NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Markets / Shares

GCSB warns cyber-attacks could get worse, issues advisory to all NZ businesses

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
30 Aug, 2020 11:36 PM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Image / 123rf

Image / 123rf

The GCSB has issued a "be prepared" advisory for all Kiwi businesses on the heels of the stock exchange suffering a fifth day of outages linked to cyber-attacks, unsuccessful attacks on Stuff and RNZ's websites over the weekend, and ransomware incidents that have hit, F&P Appliances, Lion, Toll Group and the Unversity of Auckland (where a ransom was paid by the US firm hosting its data), among others.

The advisory (in full below) comes from the GCSB's National Cyber Security Centre.

Small businesses without their own IT department - or anyone who finds it all Greek - is advised to contact another Crown agency, Cert (Computer Emergency Response Team) NZ.

Cert NZ was set up to advise individuals and small businesses on where to turn in law enforcement or the IT world if they suffer a cyber attack.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

There's potential for NCSC and Cert NZ to be overwhelmed if Kiwi businesses do seek advice en masse.

After a wave of cyber-attacks across the Tasman, Prime Minister Scott Morrison ear-marked $1.4 billion to put his country on a "war-footing" with hackers.

Our cyber-defence effort is measured in the tens of millions.

Today's GCSB advisory follows a Cert NZ warning last November that a group of hackers mimicking Russian hacker gang "Cozy Bear" were targeting NZ financial institutions with DDoS (distributed denial of service attacks) that overwhelm a website with connection requests - thereby rendering it inaccessible.

Advertisement
Advertise with NZME.

Threats are coming from multiple directions, experts say, including state actors, criminal gangs, insiders gone rogue, hackers just getting their kicks, and organisations who Inadvertently spill data into the cloud.

Cert NZ: Don't pay a ransom

Declan Ingram, deputy director of Crown cybersecurity agency Cert NZ, said his organisation never commented on individual cases, because it did not want to inhibit organisations from reporting problems.

But late last year, Cert did issue an alert around DDoS extortion attempts by Russian gangs - or at least gangs claiming to be Russian - who were targeting the financial sector in New Zealand.

And he told the Herald, "In 2019 we received 84 incident reports about DDoS attacks. In particular, cyber attackers emailed organisations alerting them that they would be subject to a DDoS attack unless they paid a ransom before a specified deadline. In some instances, the attackers initiated a warning or demonstrative attack against the organisation's IP network to prove their intent.

Discover more

Business

Signs that Garmin paid $14m ransom - with NZ company helping out

01 Aug 09:13 PM
Business

Lawyer's warning over family tree DNA tests

25 Aug 05:37 AM
Telecommunications

Spark increases profit 4% to $427m - but warns of Covid hit in FY2021

26 Aug 05:30 AM
Business

The state of contact-tracing in NZ - and countries we can learn from

28 Aug 05:28 PM

"Cert NZ does not recommend paying ransoms, as this could result in being targeted again," Ingram said.

That might be the official advice, but Wellington lawyer Michael Wigley has said there are some situations when paying up is the pragmatic choice - and Garmin reportedly paid a recent $14m ransom demand.

Cert NZ has also provided a couple of bits of advice on top of the GCSB tips below.

One is to educate staff to be suspicious of email attachments, or any digital assets their unsure of.

The other is a "cold backup" - or the old-fashioned process of copying vital files to a hard drive then storing them off-site.

A cold backup should be done as a complement to a cloud backup.

Advertisement
Advertise with NZME.

General Security Advisory: Ongoing campaign of DoS attacks affecting New Zealand entities

Summary

• The National Cyber Security Centre (NCSC) is aware of an ongoing campaign of denial-of-service (DoS) attacks affecting New Zealand entities.

• The campaign has included the targeting of a number of global entities, predominantly in the financial sector.

• The NCSC strongly encourages all organisations in this sector to consider the risk to their organisation of DoS and ensure appropriate mitigations are in place.

Recommendations

The NCSC recommends following the steps provided below, replicated from the Australian Cyber Security Centre1. It reflects best practice developed in response to previous denial of service activity.

Advertisement
Advertise with NZME.

Preparing for denial-of-service attacks

Before implementing any measures to prepare for denial-of-service attacks, organisations should determine whether a business requirement exists for their online services to withstand denial-of-service attacks, or whether temporary denial of access to online services is acceptable to the organisation.

If organisations wish to increase their ability to withstand denial-of-service attacks, they should, where appropriate and practical, implement the following measures prior to any denial-of-service attacks beginning:

• Determine what functionality and quality of service is acceptable to legitimate users of online services, how to maintain such functionality, and what functionality can be lived without during denial-of-service attacks.

• Discuss with service providers the details of their denial-of-service attack prevention and mitigation strategies. Specifically, the service provider's:

• capacity to withstand denial-of-service attacks

Advertisement
Advertise with NZME.

• any costs likely to be incurred by customers resulting from denial-of-service attacks

• thresholds for notifying customers or turning off their online services during denial-of-service attacks

• pre-approved actions that can be undertaken during denial-of-service attacks

• denial-of-service attack prevention arrangements with upstream providers (e.g. Tier 2 service providers) to block malicious traffic as far upstream as possible.

• Protect organisation domain names by using registrar locking and confirming domain registration details (e.g. contact details) are correct.

• Ensure 24x7 contact details are maintained for service providers and that service providers maintain 24x7 contact details for their customers.

Advertisement
Advertise with NZME.

• Establish additional out-of-band contact details (e.g. mobile phone number and non-organisational email) for service providers to use when normal communication channels fail.

• Implement availability monitoring with real-time alerting to detect denial-of-service attacks and measure their impact.

• Partition critical online services (e.g. email services) from other online services that are more likely to be targeted (e.g. web hosting services).

• Pre-prepare a static version of a website that requires minimal processing and bandwidth in order to facilitate continuity of service when under denial-of-service attacks.

• Use cloud-based hosting from a major cloud service provider (preferably from multiple major cloud service providers to obtain redundancy) with high bandwidth and content delivery networks that cache non-dynamic websites.

• If using a content delivery network, avoid disclosing the IP address of the web server under the organisation's control (referred to as the origin web server), and use a firewall to ensure that only the content delivery network can access this web server.

Advertisement
Advertise with NZME.

• Use a denial-of-service attack mitigation service.

Responding to denial-of-service attacks

Organisations that wish to attempt to withstand denial-of-service attacks, but have not pre- prepared should, where appropriate and practical, implement the following measures, noting that they will be much less effective than had they been able to adequately prepare beforehand:

• Discuss with service providers their ability to immediately implement any responsive actions, noting service providers may be unable or unwilling to do so, or may charge additional fees for services not covered in contracts.

• Temporarily transfer online services to cloud-based hosting hosted by a major cloud service provider (preferably from multiple major cloud service providers to obtain redundancy) with high bandwidth and content delivery networks that cache non-dynamic websites. If using a content delivery network, avoid disclosing the IP address of the origin web server, and use a firewall to ensure that only the content delivery network can access this web server.

• Use a denial-of-service attack mitigation service for the duration of the denial-of-service attacks.

Advertisement
Advertise with NZME.

• Deliberately disable functionality or remove content from online services that enable the current denial-of-service attack to be effective (e.g. implement a pre-prepared low resource version of the website, remove search functionality, or remove dynamic content or very large files).

Save

    Share this article

Latest from Shares

Premium
Capital markets report

NZX chief sees rising interest as Govt eases capital market rules

13 May 05:00 PM
Premium
Capital markets report

How Trump tariffs are clouding NZ's economic outlook

13 May 04:59 PM
Premium
Shares

Market close: Skellerup climbs 4% as tariff uncertainty eases

13 May 06:04 AM

One tiny baby’s fight to survive

sponsored
Advertisement
Advertise with NZME.

Latest from Shares

Premium
NZX chief sees rising interest as Govt eases capital market rules

NZX chief sees rising interest as Govt eases capital market rules

13 May 05:00 PM

The NZ capital market faces challenges, but NZX says reform will bring improvements.

Premium
How Trump tariffs are clouding NZ's economic outlook

How Trump tariffs are clouding NZ's economic outlook

13 May 04:59 PM
Premium
Market close: Skellerup climbs 4% as tariff uncertainty eases

Market close: Skellerup climbs 4% as tariff uncertainty eases

13 May 06:04 AM
NZ sharemarket rises on open after US stocks rally 2.8% on US-China tariff announcement

NZ sharemarket rises on open after US stocks rally 2.8% on US-China tariff announcement

12 May 10:01 PM
Connected workers are safer workers 
sponsored

Connected workers are safer workers 

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP