NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Chris Keall: Cyber-attacks: Five ways NZ is asleep at the wheel

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
15 Mar, 2021 02:00 AM8 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Communications Minister David Clark: "Any increase to cyber security spending is subject to Budget decisions. Decisions on Budget 2021 are still being considered." Photo / Mark Mitchell

Communications Minister David Clark: "Any increase to cyber security spending is subject to Budget decisions. Decisions on Budget 2021 are still being considered." Photo / Mark Mitchell

OPINION:

Cyber attacks are on the rise, but New Zealand's response remains relatively low-energy.

Here's how other countries are moving ahead, and NZ falling behind.

US, Australia on the front foot

In the US, President Joe Biden launched an emergency task force to address the aggressive cyber attack on hundreds of thousands of Microsoft Exchange customers around the world - which is still under way.

Advertisement
Advertise with NZME.

After a wave of cyber-attacks against Australia last year, Prime Minister Scott Morrison said his company needed to put itself on a "war-footing" against hackers, and announced A$1.35 billion ($1.4b) in new spending to support efforts to defend the country's public and private networks.

Here, we saw Crown agency Cert (the Computer Emergency Response Team), created in 2016 with a $22m budget, got a $2.3m lift in its annual budget over each of the next four years in Budget 2019. A pitiful $8m (or $2m) a year was allocated in Budget 2019 to "help implement Cyber Security Strategy" but so far no initiatives have been announced from it.

Cert plays an education and alert role.

At the sharp end of things is a GCSB unit called the National Cyber Security Centre (NCSC), which runs the Cortex software that helps protect government agencies, plus the networks of companies deemed to be key exporters or otherwise essential to our economic security.

Advertisement
Advertise with NZME.

Funding for the NCSC is never broken out, but we do know that Budget 2020 saw the total allocation for Communications, Security and Intelligence drop to $122m from the prior year's $131m.

Herald Network Graphic
Herald Network Graphic

The US, Australia and other countries have been happy to announce new initiatives and new spending on the fly as the cyber-threat escalates.

Discover more

Business

The year of the hacker: Why now, and why NZ is seen as a soft touch

02 Sep 05:34 AM
Business

Rocket Lab, Nash, tell Greens combat-support payload is lawful

10 Mar 06:39 PM
Official Cash Rate

Data breach: Reserve Bank likely facing $250K ransom; files from other victims made public

18 Feb 01:45 AM
Business

'Foreseeable attacks, critical gaps': Watchdog slams NZX for cybersecurity failures

27 Jan 07:16 PM

And here, there's been no shortage of high-profile victims, from the NZX to the Reserve Bank to regular folk as CERT NZ has tracked a one-third increase in cyber attacks over the past year.

However, new Digital Economy and Communications Minister David Clark told the Herald earlier this week, "Any increase to cyber security spending is subject to Budget decisions. Decisions on Budget 2021 are still being considered."

Clark is already under fire from some in the ICT sector over an apparently unhurried approach to the next spectrum auction.

National, if you're wondering, did not mention cyber-security in its IT policy last election, letting a free-hit go begging.

Under one roof vs under many roofs

Last year, a GCSB staffer complained to the Herald about a number of issues, from Cortex getting creaky to skilled staff being poached by the private sector. But perhaps the key issue was a stew of agencies being involved in cyber-security, and confusion over who should take the lead.

Martin Cocker, the head of Crown agency Netsafe - which deals with everything from cyber-bullying to hacking, scams and harmful content - has not been shy of making the same point.

Advertisement
Advertise with NZME.

"New Zealand doesn't have a clear strategy for fighting scams," Cocker told the Herald in February, as he commented on a case where a business's email system was hijacked by hackers, who then used it to send fake invoices from its real email accounts.

"We have a lot of agencies doing a lot of stuff; a lot of good stuff, but one of them needs to take a lead role."

It's a sharp contrast to Australia, where staff cybersecurity specialists from multiple agencies - including Australia Federal Police, the Aussie equivalents our GCSB and Cert, and even policy makers - are literally under one roof in the Australian Cyber Security Centre - as described by one of Australia's top cyber-cops, Brad Marden, during a recent transtasman Business Circle meeting.

NZ cybercop envious

"We've got to be a bit more dynamic, and partner more with business," Acting Assistant Commissioner Mike Johnson, Investigations, Serious and Organised Crime, New Zealand Police, told the same meeting, in the context of discussing the recent rash of attacks, including the NZX.

"We've really got to work hard on that. I'm envious of what Brad's talking about in terms of them all being in one building. We do that really well in a different way - but there's some improvement to be made," Johnson said.

"Often we're mitigating an attack in its own right - but we really need to get ahead of that to be proactive and get people to invest in protection.

"Yes, New Zealand's bottom of the world, we think we're quite safe. Actually, we're in a borderless society. So we've got to change our thinking."

Johnson said NZ Police were now "linking much more proactively" with international colleagues - such as the FBI on the NZX attack - but he added that, as a country, "we've really got to be more nimble".

Poor education

Cert NZ acts as a kind of triage unit, advising people or small businesses who've been hit by hackers. It also runs alerts. It was a sensible move to set up the Crown agency in 2016, but since then it's led a largely low-profile existence.

It needs more resources for promoting the hacker threat, and what individuals and organisations can do about it, just as Netsafe has with harmful content.

Whenever I've spoken to people who've been hacked, such as this West Auckland couple who were stung for $21,000, they've inevitably never heard of CERT.

As things stand, there's been a culture of complacency, with recent reports finding even the likes of the Reserve Bank and the NZX have under invested in security.

Mixed messages

Since 2013, Cabinet has directed government agencies to take a cloud-first approach to developing new IT services, while the distinctly cloud-hesitant GCSB still advises Crown organisations to assess the cloud on a case-by-case basis.

Similarly, a Government directive in place since 2018 that "agencies must consider how they can create opportunities for New Zealand businesses" has been reinforced during the outbreak - even as the Crown hands high-profile work, such as the new, unfinished vaccine register, to multinationals.

In 2018, there was an attempt to take things by the scruff of the neck.

Then Communications Minister Clare Curran sought to cut across the alphabet soup of digital titles and agencies in security and other IT areas by appointing a digital czar or chief technology officer with sweeping powers to shape strategy.

That effort fell on its face as appointee Derek Handley was handed a $107,500 payout as the Government had a last-minute rethink. After Curran was shuffled off stage left, it was ultimately decided that the CTO role should be replaced by a "Digital Council" of lowish-profile IT industry figures who were appointed in February 2020 without fanfare. It's put out some reports summarising the work of other agencies, and encouraged the Government to do better in areas such as closing the digital divide - where we saw a brief burst of energy during the first lockdown before it petered out as children returned to school. Government agencies, DHBs, schools, councils and other government agencies continue to take different approaches to security and other IT issues, depending on area, wealth and whim.

POSTSCRIPT: Hackers do get stopped

In its most recent publically-available annual report, for year to June 30, 2019, the GCSB says it recorded 339 "cyber-security incidents involving organisations of national significance" - actually slightly down from prior year's 347.

Of those, 131, or 38 per cent "had links to state-sponsored actors".

The GCSB says "disruption of malicious cyber activity, by Cortex capabilities, has prevented $27.7 million worth of harm to New Zealand's nationally significant organisations".

The previous year, Cortex (described by Prime Minister John Key as "Norton AntiVirus at a very high level") prevented $27.0 million worth of harm, the agency says, while over the past three years, the total is $94.7m. The methodology behind the numbers is not shared.

The GCSB says it "surveyed 250 nationally significant organisations to establish their cyber-security resilience and the potential impacts if they were compromised" in the year to June 2019. It doesn't say what the follow-up action was; certainly, it wasn't enough to spur the Reserve Bank (according to a June 2020 internal report) or the NZX (according to a January 2021 FMA report) into updating under-resourced systems. And that begs the question: how many attacks go undetected?

Stories about hackers being caught tend to be few and far between, whether big organisations or individuals are being targeted. There are obvious challenges for local law enforcement when attackers are based in Nigeria or Eastern Europe. But what about business email compromise - where a company's network is hacked and then fake invoices sent from real email addresses. That scam often involves a local accomplice, who sets up a local bank account (see the West Auckland couple story).

Cert has identified business email compromise as a rising threat over the past couple of years. I asked police for some prosecution stats over the past three years, but there was no "business email compromise" category, and even general hacking is blurred in with "illegal access" which could be me as a rogue employee misusing my company's network.

Still, the stats showed that for all NZ's various drawbacks in its war on cyber-crime, some people who mess with computers are being found out, and hauled into court.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Airlines

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM
Premium
Business

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Shares

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Pilot group to honour Erebus legacy with safety award

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM

The industry faces challenges but hopes to bring newcomers and veterans together.

Premium
The NZ boardrooms where women buck gender pay gap trend

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM
Median house prices down again, sales taking longer: monthly report

Median house prices down again, sales taking longer: monthly report

17 Jun 05:32 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP