Foreign states are actively targeting New Zealand businesses. Insider incidents are rising. And the policy wording designed to manage catastrophic state-backed cyber risk is creating coverage gaps that most clients do not know about. The New Zealand Security Intelligence Service (NZSIS) published its fourth annual Security Threat Environment Report on August 13, 2026, confirming sustained foreign state targeting of New Zealand’s private sector, a rise in insider threat incidents, and AI as an accelerant across both. The findings land at a moment when the structure of cyber policy wordings – specifically around nation-state attribution – has become materially more consequential for New Zealand policyholders.
Following Lloyd’s Market Bulletin Y5381, standalone cyberattack policies under Lloyd’s risk codes CY and CZ were required, from March 31, 2023, at inception or renewal, to include specified treatment of state-backed cyberattacks, unless otherwise agreed with Lloyd’s. In January 2023, the Lloyd’s Market Association published revised cyber war and cyber operation model clauses, including LMA5567A and LMA5567B. The A versions were designed to meet Y5381’s requirements, including provisions addressing how a cyber operation is attributed to a state. The B versions do not contain an attribution mechanism within the clause itself and therefore require prior agreement with Lloyd’s or another agreed mechanism for addressing attribution.
LMA5567A takes a threshold-based approach to certain state-linked cyber operations. The exclusion applies where a cyber operation causes a state to become an “impacted state” – defined as a state where the operation has had a “major detrimental impact” on the functioning of essential services or on its security or defence. The clause also contains an attribution mechanism for determining whether a cyber operation is attributable to a state. This means the involvement of a state actor does not, by itself, determine whether the exclusion applies; the outcome depends on the specific policy wording, attribution and the circumstances of the cyber operation.
This matters in New Zealand because state-sponsored activity is not rare. In Q4 2025, 23% of nationally significant incidents handled by the National Cyber Security Centre (NCSC) were assessed as likely linked to state-sponsored actors. Some NZ policies exclude attacks attributable to state-sponsored actors outright – and given the NCSC’s finding that a significant proportion of incidents involve state-affiliated actors, this exclusion can be material. The broker conversation this creates is specific: which LMA variant is on the client’s policy, does it apply a major-detrimental-impact threshold or a broader attribution trigger, and has the client been told?
The 2026 report is unusually specific about targeting mechanics. It notes that some states attempt to acquire sensitive technology through international front companies and supply chain intermediaries, and that a common tactic involves recruiting people with government connections or insider knowledge and pressuring them to provide insights. The NZSIS also confirms a steady increase in espionage-motivated cyber activity against New Zealand over the last three years.
NZSIS Director-General Andrew Hampton framed the commercial stakes plainly: “We are highly interconnected with the rest of the world, we produce leading innovations, hold important security partnerships, and are located in the strategically important Pacific region, close to Antarctica. This makes New Zealand not only geopolitically relevant, but attractive to threat actors who are unsentimental in their pursuit of our information and their influence over us.”
The report also flags New Zealand’s space sector as a specific foreign state target, noting attempts to establish Ground Based Space Infrastructure (GBSI). New Zealand conducted the third-highest number of orbital launches globally in 2024, with 13 launches, according to a government discussion document. The government’s Space and Advanced Aviation Strategy 2024-2030 aims to double the size of the space and advanced aviation sectors by 2030. As the sector expands, the NZSIS assessment adds a further risk consideration for brokers working with space and technology businesses, particularly those handling sensitive information or critical infrastructure.
The NZSIS report identifies a rise in insider incidents across public and private sector organisations. It notes that significant damage can be caused to national interests if even a small number of trusted insiders are compromised – whether through deliberate action, outsider influence, or unwitting behaviour. Standard crime and fidelity policies respond to direct financial loss from employee dishonesty. IP theft by a coerced or compromised insider – the specific scenario the NZSIS is describing – may produce no immediate quantifiable financial loss and may not meet the policy trigger. The ACFE’s Occupational Fraud 2026: A Report to the Nations, drawn from 2,402 real-world cases across 143 countries, found that the median fraud loss per case was $104,000, with the average exceeding $1.4 million – and that the typical scheme continues for approximately 12 months before detection. For clients holding valuable intellectual property or operating in sensitive sectors, the lag between compromise and discovery compounds the exposure significantly.WTW’s Fidelity/Crime Marketplace Realities 2026 report notes that social engineering fraud is intensifying, with AI enabling automated deepfakes – and that underwriters are increasingly scrutinising how organisations use AI and what risks that creates. The NZSIS report reinforces that picture: AI is identified as an accelerant for both extremist content and state-sponsored targeting.
The NCSC recorded $5.6 million in direct financial losses in Q1 2026 – a 76% increase from the previous quarter – and responded to three C2 “highly significant” incidents, the first at that severity level since the 2021/22 financial year. The government’s Cyber Security Strategy 2026-2030 estimated New Zealanders are losing approximately $1.6 billion annually to cybercrime, primarily through cyber-enabled fraud.
Market conditions remain soft. Aon classified New Zealand’s cyber market as soft in Q1 2026, with abundant capacity and broader coverage available. The combination of competitive pricing and worsening loss data is a known broker risk: clients may be buying broader-seeming cover at lower premiums without understanding that the nation-state carve-outs now embedded in standard wordings could be determinative in the exact scenarios the NZSIS is describing.
Hampton was direct: “National security is not something exclusively owned by the security and intelligence agencies – it must be a collective effort.” For brokers, that translates to three questions worth raising at the next client renewal: which LMA variant governs the cyber policy’s nation-state exclusion; does the crime policy respond to non-financial IP loss from an insider incident; and does the client understand that state-sponsored espionage – the specific threat the NZSIS is now confirming – may sit at the boundary of what their current programme covers. The NCSC’s annual Cyber Threat Report, due in October 2026, is expected to provide further granularity on the cyber dimensions of the threat environment.