Cyber Resilience

What 2026 taught boards about cyber resilience

By
4 October 2026

If there is one lesson from New Zealand’s high-profile cyber breaches throughout 2026, it is that cyber resilience has moved beyond the IT department to become an organisation-wide responsibility.

Right from day one, the Manage My Health breach put cybersecurity in the headlines during the usually quiet holiday period. A breach at Neighbourly played out in parallel. Other significant breaches followed throughout the year, from MediMap to, most recently, ZenTech and Thankyou Payroll.

The incidents have varied in their circumstances and impact. But they paint a common picture: cybercriminals continue to pursue valuable data and exploit weaknesses in identity, suppliers and basic security controls.

One of the clearest themes this year has been the targeting of healthcare organisations and health information. The cyberattacks in this sector show that sensitive personal information remains a primary target for cybercriminals.

Do you really need to hold all the data you currently hold?

Data minimisation is an important cybersecurity control. Boards should be asking what personal information the organisation collects, why it collects it, who can access it and how long it should be kept.

This is enshrined in law, and it is a good idea to know the Privacy Act 2020’s privacy principles inside out. Information that is no longer needed should not be left sitting in a database indefinitely – it needs to be deleted.

This year’s incidents have also demonstrated that an organisation’s cybersecurity is increasingly dependent on the security of others.

In the Thankyou Payroll incident, customer information was accessed through a third-party reporting tool, highlighting how a supplier or technology platform can become the pathway into sensitive organisational data.

Knowing which suppliers hold or can access company data should be as important as understanding who has access internally.

That does not mean conducting an exhaustive security audit of every supplier. Start with the critical ones. Identify your Tier 1 suppliers, understand what they can access and consider what happens to your business if they suffer an incident. A simple tabletop exercise with key suppliers could expose significant gaps before a real incident does.

The Manage My Health incident provides another important lesson: identity is becoming the new perimeter. The attackers did not need to overcome sophisticated security defences, they simply used stolen credentials to gain access.

Multi-factor authentication (MFA), robust access controls, least-privilege principles and good password practices remain among the most important defences an organisation has.

The same goes for people. Phishing and social engineering are still effective because they rely on exploiting human behaviour rather than technical vulnerabilities.

That is why events like Cyber Smart Week are so important. Its message is deliberately simple: improving cybersecurity does not always require greater complexity. Often, it means consistently getting the basics right and fostering a good cyber-savvy culture.

As we wrap up a busy year, what should directors be thinking about heading into 2027?

  1. Keep less. Risk less.Review what personal information you collect and retain. If you no longer need it, delete it. Every record you remove is one less record that could be exposed.
  2. Build resilience with your suppliers.Know which suppliers hold your data or support critical systems, then work with them on how you will respond if something goes wrong. Test the plan together so both sides know what to do if a supplier is compromised or unavailable.
  3. Treat identity as critical infrastructure.Make strong MFA and appropriate access controls a board-level priority. Know who can access your most sensitive systems and data, and why.
  4. Think holistically, spend strategically.Cybersecurity is not a competition to accumulate the most technology. Organisations can spend heavily on tools while underinvesting in governance, foundational controls, incident response and resilience. Review security investment holistically and prioritise where the organisation is most exposed.

And one final reminder as we gear up for the holiday season: have a Plan B.

The Christmas and New Year period is when a lot of opportunistic cybercriminals strike, as people switch off and let their guard down. What happens if your organisation suffers a breach on New Year’s Eve, but your CISO is at the beach or out of mobile coverage? Who has authority to make decisions? Who leads the communications?

Cybercriminals do not put on their ‘out of office’ for the Christmas holidays. One of the best defences during this period is being ready and having a plan in place.

Organisations remain vulnerable if they do not get the basics right: too much data, too much access, too little visibility of suppliers and insufficient preparation for when something goes wrong.

Cybersecurity in 2027 will still be about the basics. For directors, getting those basics right is increasingly a matter of organisational resilience, not just IT security.

This article originally appeared on the Institute of Directors (IoD) website. Kordia is proud to be the National Cyber Security Partner for the IoD.