Australia can already fine company directors personally for cyber failures. New Zealand is about to follow — and most boards have no idea it’s coming.
In February the Government released its plan to regulate cyber security for critical infrastructure (think energy, health, finance, water, telco). Buried in it is the part that should make every director sit up.
Directors would be personally responsible for meeting minimum cyber security standards. Not the IT team. Not the provider. The director.
The proposed penalties
- Up to $5 million (or 2% of turnover) for the business
- Up to $500,000 for an individual director
For context — right now the maximum fine in NZ for failing to report a breach is $10,000. In Australia it’s up to A$50 million. That’s the gap we’re closing, and we’re borrowing Australia’s playbook to do it.
The direction is clear
This is still at consultation stage & today it only targets critical infrastructure. But the direction is clear: cyber security is becoming a board responsibility, the same way health & safety did a decade ago. “We left it to IT” won’t cut it.
The good news — getting ahead of this is nice and simple. Know what data you hold, lock down access & identity, back it up, and have a plan for when (not if) something goes wrong.
If you’re a director or business owner in Northland and want to know where you actually stand, flick me a message. Happy to walk you through it, no jargon.
Source: NZ Government’s critical infrastructure cyber security discussion document (DPMC, Feb 2026).