The Questions Are Now Addressed to the Board
A New Zealand business hired a remote IT contractor this year. He turned out to be a North Korean state operative. He worked under a false identity. A locally recruited operator received the company-issued laptop and ran it, so its network traffic looked like it came from New Zealand. When the contract ended, he claimed to hold commercially sensitive material and threatened to leak it unless paid. The company's response, once it worked out what had happened, was a face-to-face interview and an in-person laptop handover. New Zealand has no statutory lever that would otherwise apply to a case like this.
That case sits inside the Cyber Threat Report 2026, from the National Cyber Security Centre. The Government Communications Security Bureau published it on 24 September. It recorded 369 incidents of potential national significance over the year. Four were rated C2, the agency's second-highest severity tier.[1][2] The report's own foreword says it is written for people making decisions about cyber security in medium-to-large organisations, not for security teams.[2] Every one of its five Key Judgements closes with a named list of questions a board should be able to answer.[3] The same week, the one New Zealand regulator that can actually fine an organisation over a privacy breach has not had its penalty ceiling moved since 2020.
A threat assessment can now name a board directly. The enforcement instrument meant to back it has not kept pace.
The report covers 1 July 2025 to 30 June 2026. It classifies incidents on a six-tier scale, from C1, a National Cyber Emergency, down to C6, the least severe. This year there were no C1s and four C2s, the "Highly Significant" tier. The report's own framing of that number shifts depending on which page is read. The public release calls four C2s in one year "as many as the entire previous decade combined," while the judgement covering cybercrime instead describes them as "the first cybercrime incidents of that severity for five years."[4] Both are the agency's own words, from different parts of the same document. The more precise of the two is the five-year claim.
Two of the four are now identifiable. One is the Manage My Health and Health NZ breach, already covered in this series in detail. The report classifies it, independently of the Privacy Commissioner's own compliance notices, as credentials compromised through information-stealing malware.[4] The other is a breach of the Canvas learning management system, disclosed in May. The agency's own public alert dates it to 8 May, affecting more than thirty New Zealand tertiary institutions and schools.[5] The Ministry of Education has estimated 110,000 to 120,000 students and staff had names, emails, student identification numbers or messages exposed.[6] The report also names two further C2 incidents: a medication-platform disruption and a credential-theft campaign affecting 26,000 New Zealanders. Neither is corroborated by anything beyond the report's own page.[4]
Of all 369 incidents, 23 per cent had suspected state-sponsored links. 44 per cent were likely criminal or financially motivated, an 18 per cent rise on the year before. A third were never attributed at all.[7] The report names China, in its own words, as "the most persistent and capable state actor undertaking cyber activity in New Zealand," with Russia, Iran, and North Korea also identified.[7] That is the agency's own assessment, not an independent finding of this article. Reported financial loss was $23.8 million, down from $26.9 million the year before. That figure counts only what organisations report. This year's report, unlike last year's, does not state a figure for harm prevented at all.[1] Total incident reports fell to 4,673, down from 5,995, with 3,627 from individuals and 671 from organisations.[1]
Every one of the report's five Key Judgements ends with the same device: a named list, "questions leaders should be asking." The second judgement, on state-sponsored activity, asks whether an organisation has identified the information assets that would matter most if someone got in.[7] The fourth, on supply chains, asks whether a business can say it has ongoing assurance that a third-party supplier is maintaining its security standard once the contract is signed. That assurance has to continue past the point of procurement.[8] Readers will recognise the shape. The Kaitiakitanga Checklist and the Fiduciary Risk Exposure method in this book have made the same move for two years. Both trade a technical score for a short list of questions a director should be able to answer. Two separate efforts at the same problem, a state agency's and this book's, independently landed on the same shape of answer.
The other three judgements matter just as much to a board, even without a quotable question attached here. The first names frontier AI as a force that will supercharge both the risk and the opportunity in the threat landscape ahead. The third documents the cybercrime and extortion increase already covered above. The fifth states plainly that social engineering remains a persistent threat, regardless of how good an organisation's technical controls are. None of the five is optional for a director who wants to say the organisation actually read this report.
The falling report count noted above matters too. The report does not say whether fewer total reports reflects fewer incidents, more apathy about reporting, or some other explanation entirely. A board should not read a falling number as reassurance without first asking its own security team which explanation applies here.
The National Cyber Security Centre sits inside the GCSB, an intelligence and security agency. It can publish a detailed assessment naming a board's responsibilities. It has no power to fine anyone. The agency that can fine an organisation over a privacy breach is the Privacy Commissioner. Its instrument has not moved since 2020: a maximum Privacy Act penalty of $10,000, and a Human Rights Review Tribunal damages award capped at $350,000 that has never actually been awarded at its ceiling.[9][10] Most awards fall between $5,000 and $25,000. The handful of larger payouts on record, $98,000 and $70,000 among them, remain well short of the legal maximum.[9]
Australia's equivalent, in force since 13 December 2022, is the greater of A$50 million, three times the value of the benefit obtained, or 30 per cent of the entity's adjusted annual turnover.[9][10] It is nearly four years old, which sharpens the comparison. The gap has stood for years. New Zealand's own policy process has not yet closed it, even in proposal form. That process is a discussion document proposing fines, enforceable undertakings, and criminal penalties across roughly two hundred entities in seven essential services, among them telecommunications, energy, finance, health, transport, and drinking water. It closed for comment on 19 April 2026. As of this article, five and a half months later, no Cabinet decision, exposure draft, timeline or summary of submissions has surfaced anywhere. The figures attached to that proposal, a maximum $100,000 personal criminal liability for a director on a serious breach and $500,000 on a critical one, remain proposed, not law. They have not moved any closer to being enacted since they were first published.
None of this is a comment on why the consultation has gone quiet. The dates are what they are. A document closed in April. Nothing has followed it by October. What matters for a board is simpler than the reason behind the silence. The one agency that can currently bind an organisation to a financial consequence over a cyber or privacy failure can do so only up to a ceiling that is a fraction of a per cent of what an Australian counterpart faces. The instrument that would close that gap has been sitting in a drawer for longer than most incident response plans stay current.
A second problem sits underneath the first: whether the one regulator with an instrument can actually use it. The Privacy Commissioner has told its own staff it proposes to disestablish nine of forty-six filled roles, about 15 per cent of the office. The Public Service Association says the affected teams include the ones investigating the most serious complaints. The reason for that is disputed three ways. The Commissioner's office says government funding was declined. The union says the cuts reflect chronic underfunding instead. Government says nobody asked the office to find savings. This article does not attempt to settle which account is correct. The office is, at the same time, carrying a live two-phase Manage My Health inquiry and administering the privacy principle that took effect in May. That is the specific workload against which a 15 per cent staffing cut lands. The practical fact for a board is this: the one agency able to levy any financial consequence at all is reporting pressure on the team that would apply it to the worst cases.
Put the two instruments beside each other. A threat assessment can now name a board, in writing, five separate times in one document. It can ask hard questions about state-sponsored activity, cybercrime, supply chains, and social engineering. The instrument that would let a regulator match that visibility with a financial consequence proportionate to the risk a board actually carries exists only as a document. That document stopped moving in April.
The case that makes this concrete is the one this article opened with.
A remote IT contractor used a false persona and fabricated documents to get hired at a New Zealand business. He arranged for a locally recruited operator, sometimes described as a "laptop farm," to physically receive and run the company-issued laptop. That made its network traffic look like it came from New Zealand.[7][11][12] The business grew suspicious, contacted the agency and the Police, and confirmed the worker's true origin. The agency's own account, which is the only source for this case and should be read as such, lists its mitigation as a face-to-face interview and an in-person equipment handover. It also recommends watching for cryptocurrency payment requests, refusal of video calls, and unusual working hours once a contractor is already engaged.[7] United States authorities estimate this kind of scheme generated around US$800 million for North Korea in 2024 alone, in breach of United Nations sanctions.[12]
This is a genuine gap in this book's existing toolkit, not a case where an existing control would have caught it. The Audit of Intent, this series' behavioural-detection concept, flags anomalous actions from an already-authenticated account: unusual downloads, access patterns that do not match normal use. The DPRK case is different. It is an identity fraud at the point of hiring, and the laptop farm model exists specifically so that the account's later behaviour looks ordinary. There is no chapter in this book covering pre-employment identity verification for a fully remote hire.
The same scheme works anywhere a hiring process has no in-person step. Any organisation that lets a role be filled entirely over video calls and email is offering the opening this scheme is built to exploit. Remote hiring is now ordinary. In most organisations it is unavoidable. The real governance question is whether anyone has mapped where in that process an identity claim gets checked against something harder to fake than a video call and a set of documents.
It also means the fix here is not a technical one. A face-to-face interview and a courier pickup are process controls, applied because no statutory lever currently reaches a case like this. The agency with the most to say about the threat has no enforcement role in it at all. The one case where New Zealand does have a working instrument, the Privacy Act's $10,000 ceiling, has nothing to do with a hiring fraud. Nobody's instrument fits this case cleanly.
None of this means a board should wait for the law to catch up before it acts. The report's own device, a short list of questions after each judgement, is a usable governance tool today.
A board that wants a Fiduciary Risk Exposure style comparison can use the two enforcement ceilings from this article directly, without invoking the book's internal formula by name. The current maximum statutory exposure for a mishandled privacy breach is $10,000 from the Commissioner, plus up to $350,000 in tribunal damages per complainant. Set that against the A$50 million an Australian counterpart faces for the same category of failure. That comparison does the formula's job: it turns an abstract exposure into a number a director can weigh.
Four questions are worth putting on the agenda before the next board meeting. Who in this organisation vets a remote contractor's identity before the laptop ships, not after something looks wrong? What is this organisation's actual financial exposure if the next privacy failure is ours, under the law as it stands today, not the version still in consultation? Can we ask a key vendor for evidence of its security posture, rather than a reassurance? Would we know what to do with it? If the critical infrastructure regime does eventually pass, who in this organisation already owns the compliance work it will create? That work should not start from zero on the day it becomes law.
None of these four questions needs new legislation to be answered. They need a board willing to ask them before a regulator, a sanctions committee or a journalist asks them first.
The report's own severity ladder, zero C1s this year, four C2s, thirty C3s, down to code six, has a cousin built in the open. The Common Vulnerability Scoring System, maintained publicly by FIRST, the Forum of Incident Response and Security Teams, lets any organisation score a flaw's severity the way a vendor does. The formula is published, not held inside a proprietary risk engine.[13] A board that asks a vendor for a CVSS score, and checks the working behind it, is asking a question an open standard makes answerable. A board that only accepts a vendor's own risk rating is taking that vendor's word for the ladder as well as the rung. The same openness that lets a severity score be checked by anyone has an international analogue in how the money behind this report's own North Korean case gets tracked, or fails to.
The DPRK case the report describes fits a wider pattern. The UN Security Council's 1718 Committee has overseen sanctions on North Korea since 2006.[14] Until a Russian veto ended its mandate on 30 April 2024,[15] a Panel of Experts investigated exactly this revenue model: false identities, recruited local operators, laundered payroll. Japan, South Korea, and the United States launched a Multilateral Sanctions Monitoring Team that October, to continue the work outside the UN system. The Security Council itself could no longer agree to it.[15] The same structure repeats at the national level this article describes. An institution that can investigate and name sits beside one that can actually freeze an asset or levy a fine. The two do not automatically connect, in Wellington or in New York.
When your organisation last hired a remote contractor, who actually checked that the person on the video call was who the CV said they were? Could you tell this room that story with confidence?
If your board wants an independent AI and cyber risk briefing, or a review of what your vendor's assurance actually verified, message me and I will send the scope and the fixed fee.
• • •
The views expressed in this article are entirely my own, informed by morethan 30 years of professional experience in architecture, security, andtechnology leadership in New Zealand. I write as director of Te PonoLimited; the views are personal and do not represent the position of anyclient, any government agency, or the New Zealand government. My commentaryon legislation and policy is analytical, drawing on publicly availablesources and my professional expertise in architecture, security, and AIgovernance, and it is politically neutral.
• • •
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance. Through Te Pono he provides independent AI and cyber risk briefings and vendor assurance reviews to boards; contact andreas@thehambergerreport.com for the scope and fixed fee.
This article was produced with AI assistance under my direction. Research,drafting and images pass through a pipeline I built and govern: automatedgates for source verification, forbidden language and political neutrality,and my own review before anything is published. The tools include Claude,Gemini and Openart. The frameworks, arguments and editorial judgements aremine and are the same discipline I apply to the AI systems I audit forclients. AI accelerated the work; the thinking, and the responsibility forit, are mine.
[1] National Cyber Security Centre (GCSB). "Incident Reporting Analysis 2025/26." 24 September 2026. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2026/incident-reporting-analysis-202526/
[2] National Cyber Security Centre (GCSB). "Cyber Threat Report 2026." 24 September 2026. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2026/
[3] National Cyber Security Centre (GCSB). "Key Judgements for 2025/26." 24 September 2026. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2026/key-judgements-for-2/
[4] National Cyber Security Centre (GCSB). "Judgement 3: Cybercrime and Extortion." 24 September 2026. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2026/judgement-3/
[5] National Cyber Security Centre (GCSB). "Canvas Data Breach Affecting Some Learning Institutions." 2026. https://www.ncsc.govt.nz/news/canvas-data-breach-affecting-some-learning-institutions/
[6] Wikipedia contributors. "2026 Canvas data breach." Accessed September 2026. https://en.wikipedia.org/wiki/2026_Canvas_data_breach
[7] National Cyber Security Centre (GCSB). "Judgement 2: State-Sponsored Cyber Activity." 24 September 2026. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2026/judgement-2/
[8] National Cyber Security Centre (GCSB). "Judgement 4: Digital Supply Chains." 24 September 2026. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2026/judgement-4/
[9] Corrs Chambers Westgarth. "Higher Penalties and Other Privacy Act Amendments Commence." 2022. https://www.corrs.com.au/insights/higher-penalties-and-other-privacy-act-amendments-commence
[10] Herbert Smith Freehills. "$50m Penalties, More Regulatory Powers and Expanded Global Reach: Part One." October 2022. https://www.hsfkramer.com/insights/2022-10/50m-penalties-more-regulatory-powers-and-expanded-global-reach-%E2%80%93-part-one-of
[11] 1News. "North Korean operative posing as IT contractor hired by NZ business." 24 September 2026. https://www.1news.co.nz/2026/09/24/north-korean-operative-posing-as-it-contractor-hired-by-nz-business/
[12] Otago Daily Times. "North Korea uses remote IT worker to clandestinely earn NZ currency." 2026. https://www.odt.co.nz/news/national/north-korea-uses-remote-it-worker-to-clandestinely-earn-nz-currency-dxd2lxo5
[13] Forum of Incident Response and Security Teams (FIRST). "Common Vulnerability Scoring System (CVSS)." Accessed October 2026. https://www.first.org/cvss/
[14] United Nations Security Council. "Security Council Committee Established Pursuant to Resolution 1718 (2006)." Accessed October 2026. https://main.un.org/securitycouncil/en/sanctions/1718
[15] United Nations. "Security Council Fails to Extend Mandate for Expert Panel Assisting Sanctions Committee on Democratic People's Republic of Korea." 28 March 2024. https://press.un.org/en/2024/sc15648.doc.htm

