Half of New Zealand agencies still have an email security gap

A government domain sitting at Monitor level rather than Reject can still be spoofed - and any private sector client that transacts with that agency is exposed to impersonation incidents arriving from a domain they already trust

Half of New Zealand agencies still have an email security gap

Cyber

By Roxanne Libatique

Half of New Zealand government agencies are carrying a documented cyber control gap with less than two months until a compliance deadline. For insurance brokers, that is not a technology story. It is a client conversation that needs to happen now.

Research published by cybersecurity firm Proofpoint in September 2026 found that 50% of more than 200 primary state entities had not implemented email authentication at the level required under the government’s Secure Government Email (SGE) framework. The October 2026 deadline is the second the government has set – the first, in October 2025, was extended to give agencies more time. That time has been used unevenly.

What the data shows

Proofpoint examined organisations listed on the New Zealand Government Organisations Register in August 2026, covering agencies across defence, education, social services, foreign affairs and trade, energy, and treasury and finance.

The SGE framework requires DMARC – Domain-based Message Authentication, Reporting and Conformance – at the Reject level. That is the only setting that blocks unauthorised emails from reaching recipients when they impersonate a government domain. Lower settings leave spoofed messages in play.

Of the 200-plus organisations examined:

  • 50% had reached the required Reject level
  • 35% were on Monitor, which logs email activity without blocking anything
  • 12% were on Quarantine, which filters some suspect mail to spam but does not block it
  • 3% had no DMARC record at all

Overall DMARC adoption across the group sat at 97%. The gap is not one of awareness – it is one of enforcement. The Reject rate doubled from 26% in 2025, when Proofpoint conducted its first analysis, but half the public sector remains short of the mandated standard.

According to New Zealand’s Digital Government website, the Government Digital Services Delivery (GDSD) team monitors compliance with the framework and communicates directly with agencies where changes or potential issues are identified.

Why brokers should be paying attention

Business email compromise (BEC) remains a significant cyber risk for New Zealand organisations, while email authentication controls such as DMARC can help prevent attackers from spoofing trusted domains.

The National Cyber Security Centre (NCSC) reported $8.3 million in direct financial losses in the first half of 2026, with phishing and credential harvesting among the most commonly reported incident categories. A government domain not protected at the Reject level is more susceptible to being spoofed in campaigns targeting the agency’s staff, suppliers, and the public.

That supply chain dimension is where private sector clients enter the frame. BEC attacks exploit trusted third-party relationships – impersonating known suppliers or government counterparts to redirect payments or extract credentials. Verizon’s 2025 Data Breach Investigations Report highlights the financial impact of BEC, citing more than US$6.3 billion transferred through BEC scams in 2024, based on FBI data. A business that regularly transacts with a government agency is exposed to spoofed emails arriving from a domain its staff already recognises and trusts.

When those attacks succeed, the loss lands on the client. Whether it is covered depends on policy wording. BEC and funds transfer fraud are frequently subject to sublimits, exclusions, or social engineering extensions that are not always clearly explained at placement.

The underwriting dimension

The compliance gap also has implications for cyber insurance. Gallagher’s 2026 New Zealand market update says the cyber insurance industry is continuing to evolve in response to complex and emerging risks, regulatory changes, and technological developments. Other market commentary indicates that New Zealand cyber underwriters are placing greater scrutiny on the effectiveness of clients’ security controls. The level of email authentication can therefore be relevant when assessing a client’s exposure to email spoofing and other cyber risks, although its impact on pricing and coverage will depend on the insurer and policy.

In the New Zealand market, that dynamic is already visible. Geordie Stewart, CISO at NZ cybersecurity firm NSP, has noted that BEC – where attackers log into or impersonate corporate email accounts – is by far the most common cyber claim locally. Underwriters responding to that claims pattern are scrutinising email controls more closely at renewal.

A client that states it has “email security in place” while operating at Monitor level may be technically accurate. Whether that answer holds up under underwriter scrutiny – or after a BEC claim – is a different matter.

Why the gap is hard to close quickly

The compliance shortfall is not simply explained by inaction. Moving to Reject requires mapping every third-party system authorised to send email on a domain’s behalf – marketing platforms, notification services, outsourced providers – and confirming each is correctly configured before enforcement is activated. Done incorrectly, legitimate emails get blocked.

For public sector bodies, that challenge compounds. Legacy infrastructure, distributed procurement, and the volume of contractors involved in citizen-facing communications all slow the process. Technical adoption can run well ahead of full enforcement in large organisations – which is exactly what the data shows.

Proofpoint – which sells email security products and conducted this research – flagged the practical risk of the remaining gap. Steve Moros, the company's senior director, advanced technology group, Asia Pacific and Japan, described DMARC as "a critical layer of protection against email impersonation and phishing, one of the most prevalent threats facing New Zealand organisations in this AI era."

The conversation to have before October

For brokers with public sector clients: at which DMARC policy level is the organisation operating, and has that been disclosed to the underwriter? Does the existing policy wording respond to BEC and social engineering losses, or are sublimits applying to the scenarios that email spoofing most commonly produces?

For brokers with private sector clients that transact with government agencies: is the risk of spoofed government email reflected in the current coverage structure? Are staff trained to verify payment instructions or credential requests that appear to come from official domains?

DMARC enforcement is not a complete control on its own – user awareness training and account security remain necessary layers. The compliance data shows a significant portion of New Zealand’s public sector cannot yet answer the email security question cleanly. That gap does not stay inside government. It extends to every supplier, contractor, and citizen on the other end of those domains.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!