Cyber Security Threats Facing Kiwi Businesses

A plain look at the cyber threat landscape for NZ businesses, who attackers target, why SMEs are in the firing line, and what the data from CERT NZ shows.

Cyber Security Threats Facing Kiwi Businesses

Ask a business owner in Christchurch or Tauranga whether they are a target for cyber criminals, and many will say no. They are too small, too local, not interesting enough. That belief is exactly what attackers count on. The reality on the ground in New Zealand is that small and medium businesses are not flying under the radar. They are the radar.

This article steps back from any single attack type to look at the wider picture: who is being targeted, why the threat has grown, and what the New Zealand data actually tells us. Understanding the landscape is the first step in deciding where to spend your limited security budget.

Who do attackers actually target in New Zealand?

There is a comforting myth that cyber crime is aimed at banks, government, and large corporates. Those organisations are targets, but they also have security teams, big budgets, and layers of defence. Many attackers prefer easier work.

SMEs sit in a difficult spot. They hold valuable data, client records, payment details, intellectual property, but they rarely have the same protection as a large enterprise. CERT NZ’s reporting has long shown that individuals and small businesses make up a large share of incidents. The attacker does not need to know your name. Automated tools scan the whole internet for exposed services, weak passwords, and unpatched systems, then exploit whatever they find.

So the honest answer is that most attacks are not personal. You are targeted because a tool found a gap, not because someone chose you. That changes how you think about defence. You are not trying to outsmart a single hacker. You are trying to be a harder target than the next business the scanner reaches.

Why has the threat grown for smaller businesses?

A few shifts have made the past few years harder for Kiwi SMEs.

The first is cloud and remote work. Business data that once sat on a server in the back office now lives in Microsoft 365, accounting platforms, and cloud file storage, reachable from anywhere. That flexibility is genuinely useful, and it also means a stolen password can open the front door from the other side of the world.

The second is the professionalisation of cyber crime. Attacks are now a service you can buy. Ransomware kits, phishing templates, and stolen credentials are traded openly on criminal marketplaces. A person with limited technical skill can rent the tools to run a credible attack, which expands the pool of people who might come after your business.

The third is artificial intelligence. Generative tools let attackers write convincing emails in fluent English, build fake websites quickly, and personalise scams at scale. The crude phishing email is being replaced by messages that reference your real suppliers and projects.

What does the New Zealand data tell us?

CERT NZ, the government’s cyber security agency, publishes quarterly reports on incidents reported by New Zealanders. A few patterns hold steady across those reports.

  • Phishing and credential harvesting are consistently the highest-volume category. Most incidents start with someone being tricked, not with a technical breach.
  • Scams and fraud, including business email compromise and invoice fraud, account for the largest direct financial losses.
  • Reported losses run into the tens of millions of dollars each year, and the true figure is higher because many businesses never report.

The under-reporting matters. A lot of SMEs handle a breach quietly out of embarrassment or fear of reputational damage. That silence creates a false sense that “it does not happen here.” It does, often, and the businesses affected look very much like yours.

How does the Privacy Act 2020 change the picture?

The threat is not only operational. Since December 2020, New Zealand’s Privacy Act has required organisations to notify the Office of the Privacy Commissioner and affected people when a privacy breach is likely to cause serious harm.

For a business that suffers a data breach, this turns a technical problem into a legal and reputational one. If client personal information is stolen, you may have a legal duty to tell those clients their data is in criminal hands. Failing to notify when required can bring penalties, and the conversation with customers is rarely a comfortable one.

This raises the stakes for the kinds of attacks that involve data theft, particularly ransomware groups that now steal data before encrypting it. The security question and the privacy obligation are tied together.

Which threats deserve the most attention?

Not every threat carries the same weight for an SME. Based on the New Zealand picture, three areas reward attention first.

People-targeted attacks come first. Phishing and business email compromise cause the most incidents and the biggest losses, and they often sidestep technical controls entirely.

Account and access security comes second. Weak or reused passwords, and accounts without multi-factor authentication, are the gap that turns a single phishing success into a full compromise.

Data resilience comes third. Tested, isolated backups are what stand between a ransomware infection and a business-ending event. They also shape how serious any incident becomes.

The temptation is to buy a product and feel protected. Tools matter, but the landscape shows that habits, process, and the basics done consistently make the difference for most businesses.

Where this leaves you

The threat facing Kiwi businesses is real, growing, and mostly automated rather than personal. SMEs are targeted because they are reachable and often under-defended, not because they have done anything wrong. The data from CERT NZ is consistent year after year, and the Privacy Act 2020 means a breach is now a legal matter as well as a technical one.

The good news is that the same fundamentals address most of the risk, and you do not need an enterprise budget to put them in place. What you need is a clear view of where you stand and a plan to close the obvious gaps first.

If you want help reading your own risk against this landscape, iT360 works with SMEs across New Zealand and can give you a straight assessment of where to start.

Make the plan real

Get a technology partner who can help execute.

See our cyber security services

Book a free consultation