NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Why paying a cyber ransom could land you with a big fine

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
27 Jul, 2023 10:18 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Ciaran Martin, who was in New Zealand this week, was the founding CEO of the UK's National Cyber Security Centre. He is currently chairman of CyberCX UK and Professor of Practice at Oxford University's Blavatnik School of Government. Photo / NZME

Ciaran Martin, who was in New Zealand this week, was the founding CEO of the UK's National Cyber Security Centre. He is currently chairman of CyberCX UK and Professor of Practice at Oxford University's Blavatnik School of Government. Photo / NZME

It remains legal - in many circumstances - to pay a cyber ransom.

But thanks to Vladimir Putin, there’s a new wrinkle that could see Kiwis who cave in to hackers hit with a big fine.

A visiting UK cybersecurity expert says we’ve struck the right stance on whether to pay a cyber ransom.

“The New Zealand Government has just issued some very strong guidance on not paying to the general population and essentially ruling it out for government. The latter point is really, really welcome,” says Ciaran Martin, the founding CEO of the UK’s National Cyber Security Centre, who now chairs CyberCX’s UK operation.

“There’s something in my gut that hates paying a ransom, but my gut doesn’t make good public policy.

Advertisement
Advertise with NZME.

“Cabinet has agreed that government agencies should not pay cyber ransoms,” the guidance reads.

It also says: “The New Zealand Government strongly discourages the payment of ransoms to cybercriminals, and urges all victims to report any cyber ransom incidents to the relevant agencies, regardless of whether a ransom is paid.”

Law enforcement agencies have long recommended a victim not pay a cyber ransom on the basis it incentivises further offending, there’s no guarantee you’ll get your data back (or that copies of stolen won’t be used to blackmail you or your customers) and that revenue from cybercrime helps fund offending in areas like drugs and human trafficking.

Advertisement
Advertise with NZME.

But the new guidelines highlight a more recent wrinkle, involving the Russia Sanctions Act 2022, passed by our Parliament in reaction to the invasion of Ukraine.

Many major ransomware gangs are based in Russia, according to analysis by Palo Alto Networks and other security firms who have noted groups using Russian in communications, among other pointers. And Russian nationals have featured strongly in the handful of arrests related to ransomware attacks.

That means paying a cyber ransom could now constitute breaking the new sanctions legislation. And the Government’s new guidelines highlight that could result in criminal penalties of:

  1. Up to both seven years in prison and/or a fine of $100,000 for individuals; and
  2. A fine of up to $1 million for organisations.

There’s a big qualifier, however. Ransomware gangs use a lot of tricks to mask the origin of any given attack, and demands are always made in bitcoin, the cryptocurrency not tied to any country. So proving a payment had been made to a party in Russia would be difficult to prove.

There have been calls by some tech commentators, including Herald contributor Juha Saarinen, to make it illegal to pay a cyber ransom to any party - a move billed as a circuit breaker as NZ faces ever-escalating cybercrime.

But shortly before she exited stage left, outgoing Justice Minister Kiri Allan reiterated the Government’s long-time opposition to making it illegal to pay a cyber ransom.

“While the Government understands making payments for cyber ransoms may be perceived as encouraging further attacks, taking criminal action against the victim raises issues of fairness in regard to making a victim a criminal when they are attempting to protect their business and livelihoods by making the payment. As such, there aren’t any current plans to criminalise those who pay cyber ransoms,” Allan said.

CyberCX’s Martin, who also served as director of security and Intelligence at the Cabinet Office, said, “I would, in principle, favour a ban - if a way could be found of making it work.

Advertisement
Advertise with NZME.

“If you look at what happened to the Irish health system in 2021, it was completely wiped out. There was serious disruption. It was one of the worse cyber-attacks there’s ever been.

“And the Irish state didn’t pay.

“They got lots of top-of-the-range companies in to help them. They got the army in and they got loads of help. And they found a way around that. But most organisations - particularly the smaller ones - can’t do that. They don’t have the resources of a government.”

“A ransom payment ban could only be extended beyond government organisations once the private sector had access to better support resources and the likes of insurance backstops. The best path was for a government ban, then to slowly extend that to private organisations. Otherwise there will be serious unintended consequences.”

Our Government has this week sought to improve support for cybercrime victims by folding Cert NZ into the GCSB’s National Cyber Security Centre (NCSC).

Was it the right way to go? Martin, who worked closely with NCSC head Lisa Fong during his time heading the UK equivalent, said: “This is a decision for the New Zealand Government. However, it is something we in the United Kingdom and Australia have both done successfully.”

A contrary take on AI

The rise of artificial intelligence has stoked fears about AI-assisted hacking from voice-cloning to orchestrating automated attacks that are more creative, and less likely to raise suspicion.

“AI allows you to generate lots of bad [as in malicious] code more quickly and effectively

“But luckily, AI also allows you to create good code to counter that bad code at the same sort of scale and volume. AI could be at worse neutral and at best positive.”

But his broader point is that most cyber attacks today, from ransomware to crude DDoS bot swarms that overwhelm a service, rendering it inaccessible, rely on victims using creaky systems that are about as far from AI as you can get (and one of many examples would be the Reserve Bank’s recent use of an antiquated file transfer system).

“We have legacy tech that we can’t fix. We can detect threats against it, and we can mitigate them, but you can’t fix a system that was not built with security in mind.”

Chris Keall is an Auckland-based member of the Herald’s business team. He joined the Herald in 2018 and is the technology editor and a senior business writer.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

World

Costly carriers: The growing pains of posh babywear

15 Jun 08:00 PM
Business|companies

Major banks halt over-counter deposits into others' accounts

15 Jun 07:37 PM
World

Meta messages: App users are taking over-sharing to an AI level

15 Jun 07:00 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Costly carriers: The growing pains of posh babywear

Costly carriers: The growing pains of posh babywear

15 Jun 08:00 PM

Unlike cribs, car seats and most baby gear, a carrier is not just for the baby.

Major banks halt over-counter deposits into others' accounts

Major banks halt over-counter deposits into others' accounts

15 Jun 07:37 PM
Meta messages: App users are taking over-sharing to an AI level

Meta messages: App users are taking over-sharing to an AI level

15 Jun 07:00 PM
Premium
RBNZ tight-lipped again – this time regarding 'exclusive' talk on interest rates

RBNZ tight-lipped again – this time regarding 'exclusive' talk on interest rates

15 Jun 07:00 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP