New Zealand businesses with annual turnover between $10 million and $100 million are the most concentrated target for ransomware attacks – and most are uninsured against a risk that can cost more than $2 million to recover from.
Those findings were presented by Anthony Cooke of Atmos, New Zealand’s largest dedicated cybersecurity and digital risk law firm, at Brightstar’s National Cyber Security Summit in Wellington in March 2026. Drawing on more than 3,000 incident responses handled across Australia and New Zealand over 12 years, Cooke outlined patterns in threat actor behaviour and the legal risks that compound financial losses when organisations respond poorly. The data was reported by Security Brief New Zealand on July 27, 2026.
Cooke’s data showed 42% of ransomware incidents target mid-market businesses. Threat actors avoid large multinationals to stay below the threshold of scrutiny from international intelligence agencies, while mid-market firms hold enough capital to meet six-figure demands without generating that attention. By sector, financial and insurance services recorded the highest incident share in 2025 at 18.8%, followed by professional services and consulting at 17.5% – together accounting for more than a third of all incidents.
That pattern aligns with New Zealand’s government data. The National Cyber Security Centre’s (NCSC) Cyber Threat Report 2025, covering July 2024 to June 2025, recorded 5,995 incident reports, with 331 identified as being of potential national significance. More recently, the NCSC’s Q1 2026 Cyber Security Insights report recorded $5.6 million in direct financial losses across 1,164 incidents in a single quarter – a 76% increase on the previous quarter. The New Zealand government’s Cyber Security Strategy 2026-2030, released in February 2026, estimated New Zealanders are losing more than $1.6 billion annually to cybercrime.
The median attacker dwell time has fallen to eight days before ransomware is deployed, down from approximately two weeks historically, though some intrusions extended to 163 days. Opening ransom demands had a median of $1.2 million, peaking at $3.5 million. After negotiation, median final settlements came in at $430,000, reaching as high as $1.54 million. In 80% of cases where ransoms were paid, threat actors delivered working decryption keys and did not release data. In the remaining 20%, no deliverables were provided. Some groups, including one identified as SpaceBears, re-extorted victims who had already paid.
Recovery costs – covering legal fees, public relations, and technical containment, but excluding any ransom – averaged $235,000 and reached $2.1 million at the high end. Business email compromise averaged $26,000, though high-end cases exceeded $1.4 million. For New Zealand-specific context, Kordia’s 2025 New Zealand Business Cyber Security Report found that 59% of surveyed organisations experienced a cyberattack or incident in the previous 12 months. Among the reported impacts, 22% experienced operational or business disruption, 16% had personally identifiable information accessed or stolen, 15% made a cyber insurance claim, 14% faced financial extortion, and 9% paid a ransom to recover data or systems. The divergence from the Atmos figures likely reflects the dataset’s focus on larger mid-market entities with greater ransom capacity.
For insurance professionals, the exposure picture is sharpened by what happens to firms that are not covered. One insurer has reported that 70% of uninsured SMEs across New Zealand and Australia that received a ransom demand would not survive into the following year, with business interruption costs a primary driver, according to Adelphi Insurance. Some cyber insurance brokers have reported penetration of approximately 10% across their New Zealand SME clients, and approximately 40% across large corporate clients. Fabian Willi, head cyber key accounts at Swiss Re, told Re-Insurance Business that large companies with turnover above $10 billion are already at approximately 80% penetration, placing the significant remaining protection gap squarely in the mid-market and SME segment.
Duncan Morrison, cyber practice leader at Aon New Zealand, has observed what drives that gap. “Our regulators are nowhere near as punitive as the likes of Australia,” Morrison said, noting that New Zealand’s relatively limited enforcement environment creates less pressure for businesses to scrutinise their actual coverage position. There are signs this is shifting. Jono Soo, head of cyber in New Zealand for Marsh, told Insurance Business New Zealand in November 2025 that New Zealand’s SME market for cyber insurance is in transition, with brokers fielding more sophisticated questions and seeing higher policy counts. But conversion remains uneven, particularly below the mid-market.
The commercial case for cyber cover is being reinforced at a policy level. New Zealand’s Privacy Act 2020 introduced mandatory breach notification requirements, obliging organisations to notify both the Privacy Commissioner and affected individuals when a breach is likely to cause serious harm. Failure to notify is an offence carrying fines of up to $10,000. The government published its Cyber Security Strategy 2026-2030 in February 2026, and an accompanying critical infrastructure discussion paper proposed mandatory cyber security requirements for approximately 200 of New Zealand’s most significant entities across seven essential services, including energy, finance, health, transport, and communications. For underwriters and brokers advising clients in those sectors, proposed mandatory requirements add a new dimension to both risk assessment and client advisory conversations.
Cooke addressed a further dimension of loss that intersects directly with policy response and claims handling: the risk of compromising legal privilege through public communications. In the Australian Optus class-action litigation, a court found that public statements about investigating an incident to understand what happened and prevent a recurrence indicated the investigation served a broader business purpose – and ordered forensic reports disclosed to plaintiff lawyers. His recommendation was to engage legal counsel immediately upon detecting an intrusion, so that technical investigations are structured under formal legal privilege from the outset.
Cooke also advised against issuing public apologies before technical facts are established – these may be interpreted as admissions of liability – and recommended using precise language such as “security incident” rather than “cyberattack” in any external communications. Geordie Stewart, CISO at NSP, addressing an Insurance Brokers Association of New Zealand (IBANZ) webinar on cyber insurance in 2026, identified the underwriting implication of weak controls more broadly: “Having a control isn’t the same as having an effective control. That’s the most common reason cyber claims fail.”
Cooke is scheduled to speak at the Cyber Security Risk Conference on August 4, 2026, at the New Zealand International Convention Centre in Auckland, where the session will focus on response and recovery in major incidents, including the recent Canvas data breach affecting New Zealand educational institutions.