NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Report into Commerce Commission security breach finds blame on both sides

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
5 Aug, 2020 05:30 AM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

More than 200 transcripts of meetings and interviews carried out by the Commerce Commission - some described as "sensitive" - were stolen in a burglary last October. Photo / 123rf

More than 200 transcripts of meetings and interviews carried out by the Commerce Commission - some described as "sensitive" - were stolen in a burglary last October. Photo / 123rf

An embarrassing security incident for the Commerce Commission happened five years after a KPMG review warned it about security failings, according to a report released today.

More than 200 transcripts of meetings and interviews carried out by the Crown watchdog - some of them described as "sensitive" - were stolen in a burglary last October, during which a laptop containing ComCom files was taken from the home of a contractor for an external service provider.

The contractor told the Commission they had not used password protection.

The regulator would not say which documents had been stolen, only that it had copies.

Advertisement
Advertise with NZME.

The Commission also promised to release results of an investigation to the public - which it has done today with two reports, albeit in heavily redacted form.

One report is by Richard Fowler, QC, and looks into the specifics of the October incident. The second, by KPMG, looks into the Commission's broader information management and security procedures.

Central details remain under wraps.

"The report finds the external provider had security obligations and was clearly plainly in breach of them," ComCom chair Anna Rawlings says. But it found fault with the regulator, too. Photo / File
"The report finds the external provider had security obligations and was clearly plainly in breach of them," ComCom chair Anna Rawlings says. But it found fault with the regulator, too. Photo / File

The identity of the contractor, the nature of their work and various details of the theft were suppressed by the High Court.

Advertisement
Advertise with NZME.

In addition, a section 100 order under the Commerce Act makes it a crime to disclose the contents of the stolen files.

"The report finds the external provider was clearly under contractual obligations with regard to information security and the retention and disposal of confidential material, that they understood these obligations and were plainly in breach of them," Commission chair Anna Rawlings said.

Discover more

Business

NZ's largest tech company sees Covid gains

30 Jul 03:19 AM
Airlines

Rocket Lab reveals problem that caused last mission to fail

31 Jul 08:41 PM
Business

Online casualties: Why NZ Defence Force sites went dark

01 Aug 08:20 PM
Business

Signs that Garmin paid $14m ransom - with NZ company helping out

01 Aug 09:13 PM

However, both the Fowler and KPMG reports also found fault with various Commission policies and culture - including some "informal" decision-making around security controls. ComCom staff previously leaned on the contractor as a make-shift backup when it needed a copy of mislaid files.

The watchdog has made a number of changes in response, which include:

• Ending the Commission's contract with the external provider.

• Equivalent work is now done in house by Commission staff or on-site by external providers using commission devices.

• Contacting current and past suppliers of services to the Commission to seek assurances they have appropriate security processes and protocols in place and to obtain details of those processes and protocols.

• Recruiting a Procurement Manager to improve contract management, reviewing contracts with external providers to ensure they include appropriate security and confidentiality obligations, and changing the internal contract approvals process.

Advertisement
Advertise with NZME.

• Making a number of changes to improve the way information is exchanged with external providers and third parties.

We do learn from the Fowler report that "Contractor C" was highly regarded.

But also that Contractor C's house was also burgled in 2018 - in that instance with no hardware containing Commerce Commission files on the premises.

Police say while the investigation into the October 2019 burglary is still open, it is no longer active. Photo / 123rf
Police say while the investigation into the October 2019 burglary is still open, it is no longer active. Photo / 123rf

And that Contractor C had done work for the regulator since at least 2005, but that in mid-2008 there was confusion over whether they had signed a confidentiality agreement.

The confidentiality agreement was then updated at various times as the Commission and the contractor shifted between various media for exchanging files, including email, USB keys, a shared network drive and Box.com.

Confusion over Contractor C's exact security status is a theme throughout the report as it traces the "organic growth" in the contractor's role.

"The pressures of work," meant that Contractor C did not carry out their annual deletion of files at the end of 2018, Fowler notes. In at least three instances earlier, ComCom officials had turned to Contractor C as an unofficial backup after files were mislaid at the commission's end.

Fowler also notes that a KPMG review of the Commerce Commission's IT security systems, released in May 2014, found "the security in place is not in line with the risks posed." Its major recommendations are listed in his report, but redacted.

KPMG's present-day report says relatively right security protocols were not always followed in practice.

It's report says the ComCom had a "moderate level of maturity" with its security controls but that "the Commission's approach to determining the controls to be deployed and the implementation was in many cases largely informal."

KPMG continues, "No significant policy gaps were identified. The policy requirements, however, are not consistently translating into staff working practices.

It found a"lack of centralised and formal documentation for all key information management processes, in particular those associated with in-confidence information."

KPMG also found, "Expectations are not clear about sharing information with other agencies/bodies outside the commission, e.g. courts.

A number of its report's recommendations are redacted. Those made public include that the ComCom conduct an audit of where all of its sensitive data is located, and that "to ensure classification and data loss prevention is effective and that any risk assessment is robust, the Commission "should first document the locations of all in-confidence data".

The Commission should consider streamlining its data and document repositories and educate staff on information security issues, KPMG said.

Unsolved

Meanwhile, police say while the investigation into the October 2019 burglary is still open, it is no longer active.

The stolen equipment has not been recovered and the burglar has not been located.

Police remain open to receiving and investigating any new information on the case.

The Commission encourages any person who has information about the stolen computer equipment to contact the police or the Commission.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Economy

Inside Economics: Why tomorrow’s GDP data won’t tell the real story

17 Jun 06:00 PM
Business

Rural vs urban economy: Who's doing 'the hard work' and which regions are booming?

17 Jun 05:00 PM
Premium
Opinion

Richard Prebble: How Labour can revive its fortunes with fresh leadership

17 Jun 05:00 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Inside Economics: Why tomorrow’s GDP data won’t tell the real story

Inside Economics: Why tomorrow’s GDP data won’t tell the real story

17 Jun 06:00 PM

Liam Dann takes a deeper dive into the week's economic news.

Rural vs urban economy: Who's doing 'the hard work' and which regions are booming?

Rural vs urban economy: Who's doing 'the hard work' and which regions are booming?

17 Jun 05:00 PM
Premium
Richard Prebble: How Labour can revive its fortunes with fresh leadership

Richard Prebble: How Labour can revive its fortunes with fresh leadership

17 Jun 05:00 PM
Premium
Pilot group to honour Erebus legacy with safety award

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP