NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Sacrificial lambs and broken windows: Why NZ is so bad at cybersecurity

Damien Venuto
By Damien Venuto
NZ Herald·
24 Jun, 2021 05:18 AM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Gaining access to a secure site is far less glamorous than the film industry would have you believe. Photo / Getty Images

Gaining access to a secure site is far less glamorous than the film industry would have you believe. Photo / Getty Images

A nefarious group of hackers clad in their hoodies with cool names like Acid Burn or The Plague could in theory orchestrate a sophisticated Ocean's Eleven style digital heist to enter the mainframe of a corporate entity.

The far more likely – and admittedly boring – reality is that most successful hacks are conducted by opportunists who essentially break a window at the back of a building and sneak through.

Hackers are, in most instances, the digital equivalent of a person who goes from car to car in a parking lot to find the one that's unlocked.

The fascinating 2014 hacking of a Uruguayan medical facility by a security specialist offers a clear example of this. The only thing standing in his way was the login details – and they couldn't have been simpler.

The username? Admin.
The password? Admin.

Advertisement
Advertise with NZME.

It's still unclear exactly how a group of hackers were able to get into the Waikato DHB system in what has been called New Zealand's biggest ever cybersecurity attack, but a number of recent global events illustrate that hackers aren't finding it difficult to sneak into large systems that are meant to be secure.

The hacks of the healthcare system in Canada, Toll Group in Australia and the Colonial Pipeline in the United States, and now a DHB in New Zealand, all point to some worrying trends in cybersecurity, according to a local expert.

Safestack founder and CEO Laura Bell, whose storied career includes a stint in counter-terrorism for the UK Government, says the average IT security team in New Zealand is severely under-resourced.

Advertisement
Advertise with NZME.

"Our average security team's size is 1.2 people when it should be 10 times that number," Bell says.

Bell describes the people who hold these in-house roles as "sacrificial lambs" as they are the first to lose their jobs when things inevitably go wrong.

Discover more

Business

Apple, facing App Store heat, highlights threats of 'sideloading'

23 Jun 09:30 AM
Lifestyle

The Repair Shop's success due to Kiwi's 'persistence'

25 Jun 09:00 PM

"As a defender, you have to stop every possible attack," she says.

"Going back to the house metaphor, you have to protect every window, every lock, every bit of ceiling panel, all at once.

"An attacker only has to slip past one of those things because they're not trying to find every vulnerability. They just need to find one way to get in."

Bell speaks from a place of experience. In addition to her highly stressful work with the UK Government, she also spent around five years as a "penetration tester" – the moniker used for someone who is paid by a company to try to break into systems so that they can be improved.

During this period of her career, she quickly learned that the size of the company provided little indication of how secure their networks were.

"I've done testing for large multinationals with massive brands and I've done testing with tiny high-growth companies that employ just 20 people and are essentially one step away from working in a basement," she says.

Advertisement
Advertise with NZME.

"I've seen better quality in some of the younger companies than I have in larger organisations."

Safestack founder Laura Bell has worked in counter-terrorism and as a penetration tester during her career. Photo / Supplied
Safestack founder Laura Bell has worked in counter-terrorism and as a penetration tester during her career. Photo / Supplied

As technology evolves over years, larger organisations will tend to tag things on to their systems that could leave all the data in a precarious position.

"In one area you might have a crown jewels type application that nobody could ever break into, but then literally on the same server there'll be a marketing site that uses an old version of Wordpress.

"Naturally, because of the way things evolve, we might be tempted to just put something wherever we have a bit of space – and by doing that, we create vulnerabilities in otherwise secure systems."

In other words, we are inadvertently creating the entry points that hackers are continuously scouring the internet for.

Hackers invariably target bigger organisations in the hope of securing a larger ransom from their efforts.

Bell says the issue of whether to pay a ransom is ethically fraught and really depends on the circumstances of the business.

"It's a really tricky subject," she says.

"We're in a muddle because the frequency and the size of ransoms are going up. Companies face a trade-off between how long the breach will impact their business and whether that will cost more than the amount paid in the ransom.

"The problem is that even if you pay, you have no guarantee that they're not coming back. There is a risk that by paying we actually incentivise hackers to do more of it.

"But, if we look at the big ones that have happened in the last few months, you see the days and weeks it took these organisations to come back to life and you start realising that a few million dollars might be easier to swallow than all the disruption."

What's more concerning is that our idea of the hacker, burning the midnight oil and individually looking for insecurities, is as dated as the hoodies we think they wear.

The cliche of a hacker in a hoodie doing sophisticated tech wizardry is woefully inaccurate. Photo / Getty Images
The cliche of a hacker in a hoodie doing sophisticated tech wizardry is woefully inaccurate. Photo / Getty Images

Bell explains that most hacking these days incorporates the use of automated technology that scours countless sites, identifying known vulnerabilities and possible entry points.

"There's not a lot of human effort involved in finding a target and rolling these things out. They're basically going far and wide, looking for the right technologies and the right contact details. It just becomes a numbers game," she says.

"If you can scale that up big enough and you can get enough exposure and make your emails look legitimate, then you're going to maximise your chances of somebody clicking through. All the technology that we use to build high-quality, fast-paced software in major companies is the same technology you use to spread ransomware around the world."

A common mistake businesses make to protect themselves is investing in a security system, but then do little to ensure that's staffed appropriately to keep it functioning at a decent level.

"It's kind of like the treadmill effect," says Bell.

"You buy a treadmill and you feel really great because it's going to make you fit and healthy. But buying a treadmill doesn't do that. Actually learning healthy habits and taking steps every day to improve your health makes you healthy. You might use that treadmill as part of that, but it's not the answer alone.

"New Zealand spends quite a large amount on these devices, but not enough on the teams that are meant to support them."

The reluctance on the part of businesses or even governments to invest heavily in cybersecurity on a continuous basis can also come down to the psychology of grudge payments.

It's akin to paying insurance in that it requires you to keep paying a set fee in the event that something may go wrong at some point in the future.

No one wants to make these payments, but you similarly don't want to be caught in the next tech car crash.

And with algorithms scouring the internet and opportunists knocking on all the windows they find, another breach seems inevitable.

As Bell says: "Humans have always been jerks. We have always found ways to exploit or curse or lie to each other to get what we want. The electronic realm we live in now is just an extension of what we've always done. We're just applying new tools to it."

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Business

Vietjet orders 100 Airbus A321neo planes

18 Jun 12:26 AM
Premium
Property

'Biggest New World upgrade in NZ' - what was happening before fire?

18 Jun 12:00 AM
Premium
Retail

Asahi’s zombie company: The Better Drinks Co posts 10th consecutive loss

17 Jun 11:59 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Vietjet orders 100 Airbus A321neo planes

Vietjet orders 100 Airbus A321neo planes

18 Jun 12:26 AM

The Vietnam deal includes an option to buy 50 more jets later.

Premium
'Biggest New World upgrade in NZ' - what was happening before fire?

'Biggest New World upgrade in NZ' - what was happening before fire?

18 Jun 12:00 AM
Premium
Asahi’s zombie company: The Better Drinks Co posts 10th consecutive loss

Asahi’s zombie company: The Better Drinks Co posts 10th consecutive loss

17 Jun 11:59 PM
Meat and skincare on the agenda for PM's first day in China

Meat and skincare on the agenda for PM's first day in China

17 Jun 11:36 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP