The Router Nobody Audits: When the State Walks Past Your Firewall
The nineteen-agency advisory, the edge router, and the Audit of Intent no board has run
The Systemic Risk Has a Name: When the Reserve Bank Called a Frontier Model a Threat to Financial Stability
In its May 2026 Financial Stability Report, the Reserve Bank of New Zealand named a specific frontier AI model as a source of systemic risk, and in the same chapter disclosed a three-hour outage in the high-value payment rail it operates itself
Within Months, Not Years: The Five Country Council Just Made AI Cyber Risk a Board Liability
On 22 June 2026 five allied cyber intelligence agencies, New Zealand's GCSB among them, signed a public statement telling boards that AI cyber risk is a leadership responsibility, not a technical one
Your Face Is Not Your Password: The Biometric Code Deadline NZ Boards Just Ran Out of Runway On
The 3 August 2026 deadline under the Biometric Processing Privacy Code turns nine months of quiet non-compliance into documented governance failure
Cyber Governance: New Zealand's C2 Incidents Are Back After Five Years
Three highly significant breaches in one quarter, and the architectural debt behind them
From $10,000 to Millions: The Privacy Commissioner Asks for Teeth
New Zealand's enforcement gap: 43 per cent more breaches, the same $10,000 fine
The $409 Million Lesson: When Deleting the Logs Costs More Than the Breach
The cover-up multiplier: South Korea's record privacy fine is a verdict on board conduct.
Before You Touch Frontier AI: The Advisory Every NZ Board Needs to Read Now
Executive Accountability for Frontier AI: NCSC-NZ Names the Compliance Floor
The Assurance You Didn't Verify
The MMH Phase 1 findings place cause and accountability on the public record. For boards, the lesson is not about the breach. It is about what was never confirmed in the first place.
Cybersecurity Governance: The Week AI Found the 18-Year-Old Hole
Four incidents, one pattern: AI discovers faster than boards govern
Cybersecurity Governance: Who Decides to Pay the Ransom When Your Vendor Is Breached?
The Instructure Canvas Settlement, 8,809 Institutions, and the Decision Rights Your Board Assumes It Has

