Within Months, Not Years: The Five Country Council Just Made AI Cyber Risk a Board Liability
Five people signed a three-page document on 22 June 2026, and between them they run the cyber intelligence apparatus of the English-speaking world. The heads of the United States Cybersecurity and Infrastructure Security Agency, the United Kingdom National Cyber Security Centre, the Australian Signals Directorate, the Canadian Centre for Cyber Security, and New Zealand's own Government Communications Security Bureau put their names to a single public statement. It was published the same day, word for word, on all five agency websites. The title told boards it was for them: "The AI shift in cyber risk: why leaders must act now."
These are the agencies of the Five Country Council, the allied cyber and intelligence partnership known internationally as the Five Eyes. They do not co-sign public documents often, and when they do, the document is usually addressed to network defenders. This one is addressed to directors. That single change in audience is the story.
The line that carries the statement is its assessment of time. "The rapid pace of frontier AI development," the agencies wrote, "means cyber risk assumptions can become outdated in months, not years." Read that as a governance instruction rather than a threat bulletin. It says the shelf life of a board's cyber risk posture is now measured in months. It says the model of the world a board signed off at its last review may already be wrong. And it comes not from a vendor with something to sell, but from the five agencies whose job is to assess the most sensitive threats a state can face.
Why "months, not years" is not alarmism
The temptation is to file this under the usual noise about artificial intelligence and move on. The reason to resist that is the mechanism underneath the phrase, because the agencies were specific about why the timeline has compressed.
The core assessment is dual-use, and the statement says so plainly. The same capabilities that strengthen cyber defence, it warns, "could also enable malicious actors to conduct cyber operations more quickly, at lower cost and on a larger scale." That is the structural point. Attack and defence are being transformed by the same technology, but they are not being transformed symmetrically. An attacker needs one way in. A defender has to hold every door at once. When the tooling that finds the doors gets faster and cheaper, the side that needs one opening gains more than the side that must cover them all.
The concrete change is speed. The work of finding a vulnerability and building something that exploits it used to run in weeks or months. AI compresses that cycle towards hours. New Zealand's own companion guidance, published four days before the joint statement, gives the compression a name: the "vulnerability storm" that AI-assisted attackers can generate against an organisation carrying old systems and thin security hygiene. Catriona Robinson, Deputy Director-General of Cyber Security at GCSB and the head of NCSC-NZ, put the same point in operational terms at the statement's release: AI, she said, "is already having a material impact on cyber security, lowering barriers for malicious actors while significantly accelerating the speed, scale and sophistication of attacks."
Note the tense. Not will have. Is already having. The agencies are not forecasting a future threat class; they are describing a present one and warning that its curve is steep.
The attack that needed no exotic technique
If you want to see what the advisory means in a boardroom rather than a briefing, look at Marks & Spencer. The retailer was compromised in April 2025 by the group known as Scattered Spider, and the entry point was not a zero-day or a piece of exotic malware. An attacker telephoned a third-party service desk, impersonated an employee, and had a password reset. From there the attackers reached the Windows domain controller and exfiltrated the file holding the password hashes for every user in the domain. Ransomware followed. Online sales were suspended for the better part of a week.
The numbers are the part a board feels. The suspension cost the retailer roughly £3.8 million a day in lost online revenue, on the order of NZ$8 million a day at mid-2026 exchange rates. More than £500 million was wiped from its market value. And the detail that should stay with every director is the timing at the top: the compromise landed on 17 April, and M&S leadership did not become aware of it until 19 April. Two days. The board learned about the incident that was reshaping its market capitalisation after the attackers had already been inside for the better part of a working week.
This is why the advisory's urgency is credible. The M&S attack required social engineering of a service desk and the absence of basic identity checks, nothing more. AI does not invent this attack; it makes it faster, cheaper, and more convincing to run at scale. Impersonation that used to need a skilled operator can now be generated. The conditions that let Scattered Spider in, a third party with reset authority and no verification step, are present in hundreds of New Zealand organisations right now.
What the statement actually asks of directors
The advisory is unusual because it does not stop at describing the threat. It gives boards a direct instruction, and the language is worth quoting because it is doing the work the Cyber Guide for New Zealand Boards has argued from first principles for a year.
"Cyber risk can no longer be treated as a purely technical issue," the agencies wrote. "This is a core business risk and leadership responsibility." A second direction tells organisations to give their cyber leaders real authority and real resources, not a title without a budget. A third is the one that should be read into the minutes of the next board meeting: "Boards and executives should ensure cyber resilience is in place and works under pressure; it is not enough to have controls."
That last sentence is the Audit of Intent expressed in intelligence-agency language. The question it forces is not whether a policy exists. It is whether the policy would survive contact with a real incident. A tabletop exercise that has never been run, an incident response plan that lives in a shared drive and has never been tested, a backup regime nobody has attempted to restore from: each of these is a control that exists and has not been shown to work under pressure. The advisory says that gap is now the board's to close.
Underneath the three directions sit five practical actions the agencies name for every organisation: reduce the attack surface, accelerate patching with priority on vulnerabilities known to be exploited, remediate or isolate legacy systems including exposed admin login panels and operational technology, strengthen identity and access management, and test and prepare incident response processes. None of these is new to a security team. What is new is that five intelligence agencies have jointly signed them as a leadership expectation, and have told directors to stay engaged as the guidance changes rather than treat compliance as a one-off event.
There is a fiduciary edge to this that a New Zealand director cannot wave away. Under section 137 of the Companies Act 1993, directors must exercise the care, diligence, and skill of a reasonable director. Set that duty beside a signed public statement from New Zealand's own intelligence community telling boards that AI cyber risk is their responsibility. A director who cannot show any engagement with that statement, if an AI-enabled breach later lands, would face real difficulty arguing they exercised reasonable diligence. This is an analytical observation, not a legal opinion, and I am not offering it as one. But the point is simple enough to state cleanly: the advisory itself is now part of the record against which director conduct will be measured. It is easier to explain to a court, a regulator, or a shareholder what you did about a warning than why you ignored one.
This is New Zealand guidance, not international background
It would be a mistake to read the Five Country Council statement as something that happened overseas with a local angle bolted on. GCSB and NCSC-NZ are named co-authors. The statement is New Zealand government guidance that happens to carry the weight of four allied intelligence services alongside it.
The sequencing makes the point. On 18 June 2026, four days before the joint statement, NCSC-NZ published its own document, "Frontier AI: Managing the increasing risks from vulnerabilities," followed by a second companion piece on the implications of frontier AI for cyber defence. An agency that was merely reacting to an international advisory does not publish its domestic guidance first. NCSC-NZ was not responding to the statement; it helped write it.
And the domestic guidance is not abstract. It tells New Zealand organisations to apply the Minimum Cyber Security Standards, to run disciplined vulnerability management with timely patching, to assume compromise rather than assume safety, to put controls around any use of AI for finding vulnerabilities, to limit what an AI system can reach to only what its function requires, and to weigh the legal and contractual obligations that come with all of it. That is a board reading list, not a technical appendix.
The same week, NCSC-NZ published its Quarter One 2026 Cyber Security Insights. The report recorded 1,164 incidents in the quarter and, more tellingly, NZ$5.6 million in direct financial losses, a 76 per cent increase on the previous quarter's NZ$3.2 million. Phishing and credential harvesting were the single most common category at 437 incidents. The shape of that data matters as much as the totals: incidents needing specialist technical support actually fell, while volume and financial damage rose. The threat is getting broader and more expensive without getting more technically sophisticated per incident, which is precisely the pattern the advisory describes when it talks about lower barriers and larger scale.
Then there is the case the country already has on file. In May 2026 the Privacy Commissioner, Michael Webster, issued compliance notices, the strongest tool the Privacy Act 2020 provides, to both ManageMyHealth and Health New Zealand over the December 2025 breach. The Phase 1 inquiry found that both organisations had failed to keep reasonable security safeguards in place, a breach of Rule 5 of the Health Information Privacy Code, across an inquiry scope of 99,416 patients. What the inquiry described was not one broken control but a chain of them: no monitoring for unusually large-scale access, incomplete security design, no multi-factor authentication, and Health NZ relying on ManageMyHealth's own assurances without verifying them independently. The Commissioner characterised the breach as a governance and oversight failure before it was a technical one. Phase 2 is under way as at publication. I am describing the finding as the regulator stated it, not commenting on how the inquiry has been run or how either organisation has responded; that is not a board's to adjudicate, or mine.
The ManageMyHealth breach is the local worked example of everything the advisory warns about. Legacy-adjacent systems, a missing identity control, a third party trusted without verification, sensitive data at the centre. The advisory says AI is about to make that combination faster and more consequential to exploit. New Zealand does not have to imagine the failure mode. It has the report.
What follows if boards treat this as optional
The advisory sits at the front of a regulatory trajectory, and reading the two together is where a director sees the direction of travel.
The Reserve Bank's Operational Resilience Standard, released as an exposure draft for consultation on 18 June 2026, requires each critical operation to carry a documented tolerance level, the limit of disruption an institution will accept, and makes the board responsible for owning it. The draft guidance contemplates assessing whether an AI failure, misuse, bias, model drift, cyber compromise, or third-party failure could impair a critical operation. The standard's existence and the consultation are settled facts; the exact wording of that AI clause is still draft, and I am treating it as representative of where the guidance is heading rather than as final legislative text. The standard applies to deposit takers and insurers, not to every board in the country. But it is the clearest signal yet of how the advisory's "leadership responsibility" language gets turned into a written regulatory obligation. Submissions close on 11 September 2026; the standard is not in force until December 2028. It is the direction being set, not a duty that has already arrived.
Behind it sits the proposed Mandatory Cyber Security Regime for critical infrastructure, on which consultation closed on 19 April 2026 and the government's response has not been published as at publication. As proposed, and it must be read as proposed because no legislation has been enacted, the most serious non-compliance would carry criminal liability of up to NZ$500,000 per director, and up to NZ$5 million or 2 per cent of annual turnover per entity. I make no prediction about whether or in what form that regime proceeds; the point is only that the enforcement architecture being contemplated puts director liability on the table.
The trans-Tasman baseline confirms the trend is structural rather than a local spike. The Office of the Australian Information Commissioner recorded 1,205 data breach notifications for 2025, the highest total since the mandatory scheme began in 2018 and 8 per cent above 2024. Health providers were the single largest sector at 19 per cent, a pattern that holds across consecutive years rather than an anomaly. New Zealand does not publish an equivalent annual report at that resolution, and many New Zealand organisations share suppliers, cloud infrastructure, and sector characteristics with their Australian counterparts. The floor is rising on both sides of the Tasman. A second allied advisory reinforces the consensus from outside the Five Eyes: the Cyber Security Agency of Singapore issued its own advisory on frontier AI risk in 2026, which tells a New Zealand board that the "months, not years" assessment is not a regional opinion but a cross-jurisdictional one.
The gap that widens while you wait
Here is the single most useful thing a director can take from the advisory, and it is a governance question rather than a technical one. If cyber risk assumptions can become outdated in months, then a board that reviews its AI cyber risk posture once a year is, by the agencies' own measure, structurally behind.
Work the arithmetic. A twelve-month review cycle, set against a threat the agencies say can move in months, generates a window of six to eleven months in which the board is operating on assumptions it has not tested against current conditions. That window is not static. It widens continuously as frontier capability advances between reviews. The annual cyber update, the fixture that has anchored board governance calendars for years, is the wrong cadence for a threat that changes on this clock. The question to put on the agenda is blunt: how often does this board actually review its AI cyber risk posture, and is that frequency honest against a threat the intelligence community says evolves monthly?
There is a New Zealand dimension to that gap that the series has never treated as optional. The organisations carrying the most legacy infrastructure and the most sensitive data are the health providers, and the advisory's "vulnerability storm" lands hardest exactly there. The ManageMyHealth inquiry confirmed that roughly 91 per cent of the affected patients were in Northland, many of them likely Māori, because of a unique arrangement that surfaced hospital discharge information through the portal in that region and nowhere else. That is a structural governance observation, not a cultural generalisation: the populations most exposed to the threat the advisory describes are the ones whose data sits in the legacy-rich systems the advisory specifically warns about. Māori data sovereignty is not a supplementary consideration here. It is a load-bearing part of the risk assessment, because the "who is most exposed" question has a documented answer.
What this means for sovereign capacity
The Five Country Council statement is not, in origin, a commercial governance document. It is a product of the allied signals and cyber intelligence architecture. In New Zealand, the United Kingdom, Australia, and Canada, the national cyber agency sits inside the signals intelligence service itself: NCSC-NZ is a function of the Government Communications Security Bureau, the United Kingdom's NCSC of GCHQ, the Australian Cyber Security Centre of the Australian Signals Directorate, and the Canadian centre of the Communications Security Establishment. When those services jointly assess that a threat has crossed into the civilian economy, they are applying the frame they use for state-sponsored operations. For New Zealand the implication is direct. Every critical infrastructure sector, energy, water, finance, health, logistics, runs behind the legacy-rich, identity-weak perimeter the advisory describes. A board that acts on it is meeting its director duty and strengthening the resilience its security services depend on.
So the exercise for your next board meeting is not a presentation on artificial intelligence. Your people already know AI is changing the threat. The exercise is to answer three questions with evidence rather than assurance. When did this board last review its AI cyber risk posture, and does that cadence hold up against a threat the intelligence community says moves in months? Can we show that our resilience works under pressure, or only that our controls exist on paper? And if the Privacy Commissioner, or a shareholder, or a court asked what this board did after five intelligence agencies told it AI cyber risk was its responsibility, what could we actually produce?
The agencies have already done the hard part. They have applied their most sensitive analytical frame to the problem and handed the conclusion to boards in plain language. The runway they describe is measured in months. What would your board hand over if someone asked it, next week, to show its work?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
References
[1] Cybersecurity and Infrastructure Security Agency; National Cyber Security Centre (UK); Australian Signals Directorate; Canadian Centre for Cyber Security; National Cyber Security Centre (NZ). "The AI shift in cyber risk: why leaders must act now." Joint statement, 22 June 2026. https://www.cisa.gov/
[2] National Cyber Security Centre New Zealand. "Leaders of Five Eyes Cyber Security Agencies Call to Action on AI Preparedness." 22 June 2026. https://www.ncsc.govt.nz/
[3] National Cyber Security Centre New Zealand. "Frontier AI: Managing the increasing risks from vulnerabilities." 18 June 2026. https://www.ncsc.govt.nz/
[4] National Cyber Security Centre New Zealand. "Quarter One sees significant cyber incidents (Cyber Security Insights, Q1 2026)." 22 June 2026. https://www.ncsc.govt.nz/
[5] Office of the Privacy Commissioner. "Compliance notices issued to ManageMyHealth and Health New Zealand: Phase 1 inquiry findings." May 2026. https://www.privacy.org.nz/
[6] Reserve Bank of New Zealand. "Operational Resilience Standard: exposure draft and consultation (Deposit Takers Act Tranche 3)." 18 June 2026. https://www.rbnz.govt.nz/
[7] Office of the Australian Information Commissioner. "Data breach notifications increase to all-time high in 2025, new NDB stats show." 2026. https://www.oaic.gov.au/
[8] Computer Weekly. "Marks & Spencer cyber attack: how Scattered Spider breached the retailer." April to June 2025. https://www.computerweekly.com/
[9] ISACA. "Analysis of the Marks & Spencer incident and the governance lessons for boards." ISACA newsletter, Volume 16, 2025. https://www.isaca.org/
[10] Parliamentary Counsel Office. "Companies Act 1993, section 137 (director's duty of care)." https://www.legislation.govt.nz/act/public/1993/0105/latest/whole.html
[11] Ministry of Justice; Department of the Prime Minister and Cabinet. "Proposed Mandatory Cyber Security Regime for critical infrastructure: consultation." Consultation closed 19 April 2026. https://www.dpmc.govt.nz/
[12] Cyber Security Agency of Singapore. "Advisory on risks associated with frontier AI models (AD-2026-004)." 2026. https://www.csa.gov.sg/alerts-and-advisories/advisories/ad-2026-004

