NZ cyber rules put director liability on the broker agenda

Competitive cyber pricing meets expanding governance exposures, leaving brokers to test whether existing programmes remain fit for purpose

NZ cyber rules put director liability on the broker agenda

Cyber

By Roxanne Libatique

New Zealanders are losing an estimated $1.6 billion to cybercrime each year. A government discussion document, published by the Department of the Prime Minister and Cabinet (DPMC) in February, proposes making that a personal financial problem for company directors – and the sectors targeted give brokers a defined client list to work from now.

The document proposes criminal penalties of up to $5 million or 2% of annual turnover – whichever is greater – for entities that negligently, recklessly, or knowingly fail to meet minimum cybersecurity requirements. Directors face separate personal criminal liability of up to $500,000 for the same category of breach. Consultation closed in April. Regulatory action is expected to follow.

For brokers, this does not sit inside one product. A director liability claim arising from a cyber incident can fall between a standalone cyber policy and a management liability or directors and officers (D&O) wording – particularly where management liability contains cyber exclusions, which many do.

What the DPMC document proposes

The discussion document targets approximately 200 of New Zealand’s most significant entities across seven sectors: communications and data, defence, energy, finance, health, transport, and drinking water and wastewater.

Entities in scope would need to develop and maintain a risk management programme aligned with recognised frameworks such as NIST CSF or ISO 27001 and report significant incidents within 72 hours. A one-year grace period between requirements taking effect and enforcement being considered is proposed.

The document is explicit on director accountability: it frames cybersecurity as a core element of fiduciary duty and proposes that directors of critical infrastructure entities be personally responsible for compliance with minimum requirements.

Miro Dordevich, head of QBE Insurance’s cyber portfolio in New Zealand, said the penalty figures need context. “There needs to be some type of consequence but look for the words ‘gross negligence.’ It isn’t like this will occur because something just happened to go wrong,” he told IT Brief New Zealand. He drew a comparison to Europe’s regulatory model. “It is a big number, but look at GDPR fines, at up to 4% of turnover as opposed to a punitive number,” Dordevich said.

Why this is a broker issue, not just a compliance one

Duncan Morrison, cyber practice leader at Aon New Zealand, has observed what keeps the advice gap open in this market. Writing on the Aon New Zealand blog in March 2026, he noted that boards too often receive technical updates on firewalls and patching without visibility of the actual financial exposure a major cyber event would create. “Without that financial lens, cyber risk can be underestimated or deprioritised,” Morrison said. He has also noted that New Zealand’s relatively limited enforcement environment has historically reduced pressure on businesses to examine whether their coverage addresses the risks they carry – a dynamic the incoming framework is set to change.

The DPMC document frames cybersecurity governance as a fiduciary obligation for directors – placing it alongside other board-level duties that D&O and management liability products are designed to address. That is the entry point for a conversation that spans more than one product line.

The sectors, the penalties, and the pipeline

The seven-sector scope is a starting point. Dordevich said the critical infrastructure framework signals a direction rather than a final position. “That critical infrastructure bill is important because it shows the direction in which we are heading, so whatever shape it takes, it is likely to be the start of a broader conversation,” he said.

Only 6% of small New Zealand businesses currently hold cyber insurance, according to specialist adviser CyberCover NZ – one of the lowest rates in the developed world. The framework will not close that gap on its own, but it establishes the regulatory logic that is likely to extend downstream over time.

The risk environment is moving in one direction

New Zealand’s standing makes the regulatory push easier to understand. The 2025 National Cyber Security Index ranks the country 49th globally – the lowest of all Five Eyes partners – confirmed in the DPMC discussion document itself.

The National Cyber Security Centre (NCSC) recorded $5.6 million in direct financial losses in Q1 2026, a 76% increase from the previous quarter. Three incidents were classified at the NCSC’s second-highest severity rating – the first time that threshold had been reached since the 2021-22 financial year.

Policy structure matters when an incident hits

Cyber policies vary in how they respond under pressure. Two questions brokers should check against existing client wordings: does the policy respond regardless of whether a ransom is paid or not, and does it provide access to incident response expertise rather than only indemnifying loss after the fact?

Dordevich described a local ransomware case in which a client faced escalating demands and exfiltrated personal data, and chose not to pay. “The approach as the insurer is multidisciplinary: let’s secure the environment and take it from there. They said we’ve got our processes and governance, but we need immediate help from QBE and your incident response partners,” he said.

Those two structural elements – response regardless of ransom outcome and access to incident response capability – are worth confirming in any client policy before the legislative framework takes effect, not after an incident raises the question.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!