| Cyber security leadership is the board and executive work of setting cyber risk appetite, funding the controls that match it, and holding management to account for the gap between the two. It is governance work, not technical work, and it cannot be delegated to the IT team. |
Search for what a New Zealand director is on the hook for after a cyber breach and the first page of results will tell you, more than once, that cyber risk has just become personal and that most boards have not caught up. The claim rests on a real document. It also gets two things wrong about that document, and both of them matter if you are the person making the decision.
The Department of the Prime Minister and Cabinet did publish proposals in February 2026 that would make individual directors criminally liable for the worst cyber failures. Those proposals are not law. Consultation on them closed in April 2026, no bill has followed, and the regime as drafted would reach around 200 organisations nationally, well short of every company that has a board.
So the answer to “am I personally on the hook” is that a cyber incident does not by itself make a director personally liable, and that this particular regime is a proposal rather than law. That is a long way from saying nothing is expected of you. Cyber security leadership already carries real duties in New Zealand, most of them sitting under privacy law and general director obligations, none of them cyber-specific, and the evidence suggests boards are giving them less attention than they did two years ago.
This page sets out what cyber security leadership requires of your board today, what the proposals would change and for whom, and the questions worth putting to your management team at the next meeting.
What Does Cyber Security Leadership Actually Mean for a Board?
Cyber security leadership means owning three decisions the board answers for: how much cyber risk the organisation is prepared to carry, how much it will spend to close the gap between that appetite and its actual exposure, and who answers for the gap that remains. Everything else follows from those three. Boards structure that work differently. The IoD notes that some treat it as a full board responsibility while others delegate it to an audit, risk or technology committee, and management can act within the authority the board has agreed. What does not move is who answers for the result.
The Institute of Directors sets this out in its 2025 guide for New Zealand boards, which keeps the same five core principles it carried in earlier editions. They are worth reading in full, but the shape of them is simple enough to hold in your head.
The five principles the IoD asks New Zealand boards to work to:
- Take a complete approach, treating cyber security as an enterprise-wide risk rather than an IT issue.
- Establish an enterprise-wide cyber risk management framework.
- Give cyber security regular attention on the agenda, and build the board’s own competency.
- Understand the legal environment your organisation operates in.
- Categorise and address the risks, deciding which to avoid, accept, mitigate or transfer.
Note what is absent from that list. There is no requirement to understand how a firewall works, no expectation that a director can read a penetration test. The NCSC takes the same line in its governance series, framing the board’s job as culture, roles, risk, collaboration, a funded programme and measurement, and not one of those six is a technical skill.
This is the part that gets lost when cyber security leadership is described as a training problem. Training your staff to spot a phishing email is worth doing, and we have written about how to run that well, but it is a management activity, and a board that has bought a training module has not thereby governed the risk.
Are New Zealand Directors Personally Liable for a Cyber Breach?
Not under any cyber-specific law, because New Zealand does not currently have one. A director’s exposure today runs through the general duties in the Companies Act 1993, principally the duty to exercise the care, diligence and skill a reasonable director would exercise in the same circumstances. A board that ignored a known, material cyber risk could be tested against that standard, in the same way it could be tested over any other neglected risk. What the standard does not give you is a bright line. Identifying a risk, discussing it and funding work against it are the things a board should be able to show, but a minute or a budget line does not settle whether the duty was met. Exposure in a particular organisation or incident is a question for your lawyer.

What has changed is that a specific regime has been proposed. In February 2026 the Department of the Prime Minister and Cabinet released a discussion document on the cyber security of critical infrastructure. It proposes that directors of covered entities be responsible for ensuring compliance with minimum cyber requirements, and it floats making cyber security a core element of directors’ fiduciary duty.
It also proposes penalties, and they are not trivial. A serious breach would carry a criminal penalty for the entity of up to $2 million or 1 percent of annual turnover, whichever is greater, and up to $100,000 for a director. A critical breach would carry up to $5 million or 2 percent of turnover, whichever is greater, and up to $500,000 for a director.
Read the definitions before you read the numbers, because they are not what the headlines imply. In the discussion document a serious breach means negligently, recklessly or knowingly failing to review progress against the minimum cyber security requirements within set timeframes. A critical breach means negligently, recklessly or knowingly failing to meet those requirements, or failing to comply with a national security direction. The penalties attach to what an organisation did about its obligations, not to the fact that it was attacked.
Those figures are real, and they are the ones the alarming headlines are built on. Three things about their status get left out of every headline that quotes them, and each of the three changes what the proposal means for your board.
The document is a discussion document, not a bill. Consultation ran from 27 February to 19 April 2026 and closed. DPMC’s stated next step is to use the feedback to inform final proposals for Cabinet. As at September 2026 no legislation has been introduced, no commencement date has been named, and the document itself notes that the responsible ministerial portfolio has not yet been allocated and no regulator has been chosen.
The director question is still open inside the proposal itself. Two of DPMC’s own consultation questions ask whether there is a more effective way to ensure compliance than attaching responsibility to individual directors, and whether individual director liability would produce perverse outcomes. Those are not the questions a department asks about a policy it has already settled.
The third omission is scope, and the regime as drafted would not apply to most New Zealand companies at all, for reasons the next section sets out.
Which Businesses Would the Proposed Cyber Rules Cover?
About 200 organisations, by DPMC’s own initial assessment, across seven essential services: communications and data, defence, energy, finance, health, transport, and drinking water and wastewater. New Zealand has several hundred thousand businesses. The proposed regime is aimed at the infrastructure the country cannot function without, and the thresholds are set high. Size alone would not settle the question, because the Minister would also have power to designate entities into the regime and to exempt entities that meet the definition, tabling reasons in Parliament either way.
There is no general small business exemption written into the proposals. That sounds alarming on its own, so it is worth setting out how the exclusion actually works. It operates sector by sector, with each essential service carrying its own service threshold, and those thresholds are large.
| Sector | Proposed threshold to be captured | Where a typical SME sits |
|---|---|---|
| Telecommunications | Retail services to at least 10,000 customers, or 10,000 wholesale connections | Well below |
| Electricity | Generation of 30 megawatts or more, or distribution to more than 25,000 connection points | Not applicable |
| Drinking water and wastewater | Networks serving at least 25,000 connections, plus the Queenstown Lakes District Council reticulated wastewater service by ministerial designation | Not applicable |
| Finance | Registered banks identified by the Reserve Bank as domestically systemically important, systemically important financial market infrastructure designated under the Financial Market Infrastructures Act 2021, and the NZX | Not applicable |
The communications and data category works differently again, and this is where we have a direct interest worth declaring. It captures the provision of managed services, defined as managing IT infrastructure, devices, systems, networks or applications where that IT is integral to the delivery of essential services by a specified number of critical infrastructure entities. Data centre and data services providers are captured on a related but separate basis, where they store or process data integral to the delivery of essential services by a critical infrastructure entity, with no number attached. Neither category carries a size test of its own.
Read plainly, that means a managed IT provider could be pulled into the regime through its client list rather than its own size. Exodesk is a managed service provider. We read this document closely because it may eventually apply to us, which is a better reason to trust our summary of it than the fact that it makes for an arresting headline.
For the businesses we work with, the practical answer is straightforward. If you are a professional services firm, a manufacturer, a retailer, a school or a medical practice without an intensive care unit, none of the proposed service thresholds is written for you. Check the activity and the dependencies rather than the headcount, and remember the designation power sits above the thresholds. What reaches you today is the law that already exists.
What Cyber Duties Do New Zealand Boards Already Have?
The main one is the Privacy Act 2020, and it applies to every organisation in New Zealand regardless of size. If your business suffers a privacy breach that has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and the affected people as soon as practicable. Failing to notify the Commissioner without reasonable excuse is an offence carrying a fine of up to $10,000.
That $10,000 is small enough to be misread as unimportant. The fine is not the exposure. The exposure is the Commissioner’s investigation powers, the compliance notice that can follow, the class of affected individuals who can take a complaint to the Human Rights Review Tribunal, and the possibility of the Commissioner naming the organisation publicly. Naming is not automatic. The Commissioner names an agency only where, on balance, that is considered appropriate for giving effect to the Privacy Act, which is more likely where a breach is very serious or where an agency has been unwilling to comply. Most of what determines whether you reach that point is ordinary data security practice, decided long before any incident.
Alongside the Privacy Act sit the duties every director already carries. The Companies Act obligation to act in good faith and in the best interests of the company, and to exercise reasonable care, does not carve out technology. Health and safety law offers a useful comparison here: directors are expected to exercise due diligence over a risk they are not personally expert in, by asking for information, understanding the hazard and verifying that resources have been allocated. Cyber risk is not yet regulated that way. It asks much the same of a director in practice, and boards that already handle health and safety diligence well have most of the habit they need for cyber security leadership.
Sector obligations add to this for some boards. Financial institutions have Reserve Bank guidance on cyber resilience. Public organisations have the Protective Security Requirements, mandatory for the core public service. Contracts increasingly carry their own security clauses, and your insurer will have underwritten your cover on the strength of controls it expects to find still in place when it is called on.
Why Is Board Attention to Cyber Risk Falling in New Zealand?
Attention appears to have moved. The Institute of Directors surveyed 900 New Zealand directors between August and September 2025, and the pattern in the results is hard to miss once you line the numbers up.

Boards that agreed they discuss cyber risk and their ability to respond fell to 57.2 percent, down from 62.2 percent the year before. Boards receiving comprehensive reporting on data breach risk sat at 55.2 percent, effectively unmoved across three years. Over the same period, boards working with management on how technology and AI could lift productivity rose to 60.6 percent, up from 48.2 percent.
Read together, those figures point to uneven attention across a risk and an opportunity. They do not establish that one displaced the other, and the survey records what directors report rather than what every board did. The reason to look at them together is that the same AI tooling now on the board agenda for productivity is on the attacker’s agenda for phishing and impersonation.
One more figure from the same survey deserves care, because it is easy to read backwards. The proportion of boards that had overseen a cyber attack in the previous twelve months fell from 17.9 percent to 10.3 percent. That looks like good news. It may also mean fewer incidents are reaching the board, and that is what you would expect if reporting has flattened while attacks have not. The survey does not distinguish between the two, and neither should we.
What Should a Board Ask Management About Cyber Security?
Ask questions that produce a decision. The failure mode in board cyber reporting is not that management withholds information; it is that the information arrives in a form no director can act on. A patch compliance percentage tells you nothing about whether the company would survive a Tuesday morning ransomware event.
These are the questions we would want a client’s board asking, drawn from the IoD guide, the Auditor-General’s checklist for governors and our own incident work. Cyber security leadership shows up in which of them a board is willing to keep asking after the first uncomfortable answer.
Questions worth putting on the agenda:
- What level of cyber risk are we prepared to accept, and how far is our actual exposure from it?
- What would it cost to close that gap, and what does it cost us to leave it open?
- Which data and systems would stop the business if we lost them, where do they live, and who can reach them?
- When did we last restore from backup as a planned test, not during a live incident?
- When did we last rehearse an incident, and what did we change afterwards?
- What do our third parties and suppliers have access to, and who verified their controls?
- Has anyone independent assessed our security in the last two years, and what did they find?
- If we were breached tonight, who decides whether to notify the Privacy Commissioner, and by when?
The last one catches more boards than it should. Notification under the Privacy Act runs on a legal test and a short clock, and the decision usually has to be made while the technical picture is still incomplete. Boards that have not discussed it in advance tend to discuss it for the first time under pressure, badly.
How Does a Board Know Its Cyber Reporting Is Good Enough?
Good reporting shows a trend and a gap. The Auditor-General looked at how a selection of New Zealand public organisations govern cyber risk and published the findings in April 2025, and the central observation travels well beyond the public sector. Most of the organisations audited were carrying more residual cyber risk than they had an appetite for, and it was uncertain whether they could close the difference.
That gap is the thing a board should be able to see on a page. If your cyber reporting cannot show it, the reporting is describing activity when it should be describing position.
The Auditor-General’s other findings are damning in the understated way audit reports tend to be. Reporting frequency and detail varied. Testing and rehearsal were often insufficient, and some incident response plans were not detailed enough. The role of governors during a significant incident was set out inconsistently. None of those requires new legislation to become worth fixing, and each is something a board can put on its work programme with a named owner and a date.
There is a cultural finding in there too, and it is the one closest to the original point of this page. The report is direct about tone from the top: how governors and managers themselves behave sets the expectation for everyone else. A board that asks for multi-factor authentication across the business and exempts itself from it has told the organisation exactly how much the policy is worth. Cyber security leadership is visible or it is not leadership.
Frequently Asked Questions
Is cyber security a legal responsibility of directors in New Zealand?
Not as a standalone cyber duty, because no cyber-specific director liability regime exists here yet. Directors are still covered by the general duty in the Companies Act 1993 to exercise the care, diligence and skill a reasonable director would in the circumstances, and by the Privacy Act 2020 obligations that fall on the organisation. Whether a duty has been met in a particular case is a legal question, so take advice on your own circumstances.
Will New Zealand directors face fines for cyber breaches?
Not under current law, because New Zealand has no cyber-specific director penalty regime. The February 2026 discussion document proposed criminal penalties of up to $100,000 for a director on a serious breach and $500,000 on a critical breach, but those terms describe failing to review or meet minimum cyber security requirements, not suffering an attack. Consultation closed in April 2026 and no bill has been introduced.
Does the proposed critical infrastructure regime apply to small businesses?
Usually not, but size alone does not decide it. The proposals cover an estimated 200 entities across seven essential services, with thresholds such as 10,000 telecommunications customers or 25,000 water connections. A typical small or medium business sits well below those, though the Minister would also be able to designate entities in or exempt them, so the activity and its dependencies are what to check.
Could our IT provider be captured by the proposed rules?
It is possible, and the two categories work differently. Managed services are captured where the IT managed is integral to essential services delivered by a specified number of critical infrastructure entities, and the discussion document leaves that number unspecified. Data centre and data services providers are captured where they store or process data integral to delivery by a critical infrastructure entity, with no number attached. Neither carries a size threshold.
What is the difference between cyber security leadership and cyber awareness training?
Leadership sets the risk appetite and funds the response; training builds the habits that carry it out. One is a board function and the other is a management programme. Confusing them is why some boards believe they have addressed cyber risk when what they have actually done is buy a training module.
How often should cyber security be on the board agenda?
Often enough to show a trend, which in practice means every meeting for organisations with material digital dependency and at least quarterly for everyone else. The IoD position is that it should be a standing item rather than something raised when an incident forces it.
Who should report cyber risk to the board?
Whoever holds the security accountability, with direct access to the board rather than a filtered path through management layers that have competing objectives. In smaller New Zealand organisations that is often an external provider, and the same principle applies: the board should be able to question them directly.
What does a good board cyber report contain?
Current exposure against stated risk appetite, the trend on both, detection and response times, the state of vulnerability remediation, results of the last restore and incident rehearsal, and third party risk. If the report is a list of completed tasks, it is a management report that has been sent to the wrong audience.
Do we need a director with cyber expertise on the board?
Not necessarily, and hiring for it is not the only answer. What matters is that the board has access to enough expertise to challenge what it is told, whether that comes from a director, an independent adviser or a provider it can question without management present.
Does cyber insurance transfer the board’s responsibility?
No. Insurance transfers a defined portion of financial loss and often brings useful incident response services with it, but the duty to govern the risk stays with the board. Insurers also underwrite on the strength of your controls, so weak governance shows up in your premium or your exclusions.
What should a New Zealand board do first if it has never reviewed cyber risk?
Establish the gap between the risk you are carrying and the risk you are willing to carry, because every other decision depends on that number. An external assessment can help, though it is not automatically independent or faster, so scope it around what the board needs to decide. Cyber security leadership is mostly the discipline of keeping that number in front of you.
Is the Privacy Act the main cyber obligation for most New Zealand businesses?
It is the one that applies most widely, because it applies regardless of size and carries a mandatory notification duty for breaches likely to cause serious harm. It is not automatically the most important one for every organisation. Operational disruption, sector rules, safety duties and contractual security clauses can matter more, and can be triggered by an incident that exposes no personal information at all.
NEXT STEP
Where to start
If your board has not looked at its cyber position in the last year, the useful first step is a clear picture of where your exposure sits against what you are willing to carry, in language a director can act on, and not another policy document. We run that assessment for New Zealand businesses as part of our cyber security services. You get the findings in writing, covering the material risks, what it would take to address them and what we could not establish. That is what makes cyber security leadership workable in practice: a position the board can question rather than a score it has to accept.
Or read more about our cyber security services.

