Half of New Zealand government organisations remain short of the country's strongest email-authentication standard, creating a fraud exposure that can reach businesses outside government and test whether their insurance covers a payment they authorised themselves.
Proofpoint examined 200 organisations listed on the New Zealand Government Organisations Register in August. It found 50% had implemented Domain-based Message Authentication, Reporting and Conformance (DMARC) at the required “reject” level. Another 35% remained at “monitor,” 12% used “quarantine” and 3% had no DMARC record.
The findings show a gap in enforcement rather than basic adoption: 97% had some form of DMARC, but only half were configured to reject messages that failed authentication checks. That was an improvement from 26% at the highest setting last year.
"50% are at [a high level of email security] at the moment," said Steve Moros, Proofpoint's senior director for Asia Pacific and Japan.
The government's Secure Government Email framework combines DMARC with controls covering encryption, sender verification and message integrity. Government organisations are expected to adopt the framework by October 2026, after the original October 2025 deadline was extended.
At the reject level, messages impersonating a domain should be blocked when they fail authentication. Lower settings may only record the activity or divert suspect messages, leaving recipients to assess an email that appears to come from an organisation they already trust.
The loss may then fall outside the organisation being impersonated. A supplier could act on false payment instructions or disclose credentials in response to an apparently genuine government email. Whether its insurance responds can depend on the distinction between a system intrusion and social engineering that persuades an employee to authorise a transfer.
Business email compromise and funds-transfer fraud may be excluded from standard cyber cover, subject to lower sublimits or require a specific extension. That makes both the client's security controls and the precise treatment of authorised payments relevant at placement and renewal.
The domestic loss data gives the issue greater weight. New Zealand's National Cyber Security Centre recorded NZ$5.6 million in direct losses during the first quarter of 2026 and NZ$2.7 million in the second. Phishing and credential harvesting was the most frequently reported category in the first quarter and the second most common in the next.
The potential size of an individual payment loss was illustrated by Whanganui District Council, which sent NZ$309,654 to a fraudulent bank account in December 2022 and identified the misdirected payment the following month. The incident has not been attributed to a DMARC failure, but shows why the route by which a fraudulent payment is induced can matter to coverage.
"That's why we need to make sure we get real progress getting all government agencies to the right level of enforcement, we've got to close the gap,” Moros said.
The warning arrives during favourable buying conditions. Aon's first-quarter market overview classified New Zealand's overall insurance market as soft, with abundant capacity, flexible underwriting and broader coverage. Pricing was down between 1% and 10%, while cyber was among the product lines separately described as soft.
Those conditions provide room to examine social-engineering extensions, sublimits and verification requirements before a loss. They do not remove underwriting scrutiny: Aon's cyber analysis said capacity could still be restricted where minimum security standards were not met.
Proofpoint acknowledged that moving to full enforcement could be complicated. Legitimate third-party services sending email on an organisation's behalf must be identified and configured correctly before reject policies are activated, or genuine messages may also be blocked.
Moros said there was "no real excuse" for agencies without stronger protection.
"This is all around protecting people to stop them from being lured into losing their hard earned money. Or potentially exposing records to these hackers who will then use it to go make money through exploitation, essentially ransom so 'if you don't pay we will publish the information',” Moros said.
The government maintains that the remaining gap will be closed on schedule. Richard Ashworth, general manager at the Government Digital Delivery Agency, said the framework provided technical settings intended to meet industry standards, including encryption in transit, digital signing and protection against domain spoofing.
The agency expects all organisations to adopt the framework by October.