IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Which New Zealand companies are most likely to be targeted by Ransomware hackers?

Which New Zealand companies are most likely to be targeted by Ransomware hackers?

Mon, 27th Jul 2026 (Today)
Anthony Cooke
ANTHONY COOKE Atmos

At Brightstar's National Cyber Security Summit in Q1 2026, Anthony Cooke from Atmos, the largest dedicated cybersecurity and digital risk law firm in New Zealand, shared salient stats that shine light on the nature and scale of cyber security incidents. Drawing on experience from over 3,000+ incident responses handled across Australia and New Zealand over 12 years, he shared patterns in threat actor behaviour and the costly legal mistakes in a crisis.

1. Biggest Targets

He revealed that in 2025 threat actors concentrate their efforts where financial value and regulatory pressure intersect. Over a third of all incidents target just two sectors:

  • Financial and Insurance Services: 18.8% of incidents
  • Professional Services and Consulting: 17.5% of incidents

These are sectors likely to be heavily regulated, making them difficult to manoeuvre around their obligations. They also store rich commercial data that is profitable to exploit and can be propagated to cause lasting financial harm.

Beyond sector breakdowns, the data highlighted a clear focus on company size, most significantly:

  • Mid-Market Concentration: 42% of ransomware incidents target mid-market businesses (annual turnover between $10M and $100M).

This focus on the mid-market is deliberate. Following high-profile enforcement actions in recent years, threat actors actively avoid massive global brands to stay off the radar of international intelligence agencies. Mid-market companies have sufficient capital to pay six-figure extortion demands without generating widespread intelligence / enforcement activity or attention.

2. The Nature of Attacks

Modern cyber attacks move fast, carry massive price tags, and offer zero guarantees even when demands are met.

  • Accelerating Dwell Time: The median time an attacker spends inside a network before deploying ransomware has dropped to 8 days (down from two weeks historically), though extreme cases reached up to 163 days.
  • Negotiation Reality: $1,200,000 is the median opening ransom demand (peaking at $3,500,000). Through structured negotiation, final settlements saw medians of $430,000 (peaking at $1,540,000).
  • Some Honour Among Thieves: In 80% of cases where ransoms were paid, attackers provided working decryption keys and did not leak obtained data as promised. However, in 20% of cases, no deliverables were provided. Some groups, such as SpaceBears, re-extorted victims who had already paid.
  • Recovery Costs are high for ransomware incidents: The average cost to recover from a ransomware incident (covering legal fees, PR, and technical containment, excluding any ransom payment) sits at $235,000, but can reach $2,100,000. Business Email Compromise (BEC) events averaged incident costs of $26,000, with high-end cases reaching $1,400,000+.

With some cyber insurance brokers reporting cyber insurance penetration of only around 10% across their existing New Zealand SME clients and approximately 40% across their large corporate clients, many organisations remain exposed to the financial consequences of a cyber incident. Feedback from the market suggests that balance sheet protection remains an underappreciated component of cyber resilience. Appropriate cyber insurance and other risk transfer arrangements should therefore be more actively considered as part of board-level risk management and governance discussions.

3. Legal Considerations and Preparation

The legal and reputational fallout often creates longer-lasting damage:

Preserving Legal Privilege

Public statements made by leaders can inadvertently weaken claims of legal privilege over internal forensic reports. In the Australian Optus class-action litigation, the court considered public statements about investigating the incident to understand what happened and prevent a recurrence as evidence that the investigation served a broader business purpose, not solely a legal one. This was a key factor in the court's decision to order disclosure of the forensic reports to plaintiff lawyers.

To protect these sensitive findings, engage legal counsel immediately upon detecting an intrusion so that technical investigations are ordered under formal legal privilege.

Crisis Communications and Wording

  • Avoid sensational terms like "cyber attack" in media statements, opting instead for precise terms such as "security incident" or "event."
  • Avoid immediate public apologies, which can be legally interpreted as an admission of liability before technical facts are established.
  • Prepare 24-hour crisis communication templates in advance. What an organisation says on the first day of an incident remains identical whether the breach happens today or in six months. This will help mitigate reputational risk and give the team room to breathe.

-

Continue the conversation in August conference

Since Anthony's talk in March, further high-profile incidents have happened including the Canvas data breach affecting our education institutions. We're pleased to invite Anthony again to dive into response and recovery in major incidents at our upcoming Cyber Security Risk Conference (part of the CIO Innovation and Summit experience). 

Learn more.

Cyber Security Risk Conference | 4 August 2026 | NZICC, Auckland