Skip to content

76% of New Zealand mid-sized firms faced cyber threats

76% of New Zealand mid-sized firms faced cyber threats - NCSC

New Zealand small and medium-sized businesses are reporting greater exposure to cyber attacks, with larger SMEs experiencing more incidents and more damaging consequences, according to new research from the National Cyber Security Centre.

The NCSC’s SME Cyber Security Behaviour Tracker 2026 found 43% of SMEs now consider their organisation vulnerable to a cyber attack, compared with 34% last year.

Perceived exposure rises with company size, reaching 55% among businesses employing 6-19 people and 59% among those with 20-49 employees.

Actual exposure follows a similar pattern. Some 76% of businesses with 20-49 employees experienced a cyber threat or attack during the six months before the research, compared with 53% across SMEs as a whole.

Among medium-sized businesses that experienced an attack, 44% described the impact as moderate or severe. Reported consequences included financial losses and damaged devices, while some organisations also cited stress resulting from an incident.

AI-enabled cyber threats have also entered the concerns of New Zealand businesses, ranking as the fourth most top-of-mind cyber threat in the 2026 research. Concern is growing around AI-generated scams and deepfakes, alongside attacks that are becoming harder for employees to identify.

Overall concern has increased slightly, reflecting ongoing vigilance

Overall concern has increased slightly, reflecting ongoing vigilance
Source: NCSC

NCSC Acting Deputy Director-General Kevin Moar said AI is giving cybercriminals tools to increase both the volume and effectiveness of attacks. Criminal groups are using the technology to produce more convincing phishing attempts and impersonation schemes, reducing many of the obvious signs employees previously relied on when spotting suspicious communications.

The technology used by attackers continues to change, but Moar said established cyber security practices remain effective.

Keeping software updated and using multi-factor authentication remain important controls, while regular data backups reduce the damage created by successful intrusions.

Staff awareness remains another area requiring attention. Almost one-third of SMEs, or 32%, still take no action to train or upskill employees in cyber security, with the level of preventative activity remaining broadly unchanged from last year.

Cyber security remains a highly important issue for SMEs

Cyber security remains a highly important issue for SMEs
Source: NCSC

The NCSC argues that employees represent an important line of defence because many attacks still depend on convincing someone to open a malicious link, disclose credentials or approve a fraudulent request.

Training staff to recognise suspicious behaviour and respond correctly gives businesses another barrier against both conventional and AI-assisted attacks.

Around 68% of SMEs that encountered a cyber threat reported or disclosed the incident, leaving almost one-third of affected organisations that didn’t report what happened.

Among businesses that kept incidents unreported, 58% said the event wasn’t serious enough to justify reporting. Another 51% said they saw little value in doing so, suggesting some companies still view reporting mainly as a response to major breaches rather than a source of support and threat intelligence.

AI risks are emerging as a new concern

AI risks are emerging as a new concern

Moar said smaller incidents still provide useful information about techniques being used against New Zealand organisations. Reports range from routine phishing attempts to serious breaches, and the information helps authorities identify patterns affecting multiple businesses.

Reporting also gives affected companies access to assistance in understanding an incident and limiting further damage. At national level, those reports give the NCSC more information about active threats, allowing the agency to warn other organisations facing similar activity.

The 2026 tracker shows a gap between rising awareness and changes in day-to-day security behaviour. More businesses now recognise their exposure, especially among organisations with 20-49 employees, yet preventive practices and employee training haven’t increased at the same pace.

AI adds more pressure to that gap because criminals are producing fraudulent content faster and with fewer obvious errors. For New Zealand SMEs, the NCSC’s message remains focused on established controls: stronger authentication, maintained software, reliable backups and employees trained to recognise suspicious activity.