The time a business has to patch a known software vulnerability before attackers exploit it has, by one measure, gone entirely. That shift reframes how brokers should be talking to SME clients about cyber cover – and what those clients can realistically be expected to do.
Data from the Zero Day Clock, a global project tracking confirmed software exploits, shows the median time between public disclosure of a vulnerability and its real-world exploitation fell from 771 days in 2018 to zero days in 2026. Attackers are now typically weaponizing flaws at the moment they become publicly known.
The finding is part of research published by cybersecurity company ESET in September 2026, which also examined how artificial intelligence is shortening attack timelines.
ESET tested how quickly an advanced AI model could turn a newly released browser security patch into a working exploit. The result was under an hour – a task that previously required specialist skills and significantly more time.
Scott Leman (pictured), ESET’s New Zealand country manager, was direct about what that means. “For years businesses could reasonably assume that when a new security weakness was discovered there would be some time to understand it, fix it, and protect themselves. That breathing space is disappearing,” he said.
New Zealand’s National Cyber Security Centre (NCSC) made a consistent assessment in its Cyber Threat Report 2026, warning that frontier AI tools are enabling faster identification of zero-day vulnerabilities, accelerating system reconnaissance, and enhancing the creation of phishing attacks. The NCSC also recorded an 18% rise in criminal or financially motivated incidents classified as potentially of national significance last year.
Read next: Biological weapons researchers were using AI. Insurers should know
Separate from the exploitation window issue, ESET’s research found a different AI-related risk: ChatGPT search results directing users to websites already classified as unsafe.
Over a 30-day monitoring period, ESET found those results included links to fake online stores, cryptocurrency scams, and imitation login pages. Some responses also contained malicious code capable of stealing information or compromising devices.
Four out of five New Zealanders have used AI in the past 12 months, according to InternetNZ's Aotearoa Internet Insights 2025 report. ChatGPT was also New Zealand’s most downloaded free iPhone app in 2025.
Leman said the trust users place in AI-generated results is itself the problem. “Because that recommendation has come from a tool they trust, they may be less likely to question whether the destination itself is genuine or safe,” he said.
ESET’s New Zealand threat telemetry for July 2026 found phishing-related threats made up just under 35% of all cyber threats detected across its local user base. The NCSC’s Q2 2026 Cyber Security Insights report found phishing and credential harvesting was the second most reported incident category between April and June 2026, behind scams and fraud
Leman described the attack chain that follows a successful credential theft – one that cyber insurers will recognise from claims experience.
An attacker gains access to a business email account, monitors ongoing conversations, identifies a pending invoice, then sends a message from the genuine address advising that bank details have changed.
“The customer has little reason to suspect anything is wrong because the message has come from the same email address and may even form part of an existing conversation. By the time either side realises what has happened, the money may already be gone,” Leman said.
No malware is involved. Antivirus software cannot flag it. “There may be no virus file for antivirus software to find because the criminal is effectively walking through the front door using the user’s own key,” he said.
The NCSC’s Q2 2026 data puts figures to what follows. Unauthorised access – often the stage after credential theft – accounted for approximately $1.3 million of the $2.7 million in reported financial losses for the quarter. Just 49 incidents with losses above $10,000 represented 91% of all reported losses, pointing to a pattern of concentrated, high-value harm rather than high-volume, low-value incidents.
Read next: What the Gemini and Claude hacking incidents mean for cyber insurers
The threat data sits against a protection gap that remains wide. Kordia’s New Zealand Business Cyber Security Report 2025, which surveyed 295 businesses, found 59% had experienced a cyberattack or incident in the prior 12 months. Email phishing accounted for 43% of those attacks, and almost one in 10 businesses that experienced an incident paid a ransom or extortion demand.
Swiss Re estimated in 2025 that cyber insurance penetration among SMEs sits between 10% and 20% – figures drawn from North American and European data, though broadly indicative of comparable markets.
The regulatory exposure for uninsured or underinsured businesses is real. Under the Privacy Act 2020, New Zealand organisations must notify the Privacy Commissioner when a breach has caused, or is likely to cause, serious harm. Failure to notify without reasonable excuse is a criminal offence under section 118 of the Act, carrying a fine of up to $10,000. Separately, the Human Rights Review Tribunal can award damages of up to $350,000 for the most serious privacy breaches, according to the Office of the Privacy Commissioner (OPC).
A phishing attack that results in unauthorised access to customer data can trigger those obligations – with or without a cyber policy in place.
Leman summed up the scale of the shift for SMEs. “When attackers were moving at human speed, delays were already a problem. As AI increasingly allows attacks to operate at machine speed, businesses and consumers can no longer assume they will have time on their side,” he said.