IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
iPayroll mandates 2FA security for employee logins

iPayroll mandates 2FA security for employee logins

Mon, 20th Jul 2026
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

iPayroll has made two-factor authentication mandatory for all Employee Kiosk logins, extending a security requirement that already applied to payroll back-office staff.

Employees must now use either an authenticator app or email-based verification to access their accounts. Staff already using an authenticator app can continue to do so, while other users will receive a one-time code at their registered email address.

The change comes as businesses in New Zealand face a sustained rise in cyber incidents. Payroll systems are a frequent target because they hold personal and financial information, including salary details, tax records, and bank account data.

Recent attacks have sharpened attention on data protection across the country. A breach involving a health patient portal exposed sensitive medical information belonging to more than 120,000 New Zealanders, adding to concerns about how organisations manage confidential records.

Industry figures cited by iPayroll point to broad pressure on employers. Up to 59% of New Zealand businesses experienced a cyber incident in the past year, while 44% of medium-to-large organisations were affected by cybercrime.

Security shift

Two-factor authentication adds a second identity check beyond a password. In practice, users must provide more than just a password before entering the system, reducing the risk of access via stolen or reused login details.

Until now, iPayroll required two-factor authentication for payroll back-office staff, but left it optional for employees using the Employee Kiosk. That option has now been removed, applying the control across all employee logins.

The decision reflects a broader shift by software providers and employers to tighten access controls around systems that store sensitive workforce data. Payroll services sit at the centre of employment administration, so that a security lapse can expose both personal information and payment processes.

For employers, stronger login checks can also affect compliance and internal risk management. Businesses are under growing pressure to show they have taken reasonable steps to protect employee information, particularly when systems are accessible remotely.

Company context

Founded in Wellington in 2001, iPayroll provides payroll software and online PAYE intermediary services in New Zealand. It says it supports more than 10,000 businesses and offers tools for pay runs, tax calculations, reporting, leave management, and other payroll tasks.

iPayroll also holds ISO/IEC 27001 accreditation, a widely used standard for information security management. The latest authentication change sits within a broader framework of security and risk controls rather than as a standalone measure.

The company described payroll as one of the most sensitive functions inside an organisation because of the volume and type of information involved. That sensitivity has made payroll and human resources systems an attractive route for attackers seeking identity data, financial details, or a way into wider corporate networks.

Cyber specialists have long argued that passwords alone offer weak protection, especially when staff reuse credentials across multiple services or fall victim to phishing attempts. A second verification step does not remove all risk, but it can make unauthorised access more difficult.

Martin Gleeson outlined the rationale for the move in a statement.

"As cyber threats continue to evolve, businesses need stronger layers of protection beyond passwords alone. Mandatory 2FA is an important step in helping protect both businesses and employees from unauthorised access and emerging cyber risks," said Martin Gleeson, Managing Director, iPayroll.

Mandatory two-factor authentication for employee access marks a notable tightening of controls for a system used by thousands of businesses. It also underlines how routine payroll access is increasingly being treated as a frontline cybersecurity issue rather than a back-office technical matter.