SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
New Zealand SMEs face rising cyber threats, study finds

New Zealand SMEs face rising cyber threats, study finds

Tue, 22nd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

New Zealand's National Cyber Security Centre has published research showing rising cyber exposure among small and medium-sized businesses, with stronger pressure on medium-sized firms.

Nearly half of SMEs surveyed, 43%, said they believe their organisation is vulnerable to a cyber attack, up from 34% a year earlier. That sense of exposure was higher among larger SMEs, reaching 55% for businesses with six to 19 employees and 59% for those with 20 to 49 employees.

The data also showed medium-sized companies were more likely to face direct threats. More than three-quarters, 76%, of businesses with 20 to 49 employees said they had experienced a cyber threat or attack in the previous six months, compared with 53% of SMEs overall.

Among medium-sized businesses that suffered a cyber attack, 44% said the impact was moderate to severe. Reported effects included financial loss, device damage and stress.

AI concerns

The research identified AI-enabled threats as an emerging concern for business owners and managers. AI-generated scams, deepfakes and more sophisticated cyber attacks now rank as the fourth most prominent cyber threat for SMEs.

Kevin Moar, Acting Deputy Director-General at the National Cyber Security Centre, said the technology is changing how criminals approach fraud and intrusion.

"AI is making it easier for cyber criminals to carry out attacks and increase their effectiveness. We're seeing it used to make scams, phishing attempts and impersonation more sophisticated and convincing, which can make it much harder for people to recognise when something isn't right. The technology used by criminals continues to evolve, but the fundamentals of good cyber security do not. Keeping software up to date, using multi-factor authentication, backing up important data and making sure staff know how to recognise and respond to threats can significantly reduce an organisation's vulnerability," Moar said.

Despite greater awareness of cyber risk, the range of preventative steps taken by SMEs was broadly unchanged from the previous year. Staff training remained a notable gap.

Almost one in three SMEs, 32%, said they were taking no action to train or upskill staff in cyber security. That suggests many smaller employers still rely on technical controls alone, even as phishing, impersonation and other people-focused attacks become harder to detect.

Reporting gap

The survey also found that not all incidents are being disclosed. While 68% of SMEs that experienced a cyber threat reported or disclosed it, almost a third did not.

Among businesses that chose not to report an incident, 58% said it was not significant enough to report and 51% said they did not see the point. Those responses suggest many smaller businesses still treat lower-level incidents as isolated events rather than useful intelligence.

Moar said under-reporting limits understanding of the broader threat landscape and can reduce the help available to victims.

"Cyber security is everyone's responsibility, and people are one of the strongest defences a business has. Giving staff the skills to recognise suspicious activity, question something that doesn't look right and know what to do when an incident happens can make a meaningful difference. Cyber Smart Week is a chance for businesses to make those conversations part of everyday work. Small actions taken consistently can make an organisation significantly harder to target," Moar said.

The study was conducted by TRA for the National Cyber Security Centre and surveyed 373 IT and operational decision-makers from New Zealand businesses employing up to 49 people. The figures offer a snapshot of sentiment and experience across the country's SME sector.

The concentration of attacks among firms with 20 to 49 staff may reflect their position in the market. These businesses are often large enough to handle more customer data, payments and supplier relationships than very small firms, but may still lack the resources and specialist security teams available to larger corporates.

That pattern matters because it suggests cyber risk is not spread evenly across the SME segment. Businesses moving beyond the smallest size bracket may face a sharper rise in exposure before their security practices catch up.

Moar said even low-level incidents could help build a clearer picture of threats affecting New Zealand businesses.

"Even seemingly minor incidents can help build a clearer picture of the threats facing New Zealand businesses. We receive reports of all sizes, from phishing attempts through to major breaches. Reporting can help a business understand what has happened, limit further harm and recover. It also gives us a clearer picture of the threats affecting New Zealand, so we can warn and support others," Moar said.