Cybersecurity compliance in the ANZ region sits at the intersection of several overlapping frameworks, some mandatory and some voluntary. The result is a landscape that's genuinely confusing for businesses that aren't dedicated to tracking it.
This is a practical guide — not legal advice — to understanding what applies to your business and what you actually need to do.
New Zealand: The Privacy Act 2020 and CERT NZ
The Privacy Act 2020 is the primary legislation affecting how NZ businesses handle personal information. Key cybersecurity implications:
Mandatory breach notification. If a privacy breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals. There's no size exemption — this applies to any business holding personal information, including sole traders.
Security safeguards (Information Privacy Principle 5). You must protect personal information against loss, unauthorised access, use, modification, disclosure, or other misuse. The standard is "reasonable security safeguards" — what's reasonable scales with the sensitivity of the data and the size of the organisation.
Penalties. The Privacy Commissioner can issue compliance notices and refer serious cases to the Human Rights Review Tribunal. Fines for certain offences reach $10,000. The reputational and civil liability risks are typically larger than the statutory fines.
CERT NZ provides the Critical Controls framework — eight prioritised security controls aligned with the Australian Essential Eight. These aren't mandatory for most NZ businesses, but they're the standard against which "reasonable security safeguards" is increasingly measured.
Australia: The Privacy Act, Essential Eight, and Sector Rules
Australia's Privacy Act 1988 is currently being significantly reformed. The key change for SMBs: the government has proposed removing the small business exemption (currently businesses under AU$3M turnover are largely exempt). If this proceeds, substantially all Australian businesses will have direct Privacy Act obligations.
The Essential Eight is the Australian Signals Directorate's (ASD) prioritised mitigation framework:
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
For most SMBs, achieving Essential Eight Maturity Level 1 is the practical target — and it's increasingly expected by cyber insurers, enterprise clients, and government contracts.
Sector-specific requirements:
- Healthcare: My Health Records Act, state-level health privacy legislation
- Financial services: APRA CPS 234 (for regulated entities), AML/CTF obligations
- Critical infrastructure: Security of Critical Infrastructure Act 2018 (for larger organisations in designated sectors)
- Defence suppliers: DISP membership requirements and associated security obligations
What Both Countries Require in Practice
Across both jurisdictions, the baseline expectation for any business holding customer or employee data includes:
- Access controls — who can access what, with appropriate authentication (MFA for sensitive systems)
- Encryption — data in transit and at rest, particularly for personal information
- Patching — operating systems and applications kept reasonably current
- Backups — tested, offsite or cloud-based, with known recovery time
- Staff training — documented evidence that staff understand their obligations
- Incident response — a documented process for identifying, containing, and reporting breaches
The staff training component is specifically relevant for SecureAZ. Having trained your team — and being able to prove it with completion records and certificates — is a meaningful part of demonstrating "reasonable security safeguards" under both frameworks.
Cyber Insurance
Cyber insurance in the ANZ market has tightened significantly since 2021. Insurers now routinely require:
- MFA on email and remote access
- Regular patching
- Documented security awareness training
- Tested backup and recovery process
- Incident response plan
Several major brokers report that businesses without documented security awareness training now face premium loadings or coverage exclusions for social engineering attacks. A SecureAZ completion report is exactly the documentation insurers ask for.
If you're not sure where to start, CERT NZ's Small Business Guide and the ASD's Small Business Cyber Security Guide are the best plain-language starting points in each country.