Your Board Has Three Weeks to Shape New Zealand's Critical Infrastructure Law
Return to Part 0: Table of Contents
Previous Article: Part 7, The Board's 24-Hour Fog of WarSunday 29 March 2026
Next Article: Part 8, Rebuilding Trust through AccountabilitySunday 12 April 2026
Five hundred thousand dollars. That is the proposed personal criminal penalty for a director of a critical infrastructure entity who negligently fails to meet minimum cyber security requirements under the framework New Zealand is building right now.
Not recklessly. Not knowingly. Negligently. The word choice matters. It means a director who simply failed to pay adequate attention to cyber risk could face criminal prosecution. Not a civil claim. Not a governance black mark. A criminal record and a fine that would end most careers.
The entity penalty is equally significant: up to the greater of $5 million or 2 per cent of annual turnover. For New Zealand's major banks, energy companies, and telecommunications providers, that is a figure measured in tens of millions.
These numbers are not law. They are proposals in a discussion document published by the Department of the Prime Minister and Cabinet (DPMC) on 27 February 2026 [1]. The consultation closes at 11:59 PM on 19 April 2026. Three weeks from today.
New Zealand ranks 49th on the National Cyber Security Index (NCSI), the lowest of the Five Eyes partners, and is the only one without dedicated critical infrastructure cyber security legislation [2]. That ranking provides context for the regulatory direction these proposals represent.
If your board sits within or adjacent to the seven proposed critical infrastructure sectors, being communications and data, defence, energy, finance, health, transport, and drinking water and wastewater, this is the most significant governance obligation change since the Companies Act 1993 established the section 137 standard for director care and diligence. And if your board has not read the discussion document, you are already behind.
What Is Being Proposed
New Zealand currently relies on voluntary adoption of NCSC tools and guidance for critical infrastructure cyber security. There is no mandatory baseline and no required incident reporting for critical infrastructure entities. The DPMC discussion document proposes to change this through six measures, any of which could be adopted individually or as a package [1].
The architecture starts with definition. Seven essential services form the initial scope. Within these sectors, regulations would clarify which entities meet the threshold for mandatory obligations. The discussion document offers specific examples: electricity generators with capacity at or above 30 megawatts, registered banks identified as domestically systemically important, hospitals with intensive care units. The framework distinguishes between essential infrastructure broadly and Critical Infrastructure of National Significance (CINS) at the apex, where disruption would have severely debilitating national consequences [1].
Approximately 200 organisations would fall within the initial regulatory perimeter, according to the IoD briefing on 27 March 2026 [3]. But the boundary cases are where the real governance questions emerge, and where board-level attention is most urgently needed.
The six measures span the full regulatory spectrum. Mandatory information provision to government about critical components, ownership, and dependencies. A voluntary cross-sector information exchange connecting entities with each other and with government. Mandatory sharing of specified operational information between entities. Required incident reporting, both regular and urgent. Minimum cyber risk management requirements with director accountability. And a last-resort ministerial direction power for national security threats, usable only where the threat is significant, good-faith consultation has occurred, the proposed action is proportionate, and there is no alternative [1]. That final power was misunderstood when Australia introduced its equivalent under the Security of Critical Infrastructure (SOCI) Act [4]. It is a backstop, not an operational takeover; the entity does the stopping or starting, not government.
The Cascade Problem
The discussion document includes a diagram that every director should study. It maps what happens when power and communications fail simultaneously. The cascade is immediate and total: traffic control centres go offline, airports cannot process freight, logistics companies cannot move goods, petrol stations cannot operate, banks cannot process electronic payments, emergency services lose communications, drinking water and wastewater systems fail, hospitals cannot manage patients or restock supplies, supermarkets cannot supply groceries [1].
This is not a hypothetical. This is the interdependency problem that a voluntary approach, without common baselines, leaves unresolved. When different sectors operate at different levels of security maturity, a single gap becomes a systemic vulnerability. The banking sector may invest heavily in cyber security. If a state-affiliated actor takes out the telecommunications network that banking depends on, those investments are irrelevant. Your sector's security posture is only as strong as the weakest link in your dependency chain.
New Zealand does not need to imagine this scenario abstractly. The ManageMyHealth (MMH) breach, detected 30 December 2025, compromised approximately 126,000 patient records across a platform serving 1.8 million registered users and connecting GP practices from Northland to Canterbury [5]. As of 23 March 2026, all patient notifications are complete, the mobile app is returning to service with mandatory two-factor authentication, and the Office of the Privacy Commissioner (OPC) inquiry remains active. The Ministry of Health's independent review is due by 30 April 2026. In February, the MediMap breach affected an estimated 60 per cent of New Zealand aged care facilities [6]. Two major health sector breaches in two months. Health is one of the seven proposed essential services. Under the proposed framework, a platform failure affecting patient data at this scale would trigger mandatory incident reporting and potentially director liability.
The NCSC's 2024/25 Cyber Threat Report quantified the broader exposure. Direct financial losses from cyber incidents reported to the NCSC reached $26.9 million, up from $21.6 million the previous year. Three hundred and thirty-one incidents were assessed as being of potential national significance, nearly one per day. Eighty-two of those, roughly a quarter, had suspected state-sponsored links [7].
The threat actors are not abstract. The DPMC discussion document confirms that Salt Typhoon, a state-affiliated cyber group targeting telecommunications infrastructure and critical infrastructure supply chains, has been observed operating in New Zealand [1]. These are active operations against New Zealand infrastructure, not speculative scenarios from international threat briefings.
The Sentence That Changes Everything
Buried in the discussion document's compliance framework, beside a clipboard icon, is a single statement: "Directors responsible for meeting minimum requirements" [1].
Not the entity. Not the CISO. Not the IT department. Directors. Personally.
The proposed compliance framework is staged. For minor breaches, the toolkit starts with targeted education, written warnings, and administrative fines of up to $50,000. For moderate breaches, compliance notices, enforceable undertakings, and civil penalties of up to $200,000. For serious breaches, criminal penalties: up to $2 million for the entity or 1 per cent of annual turnover, whichever is greater, and up to $100,000 for a director. For critical breaches, the ceiling rises to $5 million or 2 per cent of turnover for the entity, and $500,000 for the director [1][8].
The thresholds for director liability are explicitly framed around conduct: negligent, reckless, or knowing failure to meet the minimum requirements. DPMC has noted that these words are themselves open for feedback [3]. If negligently is not the right threshold, if the distinction between reckless and knowing creates unintended consequences, that is exactly what the consultation is designed to test. The proposed defences are reasonable: protection of life and health, matters beyond the entity's reasonable control, reasonable reliance on third-party information, and contraventions not known and not reasonably knowable [1][9]. But the direction is clear. This is a regime that treats cyber failure as a governance failure, and holds directors personally accountable.
The Law Commission is separately reviewing director liability frameworks [3]. For directors in critical infrastructure sectors, the convergence of these proposals and the Law Commission's work signals a governance environment where personal accountability for cyber risk is an inevitability to prepare for, not a possibility to defer.
The Five-Step Framework
The minimum cyber risk management requirements proposed in the discussion document follow a five-step cycle that will be familiar to any director with ISO 27001 or NIST Cybersecurity Framework (CSF) experience [1].
Step one: scope. Conduct a criticality assessment identifying the components most important to delivering your essential service, including workforce and third-party dependencies. Step two: understand. Assess the material risks that could affect those critical components. Step three: evaluate. Assess the likely impact of those material risks, including impacts on value chains and supply chains. Step four: treat. Develop and implement specific actions to reduce risk. Step five: monitor. Review and report on the effectiveness of those actions, confirm compliance, and feed findings into the next cycle.
The framework requires alignment with an internationally recognised cyber security framework. It does not mandate a specific one, but the reference points are clear: NIST CSF 2.0, ISO 27001, and the NCSC Minimum Cyber Security Standards that the Privacy Commissioner confirmed in March 2026 he is using as the "defensible baseline" for assessing compliance with the Privacy Act 2020 [10].
The treatment standard is "as far as reasonably practicable." That phrase carries specific legal weight. It provides proportionality, recognising that a rural water authority cannot invest at the same level as a major bank. But it also creates an expectation: if a risk is material, if remediation is practicable, and if you chose not to act, you will need to explain why.
The Gap the Consultation Does Not Address
One dimension of critical infrastructure governance is absent from the discussion document. Critical infrastructure entities in the health and water sectors hold taonga data, information with cultural significance under Te Tiriti o Waitangi, including health records, water management data, and land information. Te Tiriti obligations are not extinguished by a cyber security framework. They sit alongside it.
The discussion document is silent on how cultural security governance integrates with the proposed measures [1]. Boards in sectors where taonga data is held should not wait for the framework to address this. Te Mana Raraunga's Māori data sovereignty principles provide existing guidance [11]. Entities should be seeking hapū and iwi input on security governance for data with cultural significance, regardless of what the final legislation requires. For boards preparing submissions, this is a gap worth raising.
What Your Board Should Do Before 19 April
Four actions. All are achievable before the consultation closes.
First, determine your tier. Does your entity fall within one of the seven proposed essential service sectors? If you serve health, utilities, communications, finance, transport, or water, work on the assumption that you are in scope until DPMC clarifies otherwise. If you operate adjacent to these sectors, providing technology platforms, managed services, or supply chain functions to critical infrastructure entities, the framework's supply chain provisions may reach you [9]. Read the discussion document's supplementary material on defining critical infrastructure.
Second, map your critical components. What systems underpin your essential service delivery? This is step one of the proposed five-step framework. Starting now gives you a baseline when the regime takes effect and demonstrates governance diligence if the transition creates liability questions. If you are a director, ask your management team to present this mapping at your next board meeting.
Third, identify your architectural debt. What legacy systems are on your register that cannot meet modern security standards? The proposed framework will surface these through the risk identification process. Directors who can demonstrate they identified and documented their architectural debt, developed a board-approved remediation plan, and are executing against that plan are in a fundamentally different position from directors who chose not to look.
Fourth, make a submission. Use the DPMC consultation hub at consultation.dpmc.govt.nz or email criticalinfrastructure@dpmc.govt.nz before 19 April 2026 [12]. Your sector's experience and constraints are precisely what DPMC needs to calibrate the final framework. Board-level input is consistently under-represented in regulatory consultations. The IoD is preparing a draft submission focused on governance aspects and plans to circulate it to members [3]. If you are an IoD member, engage with that process. If you are not, submit directly. The consultation accepts individual submissions.
The discussion document is clear that submissions become official information under the Official Information Act and will be published in PDF format on the DPMC website [12]. Draft accordingly.
The Choice Before Boards
The consultation closes on 19 April 2026. What happens after that is legislative drafting, Parliamentary process, and implementation. DPMC has indicated a staged approach: if legislation is enacted, the first year would focus on the regulator providing tools, guidance, and support to entities, not on enforcement [3].
But the governance obligation begins now. Directors who wait for legislation to be enacted before understanding their exposure are making the same mistake that directors who waited for the Privacy Act 2020 to be enforced made: assuming that preparation time is free and unlimited.
Every Five Eyes partner has enacted dedicated critical infrastructure cyber security legislation. Australia, the United Kingdom, Canada, and the United States have all moved to mandatory baselines, incident reporting, and structured accountability [4]. New Zealand's discussion document signals movement in the same direction. Whether and how that translates into legislation is a question boards cannot afford to wait to have answered.
The question for your board is not whether to engage. It is whether you shape the framework or inherit it.
Three weeks. Nineteen April. The consultation hub is open.
Is your board in scope? What step will you take this week to prepare a submission or engage with the consultation?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is the author of The Hamberger Report: Cyber Guide for New Zealand Boards and The Hamberger Report: Generative AI 2026. He holds TOGAF, IAPP, and AMInstD credentials and has spent 30 years building mission-critical technology platforms across New Zealand's public and private sectors. He writes the Cyber Sunday series to make board-level cyber governance accessible, specific, and actionable. This is a special edition of the Cyber Sunday series, published alongside the regular 15-part schedule as a companion to the DPMC consultation. The regular series resumes next Sunday with Part 8: Rebuilding Trust through Accountability. The Hamberger Report: Cyber Guide for New Zealand Boards is the definitive board-level cybersecurity governance guide.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
[1] Department of the Prime Minister and Cabinet. "Enhancing the Cyber Security of New Zealand's Critical Infrastructure System: Discussion Document." February 2026. https://www.dpmc.govt.nz/publications/discussion-document-enhancing-cyber-security-new-zealands-critical-infrastructure-system
[2] IDM Magazine. "New Zealand Proposes Mandatory Cyber Security Regime." 2026. https://idm.net.au/article/0015522-new-zealand-proposes-mandatory-cyber-security-regime
[3] Institute of Directors / DPMC briefing session on "Enhancing the Cyber Security of New Zealand's Critical Infrastructure System." 27 March 2026. Attended by the author. Session conducted under Chatham House rule; no individual attribution.
[4] Cyber and Infrastructure Security Centre (Australian Government). "Security of Critical Infrastructure Act 2018." https://www.cisc.gov.au/legislation-regulation-and-compliance/soci-act-2018
[5] ManageMyHealth. "MMH Cyber Breach Update." 23 March 2026. https://managemyhealth.co.nz/mmh-cyber-breach-update/
[6] MediMap breach reporting, February 2026. Estimated 60 per cent of NZ aged care facilities affected; exact figures pending confirmation.
[7] National Cyber Security Centre (NCSC). "Cyber Threat Report 2024/25." 2025. https://www.ncsc.govt.nz
[8] Simpson Grierson. "New Zealand's Next Cyber Era: Higher Standards, Harder Consequences." 2026. https://www.simpsongrierson.com/insights-news/legal-updates/new-zealand-s-next-cyber-era-higher-standards-harder-consequences
[9] Russell McVeagh. "Consultation Open on Cyber Security Regime for Critical Infrastructure." 2026. https://www.russellmcveagh.com/insights-news/consultation-open-on-cyber-security-regime-for-critical-infrastructure/
[10] Privacy Commissioner Michael Webster. National Cyber Security Summit speech, 17 March 2026. Public address confirming use of NCSC Minimum Cyber Security Standards as "defensible baseline" for Privacy Act compliance assessment.
[11] Te Mana Raraunga (Māori Data Sovereignty Network). https://www.temanararaunga.maori.nz
[12] DPMC consultation page. https://consultation.dpmc.govt.nz/cyber/cyber-security-of-critical-infrastructure/

