NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Economy / Official Cash Rate

Chris Keall: Two problems with the report on the Reserve Bank data breach

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
1 Jun, 2021 05:34 AM9 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

"We had no warning to avoid the attack which began in mid-December. Accellion failed to notify the Bank for five days," Reserve Bank Governor Adrian Orr says. Photo / Mark Mitchell

"We had no warning to avoid the attack which began in mid-December. Accellion failed to notify the Bank for five days," Reserve Bank Governor Adrian Orr says. Photo / Mark Mitchell

OPINION:

An independent report on the Reserve Bank's December data breach is unsatisfying, at least in its public version.

The incident saw a breach of a file-sharing service called FTA (File Transfer Application), operated by a US company called Accellion, which the RBNZ used to share files with its customers, who include retail banks and insurance companies.

Report author KPMG focuses heavily on the breach itself and particularly how various parties acted in its aftermath.

Advertisement
Advertise with NZME.

That's not to criticise KPMG, which was given limited scope. It was working to a terms-of-reference brief with a heavy emphasis on incident response, and recommendations for improvements.

Still, I was surprised that the public version of the report made no mention of two major elements in the story - both of which involve technical issues, but also suggest a wider management issue of warnings being ignored.

The first is a May 2020 (initially confidential) RBNZ report called Digital Services: Consultation for Change, with a foreword by the bank's chief information officer Scott Fisher.

The report includes the lacerating line that there is, "High operational risk due to technical obsolescence and an underinvestment in security across many of the core technology platforms."

Advertisement
Advertise with NZME.

The report namechecks Accellion and also calls for a move to "more resilient platforms" and an "uplift in our cyber-security capability".

So I was surprised that, six months later, the RBNZ was still using Accellion's creaky FTA service.

Discover more

Business

Revealed: NZ Space Agency briefing on Rocket Lab's controversial Gunsmoke J launch for US Army

31 May 05:38 AM
Business

Why are our defences so shaky? The Waikato DHB ransomware attack in 20 questions

28 May 05:00 PM
Business

'Foreseeable attacks, critical gaps': Watchdog slams NZX for cybersecurity failures

27 Jan 07:16 PM
Business

NZX attack: Where the buck stops - and why your company could be next

28 Jan 05:00 AM

Which brings us to the second major point not discussed in the KPMG report: Accellion's own warning that FTA was past its use-by date.

Accellion has been making assertive efforts to move its customers from FTA to its new Kiteworks service.

Spokesman Rob Dougherty said Accellion had been strongly encouraging its partners to upgrade from FTA to its newer, more secure Kiteworks service, which was first released in 2014 and works with Google Drive and Dropbox.

"For the past three years, Accellion has been attempting to move its existing FTA customers over to our modern and more secure platform, Kiteworks," Dougherty said.

RBNZ was one of around only 10 per cent of Accellion's customers still clinging to FTA.

Accellion's own independent report, by security company FireEye, doubles down on the point that FTA was an end-of-life legacy product. It notes that Kiteworks, which was built from the ground up on a new code base, was not breached during the attack.

Advertisement
Advertise with NZME.
Image / 123rf
Image / 123rf

While it ignores Fisher's report with its warning of "high operational risk" from underspending and outdated tech, KPMG's report does note that the RBNZ did address the need to upgrade its IT systems in its "Statement of Intent 1 July 2020 - 30 June 2023". However, the Statement addressed the issue in the blandest possible, feel-good terms, with lines like "We have developed a strategy to improve the digital capability of the Bank to ultimately become a stronger, more reliable and secure kaitiaki [guardian]."

Vulnerabilities with FTA were first reported in 2016.

A spokesman for RBNZ said the company stopped using FTA. (Now the case with all customers. Accellion shuttered the service on April 30.)

Image / 123rf
Image / 123rf

Elsewhere, KPMG backs the Reserve Bank's claim that when Accellion discovered the FTA security breach in December, it was slow off the mark to inform the RBNZ and other customers (a point that Accellion had already tacitly conceded by refusing to answer Herald questions about a detailed timeline).

KPMG says Accellion first discovered the FTA security breach on December 16. Accellion says it was able to offer customers a patch within 48 hours. KPMG says a technical failure in Accellion's alert system means the RBNZ was not informed until January 6. The bank implemented the patch on January 7, but by that time the horse had bolted - or at least the attackers had already downloaded what RBNZ described as "sensitive" files.

Accellion's slow communications allowed Reserve Bank governor Adrian Orr to go on the front foot, and shift attention from the RBNZ's failure to heed warnings about using an outdated system to share files.

Image / Getty
Image / Getty

KPMG says "There were also initial alerts of potential malicious activity on the System [FTA] in December 2020 that would have helped provide early detection had they been identified and/or followed up by the Bank's support staff. These alerts were default alerts enabled within the System since 2015."

KPMG also says the RBNZ should have undertaken a formal risk audit, which would have identified FTA as a potential pain point (Fisher's May 2020 warning notwithstanding).

Instead, the Reserve Bank seems to have gone in the other direction, developing an over-reliance and too much trust in FTA.

The Russian group known as 'Fancy Bear' has been blamed for several cyber-attacks around the world. In November 2019, Cert NZ warned it was targetting financial
The Russian group known as 'Fancy Bear' has been blamed for several cyber-attacks around the world. In November 2019, Cert NZ warned it was targetting financial

As KPMG puts it, "Usage of the System [FTA] by the Bank was not limited to secure file transfers as intended. Working practices evolved over time to the point where the System was also used as an information repository and collaboration tool, which was not
in adherence with the Bank's 2014 guidelines on acceptable use of the System. Adherence would have significantly reduced the volume of information at risk."

Broadly, KPMG gives the Reserve Bank a thumbs up for the way it responded from when it was first formally alerted to the hack by Accellion on January 6.

But it does note, "Some key events in the timeline in the period up to 9 January 2021 were not recorded in the detailed incident log", so KPMG was not working off a full record.

Image / Getty
Image / Getty

Early in the controversy, an insider told the Herald that the RBNZ's slow reach was, in part, because it was the Christmas/New Year holiday period and a lot of people were at the beach.

KPMG says staff responded rapidly, despite the incident falling in the holiday period, but does add that there was not strict adherence to all aspects of the MIRP [Major Incident Response Plan] with respect to the use of the defined playbooks," adding "It is difficult to extrapolate whether these factors would have materially impacted the overall timeline and outcome."

And its report also implies that while members of the MIRP team quickly ditched their beach towels, the response was hampered, to a degree, by not everyone being on deck.

It says a full response was delayed, for an unspecified time, because "Not all key Bank users of the System were involved in determining the extent of the potential breach as there was not widespread understanding of who was using the System, the nature of that usage and the at-risk information that was stored on the platform."

And although it never explicitly the RBNZ's failure to upgrade from FTA to Kiteworks (Kiteworks is never mentioned, per se), it implies that an upgrade project in the works - but that the bank was not taking steps to be more careful in the meantime.

"Delays in the project to replace the System [FTA] did not trigger any interim mitigating controls to be implemented or reinstated," KPMG says.

Recommendations

KPMG's report makes a series of sensible recommendations - some of which it says are already underway - including a risk-audit of systems, and the implementations of risk-management processes, including with third-party processes, that have so far been missing or are "not consistently enforced."

It's all straightforward, sensible stuff. The only question is why such routine security policies were not already in place.

Orr says the recommendations will be implemented.

What was taken?

Acceleron says 25 customers lost files after the FTA breach.

Those included the RBNZ. Orr said on February 9 that "For security reasons, we can't provide specific details about the number of files downloaded, or information they contain. We have been in regular communication with all organisations who have had files illegally downloaded ... External legal advisers are also providing assurance checks and advice on any personal information which was included in the downloaded files."

I'm not clear how simply saying the number of files taken, or the partner companies involved, would compromise security in any way. In some cases, citing "security" for saying almost nothing about a breach seems more like a public relations than cybersecurity strategy.

$3.5m hit

So many questions remain, including why the RBNZ did not opt for an on-shore file-sharing service.

Luckily, no RBNZ files have been spilled onto the web - a common tactic by ransomware attackers as they try to pressure victims. That could be luck, the fact that documents about the OCR, packed with dense economic jargon, have limited sex-appeal on the dark web).

Certainly, it wasn't because the Reserve Bank paid a ransom. Orr said it would not entertain the idea, in line with advice from police and the GCSB (which assisted post-attack, and covers various institutions of national interest with its Cortex system).

Nevertheless, the bank estimates that the final cost of the breach response, including internal resources, will be around $3.5 million, according to KPMG. All costs associated with the breach were absorbed into its baseline budgets.

Big picture lacking

A final missing piece: it could also have been useful for KPMG to look a the Reserve Bank's data breach through the lens of NZ's broader cyber-security crisis, which has seen not only institutions like the RBNZ and the NZX hit, but top corporates like F&P Appliances, Lion and Toll Group - and of course now the Waikato DHB.

In some organisations, there seems to be no appreciation that cyber-security is no longer an issue for the IT crowd, but clear and present danger to reputation, profit - and in some cases, lives - that boards to address.

There seems to be a systemic issue with major New Zealand institutions under-investing in cyber-security, and little sense of urgency from boards or the government to address the problem. But with KPMG being asked to work within such a narrow brief, those answers will have to wait for another report.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Official Cash Rate

Premium
Official Cash Rate

Reserve Bank blocks media from talk by OCR committee member Prasanna Gai

15 Jun 08:32 PM
Interest rates

Final big bank drops home loan rates after OCR cut

12 Jun 05:52 AM
Premium
Opinion

Jenée Tibshraeny: RBNZ's lack of transparency erodes its credibility

11 Jun 09:00 PM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from Official Cash Rate

Premium
Reserve Bank blocks media from talk by OCR committee member Prasanna Gai

Reserve Bank blocks media from talk by OCR committee member Prasanna Gai

15 Jun 08:32 PM

The Reserve Bank says no new information was disclosed in the speech.

Final big bank drops home loan rates after OCR cut

Final big bank drops home loan rates after OCR cut

12 Jun 05:52 AM
Premium
Jenée Tibshraeny: RBNZ's lack of transparency erodes its credibility

Jenée Tibshraeny: RBNZ's lack of transparency erodes its credibility

11 Jun 09:00 PM
Internal documents reveal why Adrian Orr resigned as Reserve Bank Governor

Internal documents reveal why Adrian Orr resigned as Reserve Bank Governor

10 Jun 11:16 PM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP