Cyber Liability Is Coming for NZ Company Directors

Posted: June 25, 2026Category:

Australia can already fine company directors personally for cyber failures. New Zealand is about to follow — and most boards have no idea it’s coming.

In February the Government released its plan to regulate cyber security for critical infrastructure (think energy, health, finance, water, telco). Buried in it is the part that should make every director sit up.

Directors would be personally responsible for meeting minimum cyber security standards. Not the IT team. Not the provider. The director.

The proposed penalties

  • Up to $5 million (or 2% of turnover) for the business
  • Up to $500,000 for an individual director

For context — right now the maximum fine in NZ for failing to report a breach is $10,000. In Australia it’s up to A$50 million. That’s the gap we’re closing, and we’re borrowing Australia’s playbook to do it.

Australia is the preview

In February 2026 the Federal Court fined Australian financial services firm FIIG Securities AUD $2.5 million. The company had suffered a cyber-attack that exposed the personal data of around 18,000 clients — drivers’ licences, passports, bank and tax details, later dumped on the dark web. The penalty wasn’t for the breach itself. It was for years of underinvestment in security before it happened. The judge called it “a warning to businesses with inappropriate underinvestment in cybersecurity”.

Across the ditch, cyber has become a director problem. In New Zealand we’re a step behind — but heading the same way.

The direction is clear

This is still at consultation stage & today it only targets critical infrastructure. But the direction is clear: cyber security is becoming a board responsibility, the same way health & safety did a decade ago. “We left it to IT” won’t cut it. A new civil penalty regime under the Privacy Act is being considered alongside it — and the Privacy Act reaches a lot more of us than critical infrastructure does.

What a business owner should actually do this quarter

Here’s the good news — you don’t need to panic or spend a fortune. Three simple things will put you ahead of most:

  • Turn multi-factor authentication (MFA) on everywhere — email, remote access and admin accounts.
  • Write down who does what the day you’re breached — a one-page incident plan beats a blank stare.
  • Check your cyber insurance actually pays out — read what it requires of you, before you need to claim.

Beyond that: know what data you hold, lock down access & identity, back it up, and keep evidence of due diligence — an audit a board can point at.

Want to know where you stand?

We help Northland business owners get the basics right without the jargon or the scare tactics. See how we keep businesses secure, or if you’re a director or business owner in Northland, flick me a message. Happy to walk you through it, no jargon.

Source: NZ Government’s critical infrastructure cyber security discussion document (DPMC, Feb 2026); Federal Court of Australia, ASIC v FIIG Securities (Feb 2026).

Contact us today