The National Cyber Security Centre (NCSC) released its Cyber Threat Report 2026 on September 24. For brokers, the headline figure is not artificial intelligence.
Of the 369 incidents of potential national significance handled by the NCSC during the 2025/26 financial year, 162 were linked to criminal or financially motivated actors – an 18% rise on the prior year. Four were classified C2, highly significant – the first incidents of that severity in five years.
“The severity of incidents has increased. During 2025/26 the NCSC recorded four incidents classified as C2, or Highly Significant. That’s as many in one year as were recorded over the previous ten years,” said Catriona Robinson, head of the NCSC.
That loss environment sits against a market moving the other way. Aon classified New Zealand’s cyber market as soft in Q1 2026, with abundant capacity and broader coverage available. Marsh has similarly noted that cyber premiums have levelled off, while cautioning that carriers expect effective cybersecurity controls and that organisations without basic protections may find it more difficult to secure cover.
Clients renewing into cheaper terms this year are doing so while their underlying exposure is getting worse.
The report details two incidents that translate directly into broker conversations at renewal.
In late December 2025, a cybercriminal used credentials stolen via Lumma Stealer malware to access the Manage My Health (MMH) patient portal, exfiltrating health and personal information belonging to more than 99,000 New Zealand patients. The Ministry of Health found the breach was largely preventable. Multi-factor authentication (MFA) was available on the platform but was not mandatory for all users.
The Privacy Commissioner subsequently issued compliance notices to both Manage My Health and Health NZ for failing to meet the security requirements of rule 5 of the Health Information Privacy Code at the time of the attack.
In May 2026, a supply chain attack on Canvas – a US-owned, cloud-hosted learning management system – hit more than 30 New Zealand tertiary institutions and schools. The Ministry of Education estimates between 110,000 and 120,000 students and staff had personal data stolen. Institutions lost access to essential services for several days while the US-based operator restored its systems.
Neither breach used technically complex methods. Both exploited control gaps that sit squarely in a broker’s renewal conversation.
Read next: NZ cyber rules put director liability on the broker agenda
The Manage My Health breach illustrates a shift already underway in the New Zealand market.
New Zealand cyber insurers have tightened application requirements, with MFA now functioning as a baseline eligibility criterion rather than an optional risk mitigant, according to NSP cyber CISO Geordie Stewart, who presented on the topic to Insurance Brokers Association of New Zealand (IBANZ) members in April 2026.
“If you don’t have multi-factor authentication in place, you’re probably going to find it very difficult to get cover. And if you do get cover offered, it’s probably going to be a significant premium,” Stewart said.
Partial rollouts no longer satisfy underwriters. Insurers expect MFA across email, remote access, VPN, and all administrator accounts – and they verify this at claims time, not just at application.
Stewart Hunt, an insurance adviser at First Commercial Insurance Brokers, noted in a guide published in May 2026 that “cyber insurance is one of the few covers where what’s not in the policy matters as much as what is.”
The regulatory exposure runs alongside the coverage question. Under the Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner (OPC) of any breach likely to cause serious harm. The Privacy Amendment Act 2025, which received royal assent in September 2025 and introduced expanded notification requirements effective May 2026, has extended those obligations further.
A client without MFA is not just harder to place. After a breach, they may also face regulatory enforcement.
The NCSC report cites Hiscox survey data indicating approximately 40% of victims who paid a ransom failed to recover their data, and approximately 80% of organisations that paid were attacked again – often by the same group.
The Hiscox Cyber Readiness Report 2025, which surveyed 5,750 businesses, found that of those who paid a ransom, only 60% successfully recovered all or part of their data. Nearly a third of those who paid then faced a follow-on demand for more money.
For brokers advising clients on extortion coverage terms, that data argues against treating payment as a reliable recovery strategy – and it is a conversation worth having before an incident occurs.
The NCSC report attributes 23% of nationally significant incidents to suspected state-sponsored actors, with China assessed as the most persistent and capable. Russia, Iran, and North Korea are also identified.
That figure has a direct policy implication many New Zealand clients are unaware of.
Following Lloyd’s Market Bulletin Y5381, standalone cyber policies under Lloyd’s risk codes CY and CZ have been required since March 2023 to exclude losses arising from state-backed cyberattacks – specifically, attacks that significantly impair a state’s ability to function or undermine its security capabilities.
The practical difficulty is attribution. The NCSC report itself flags known links between state actors and criminal networks, with tools, credentials, and techniques exchanged between them. The line between state-directed and state-affiliated activity is rarely clear at the time of a claim.
For clients in sectors the NCSC identifies as targets – health, education, infrastructure, and professional services – brokers should be checking whether policy wording is explicit on how state attribution is handled and where the exclusion threshold sits.
The report’s leading judgement is that frontier AI will accelerate the threat environment. The NCSC assesses that by early 2027, malicious actors may have access to AI capabilities currently limited to leading frontier models – enabling faster vulnerability identification, automated reconnaissance, and more convincing phishing at scale.
“AI offers many opportunities, but it is already being used by malicious actors to increase the speed, scale, and sophistication of cyberattacks. The next generation of frontier AI models could automate attacks, identify vulnerabilities, and enable highly personalised targeting of organisations and individuals,” Robinson said.
In June 2026, the Five Eyes agencies – Australia, Canada, New Zealand, the UK, and the US – issued a joint Call to Action urging business leaders to prioritise foundational cyber security practices ahead of that shift.
For brokers, AI is a medium-term accumulation and pricing question. The near-term story is already in the claims data.
Read next: What the Gemini and Claude hacking incidents mean for cyber insurers
The NCSC report does not address insurance directly. But its findings point to three questions brokers should raise with every commercial cyber client before binding cover.
Do your access controls meet current insurer eligibility requirements? Does your policy respond to losses triggered by a third-party vendor breach? And does your policy wording make clear how state attribution is treated?
“Government cannot protect every organisation from every cyber threat. Leaders are responsible for cyber security within their organisations, and those who prepare now will be best placed to manage the challenges of frontier AI,” Robinson said.
In a soft market, clients have less financial pressure to engage with those questions. The loss data in this report is the argument for raising them anyway.