New Zealand's cyber insurance market is currently soft, with abundant capacity and pricing that has been falling for several quarters. At the same time, the National Cyber Security Centre has published guidance that sets out, in more specific terms than before, what "reasonable security safeguards" under the Privacy Act 2020 actually require when a client outsources data handling to a supplier.
Brokers advising on renewals right now are effectively pricing cover against a standard of care that just moved. Clients who have not reviewed their supplier contracts since that standard shifted may be carrying more uninsured exposure than their premium suggests.
Aon classified New Zealand's cyber market as soft in the first quarter of 2026, with abundant capacity and broader coverage on offer to buyers. That softening sits awkwardly against the NCSC's own numbers from the same quarter. The agency recorded $5.6 million in direct financial losses in Q1 2026 - a 76% increase on the previous quarter - and responded to three incidents severe enough to be classified at its second-highest rating, the first time that threshold had been reached since the 2021-22 financial year. A client renewing into cheaper terms this year is doing so against a loss environment that is moving in the opposite direction.
The clearest illustration of what the new standard looks like in practice is a December 2025 breach at a medical record platform, which exposed the personal information of over 99,000 New Zealanders - among the country's largest known compromises of sensitive personal data.
The Office of the Privacy Commissioner's review found that threat actors used valid stolen patient credentials to reach large volumes of health information through a patient portal, and concluded that reasonable security safeguards could likely have prevented the compromise. The Commissioner's Phase 1 findings, published in late May, went beyond a general finding of poor oversight. They identified gaps in access control, no requirement for multi-factor authentication across all users, and detection systems too weak to flag unusual activity while data was still being taken.
Around 91% of those affected were based in Northland, and the Commissioner has said he intends to issue compliance notices to both organisations involved. Those specific failures give brokers a working checklist of what a regulator will now look for after an incident - which is more useful than the general "reasonable security safeguards" language it replaces.
Policy wording is the point where the regulatory shift stops being theoretical. In the final quarter of 2025, 23% of the incidents the NCSC classified as nationally significant were assessed as likely linked to state-sponsored actors, and some New Zealand cyber policies exclude attacks attributed to state actors outright. Whether a loss falls inside or outside cover can turn as much on the specific wording a client is carrying as on the facts of the incident - which makes the exclusion itself a conversation worth having before a claim, not during one.
Notification timing carries similar weight. A separate health data provider, Canopy Healthcare, took roughly six months earlier this year to tell patients that unauthorised access had occurred, despite notifying police and the Privacy Commissioner and securing a High Court injunction over the data at the time. A gap of that length is precisely what insurers scrutinise when testing whether a policy's prompt-notification conditions have been met, and it is the kind of timeline a broker would want flagged well before renewal, not discovered at claim stage.
The NCSC's guidance is directed at organisations that hold contracts with third-party suppliers, and it recommends setting data protection and cyber security expectations at the procurement stage, then reviewing them for the life of the contract. On governance, it states plainly that organisations should not assume suppliers are following good practice by default, and that oversight remains the contracting organisation's responsibility even when the data itself sits with someone else.
Beyond governance, the guidance covers contract clauses, incident reporting obligations, network protection, data protection measures, and independent security testing of suppliers. The basic controls it sets out are specific: firewall protection, data encryption, multi-factor authentication across all systems and accounts, access limited on a least-privilege basis, and data loss prevention tools for data at rest. Each of these maps directly onto the questions an underwriter is increasingly likely to ask at renewal - and each is now also the minimum standard a Privacy Commissioner will apply when assessing whether "reasonable security safeguards" were in place. Brokers should confirm clients meet all five before the next renewal conversation, not after an incident raises the question.
New Zealand's light regulatory touch has historically been part of the pricing story. Duncan Morrison, cyber practice leader at Aon New Zealand, said earlier this year that "our regulators are nowhere near as punitive as the likes of Australia" - a comment made in the context of the country's broader cyber resilience gap.
The NCSC's new guidance is a step in that direction, though it addresses supplier oversight specifically rather than the wider resilience gap Morrison was describing. It also points organisations toward the NZISM, the Protective Security Requirements' GOV 5 requirement on managing risk with others, and international standards including NIST SP 800-53, NIST SP 800-161 and ISO/IEC 27001. A refresh of GOV 5 is under way, with the PSR developing a Common Criteria for Assessing Risk to help organisations rank supplier risk.
None of this moves pricing on its own. But a soft market combined with a regulator that has just set out a more specific standard of care leaves a window where clients can buy cover cheaply without necessarily meeting the standard that determines whether a future claim gets paid. That gap is the one worth raising at the next renewal conversation - and the NCSC's five basic controls give brokers the specific language to raise it.