articles have described are becoming operational. The question has shifted from what must you do to did you do it.
The series began in February with a single proposition: board governance of cybersecurity in New Zealand is a fiduciary obligation, not a technical exercise. Part 10 delivers the practical answer to what that proposition always implied. What does governance that passes the accountability test actually look like?
The answer is the Resilience Manifesto. Seven commitments every New Zealand board should carry out of this series.
What the Series Established
Nine parts built the evidence base the Resilience Manifesto rests on.
Part 1 established the fiduciary foundation: directors have a positive duty under section 137 of the Companies Act to acquire and maintain sufficient information to make informed decisions. Cybersecurity is embedded in the director's duty of care, not optional on the governance agenda.
Parts 2 and 3 established the financial stakes. The Fiduciary Risk Exposure formula quantified the gap between what governance failures cost and what governance investment requires. The ManageMyHealth breach demonstrated those numbers in practice: legal costs, notification obligations, reputational damage, and regulatory inquiry, all of which materially exceeded what preventive investment would have required.
Parts 4 and 5 traced the supply chain and access architecture dimensions. The breach was not a perimeter failure. It was an access control failure in a federated identity architecture where valid credentials granted platform-wide access. The Architectural Debt that created that vulnerability had been accumulating for years.
Part 6 introduced the Hour-Zero Protocol: the governance pre-work that determines whether a board governs an incident or is governed by it. Decision authority, communication authority, and escalation authority must all be pre-assigned before the incident arrives.
Part 7 addressed the board's 24-hour fog of war: the specific failure of governance under pressure, when information is incomplete, authority is unclear, and the decisions required are the ones the board never discussed in advance.
Part 8 mapped the regulatory convergence: the MCSS, the proposed critical infrastructure regime, and IPP 3A. The compliance floor for New Zealand organisations is now documented, enforced, and in the case of the proposed critical infrastructure regime, carries personal director liability.
Part 9 addressed the practical toolkit: the specific response tools ManageMyHealth lacked, the shadow AI governance gap most New Zealand response frameworks were not built for, and the four board questions that define minimum readiness for the May accountability window.
Part 10 closes the loop. Everything the series built toward can be expressed in seven governance commitments.
The Architecture of Accountability
Before the commitments, the accountability architecture they must stand up to.
The proposed critical infrastructure regime, as outlined in the DPMC's public consultation document released in February 2026, describes a five-tier penalty framework. The tiers run from minor contravention through moderate, serious, and severe, to critical. The distinction between serious and severe is, in practical terms, the distinction between a governance failure and a governance failure that continued after the organisation became aware of it. The distinction between severe and critical involves conduct that contributed to significant harm to critical infrastructure. The consultation period closes this week; the regime remains a proposal, not enacted legislation.
The proposed regime describes four defences available to directors: protection of life, health, or property; matters beyond reasonable control; reasonable reliance on third-party information; and non-compliance that was not known and could not reasonably have been known. That last defence is significant for boards. It rewards documented governance. If your board had a reasonable process, sought competent advice, and acted on it, the proposed defence would be available. If your board had no documented process, it would not.
This is the accountability architecture the series has been building toward. Not fear-mongering. A factual description of the regulatory trajectory for boards governing organisations that touch critical infrastructure.
Privacy Commissioner Michael Webster described the integrity dimension of the ManageMyHealth incident in February 2026: changing people's information without their consent is a violation of privacy regardless of whether that information leaves the organisation. The Privacy Act does not only protect against disclosure. It protects information in its entirety, including accuracy and integrity. That framing extends the governance obligation beyond data security into data stewardship.
The New Zealand Threat Environment Closing This Series
The Kordia 2026 New Zealand Business Cyber Security Report found that seventeen percent of all cyber incidents affecting New Zealand organisations in the past year involved personally identifiable information theft. This is the clinical record, the tax file, the identity credential. Not ransomware, not system outage. For boards governing health, financial, or social services organisations, PII theft is the specific liability category most directly engaged by the Privacy Act's notification and accountability obligations.
Financial extortion was reported in nineteen percent of incidents, up from fourteen percent the year prior. The perpetrators in most cases are organised criminal enterprises operating with the operational sophistication of mid-sized companies. The board governance response is pre-made decisions, tested recovery, and a documented escalation path.
The NCSC's finding on te reo Māori in AI-generated phishing deserves specific attention in any New Zealand governance context. Attackers are now generating phishing content in te reo Māori, targeting organisations where staff communicate in te reo and where security tools may not flag the content as anomalous. This is not a generalised trend extrapolated to New Zealand. It is a New Zealand-specific NCSC finding, and it changes the threat model for any organisation with a Māori-language workforce or constituency. The Cultural Security Envelope applies here precisely: security culture must extend to the languages and communication channels your organisation actually uses.
The DPMC's public consultation document acknowledged the activity of state-sponsored threat actors targeting organisations relevant to New Zealand's critical infrastructure. For boards, the governance implication is that the threat environment includes actors operating with resources, patience, and objectives that differ materially from commercial ransomware groups. The detection and response architecture a board should require reflects that.
The water infrastructure governance precedent, raised in the DPMC's own consultation framing, signals the regulatory trajectory. When a government recognises that systemic under-investment in infrastructure has created unacceptable risk, the regulatory response typically involves mandatory standards, audit obligations, and liability frameworks. Cybersecurity governance is following a similar trajectory. The boards treating it as compliance theatre may find that the curve has moved past them.
The New Zealand Board Resilience Manifesto
Seven commitments that translate the series' frameworks into governance language a board can adopt, audit, and affirm. Not a checklist. The difference between a board that governs cyber risk and one that delegates it.
Commitment One: We know what we have.
The Identify function in NIST CSF v2.0 is the foundation on which every other governance commitment rests. This commitment means the board has approved an asset register covering systems, data, third-party connections, and AI tools in use across the organisation. A board-visible document, reviewed at least annually, feeding the risk register.
Commitment Two: We know what is expected of us.
The MCSS, the Privacy Act, IPP 3A, and the proposed critical infrastructure regime define the compliance floor. This commitment means the board has a documented map of those obligations, assigned accountability for each, and a reporting mechanism that tells the board whether they are being met. The compliance floor is not the ceiling. As EA Thursday Chapter 9 examined in its treatment of identity governance under IPP 3A, the algorithmic transparency requirements extend beyond credential management into the governance of every automated decision touching personal information.
Commitment Three: We ask intent, not just permission.
The Audit of Intent is the governance question the ManageMyHealth attacker's credential architecture could not answer: not does this credential have access, but does this behaviour match the pattern of legitimate use. This commitment means detection architecture includes anomaly-based controls alongside credential-based controls.
The Hour-Zero Protocol is the governance pre-work that determines whether the board leads the response or follows it. This commitment means the board has documented, discussed, and formally adopted a ransom decision framework, an incident notification authority matrix, a regulatory engagement protocol, and a public communications authority. None of these decisions should be made for the first time at the moment an incident requires them.
Commitment Five: We see our own architecture as the attacker does.
Architectural Debt is the accumulated cost of deferred security investment. This commitment means the board has a mechanism to surface deferred investment decisions and assess their risk implication. The question the board asks annually: what deferred investment has accumulated, what is the risk exposure it represents, and what is the decision we need to make about it?
Commitment Six: We govern our culture, not just our controls.
The Cultural Security Envelope is the governance principle that shadow AI makes urgent. This commitment means the board has adopted a policy on AI tool use for employees who handle personal information, communicated and enforced at a level consistent with IPP 3A and the Privacy Act's information security principle. The 55% year-on-year increase in documented AI incidents, as Gen AI Tuesday has tracked through the Governance Gap, is the evidence base: AI tools are proliferating faster than the governance frameworks required to manage them.
Commitment Seven: We are accountable for outcomes, not just processes.
The Fiduciary Risk Exposure formula quantified this commitment. A board that can demonstrate it had governance processes in place, but cannot demonstrate whether those processes produced outcomes, is not meeting the section 137 duty of care standard. The board receives outcome reporting on security posture, not only activity reporting on security spend.
The 90-Day Action Plan
May: Complete the shadow AI audit: a structured inventory of AI tool use across the organisation, assessed against personal information handling obligations, briefed to the board. Adopt the Commitment Six policy before IPP 3A enforcement reaches its first full month. Brief the board on MCSS self-assessment results and gaps against CMM Level 2.
June: Run the incident response scenario exercise. Not a desktop review. A live scenario, conducted with the people who would actually invoke the Hour-Zero Protocol and the regulatory notification process. Document findings. Act on them. Review the Architectural Debt register.
July: Board sign-off on the Resilience Manifesto commitments, with accountabilities assigned and reporting obligations confirmed. Review the risk register in light of the May and June work. Assess readiness against the proposed critical infrastructure regime obligations before the pre-election period reduces the window for governance reform.
Closing: The Governance Obligation Is Also a Human One
Grey Power's president Gayle Chambers said in February 2026, in response to the ManageMyHealth breach, that older New Zealanders should be able to trust that their health information is held to the highest standard. That trust is not given because an organisation passed a compliance audit. It is earned by the sustained demonstration that the organisation takes its stewardship obligation seriously.
The Resilience Manifesto is how a board makes that commitment explicit, visible, and accountable.
The AI incident count will keep rising. The threat environment does not pause because a series concludes or a regulatory window closes. The governance obligation is permanent. Nine articles have mapped the architecture of that obligation. The ManageMyHealth case study has shown what its absence costs. The regulatory framework has described what compliance looks like.
This is the final article in the Cyber Sunday: Cyber Guide for New Zealand Boards series. Ten parts, ten weeks, one argument: board governance of cybersecurity in New Zealand is a fiduciary obligation, and the tools to discharge it are practical, deployable, and already described.
The Hamberger Report: Cyber Guide for New Zealand Boards will be available as a consolidated publication in November 2026, after the election. If you would like to receive a preview PDF before it releases, contact me directly. I will reach out to everyone who gets in touch before the November release date.
From next Sunday, Cyber Sunday continues in the regular Cyber News cycle: current NZ and global cybersecurity developments, practitioner analysis, and governance implications for boards, every week. No book arc. Just the news that matters, read through a governance lens. The same format Space AI Monday has been running all year.
The series closes with one question worth carrying into every board meeting that follows.
If the organisation you govern experienced the ManageMyHealth breach tomorrow, with everything the OPC's Phase 1 findings will establish as the standard of care, would your governance record demonstrate that you took reasonable steps?
If the answer is yes, the series did its work.
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
References
[1] Stanford HAI. "AI Index Report 2026." April 2026. https://aiindex.stanford.edu/report
[2] ManageMyHealth breach: public communications, RNZ reporting, OPC inquiry public record. December 2025 onwards.
[3] DPMC. "Enhancing the Cyber Security of New Zealand's Critical Infrastructure System: Discussion Document." February 2026. https://www.dpmc.govt.nz/publications/discussion-document-enhancing-cyber-security-new-zealands-critical-infrastructure-system
[4] Privacy Commissioner Michael Webster. RNZ Midday Report. 25 February 2026.
[5] Kordia. "New Zealand Business Cyber Security Report 2026." March 2026. https://www.kordia.co.nz/cyber-security-report-2026
[6] NCSC. "Annual Cyber Threat Report 2024-25." 2025. https://www.ncsc.govt.nz
[7] NIST. "Cybersecurity Framework v2.0." February 2024. https://www.nist.gov/cyberframework
[8] Companies Act 1993, s137. New Zealand Legislation.
[9] Gayle Chambers, Grey Power. Scoop. 26 February 2026.
[10] DPMC. "New Zealand's Cyber Security Strategy 2026-2030." February 2026. https://www.dpmc.govt.nz/publications/new-zealands-cyber-security-strategy-2026-2030
[11] The Hamberger Report: Cyber Guide for New Zealand Boards. Andreas Hamberger. 2026.

