In October 2025, New Zealand's National Cyber Security Centre (NCSC) published minimum cyber security standards applicable to public service agencies and organisations connected to government systems. The standards set a formal baseline — and while they're currently targeted at the public sector, they signal the direction of travel for all NZ organisations.
If you work with government agencies, hold sensitive data, or are subject to a contract requiring you to demonstrate security controls, these standards are already your practical baseline. Here's what they require.
What the NCSC minimum standards cover
The NCSC minimum cyber security standards establish requirements across six control domains:
1. Governance — Security accountability must be assigned at the executive level. This isn't an IT problem; it's a board problem. The standard requires documented security policies, a named person responsible for security outcomes, and evidence of regular board-level security reporting.
2. Asset and access management — You must know what you have and who can access it. This includes maintaining an asset inventory, implementing least-privilege access, and ensuring multi-factor authentication (MFA) is in place for all privileged accounts and remote access.
3. Vulnerability and patch management — Critical vulnerabilities must be patched within specific timeframes. The standard references the NCSC's known exploited vulnerabilities guidance as the priority list. End-of-life software still in production use is an automatic finding.
4. Data protection — Data must be classified, and protection controls applied according to classification. Encryption at rest and in transit for sensitive data is a baseline expectation.
5. Incident detection and response — Covered organisations must have a documented incident response plan, a process for detecting and logging security events, and a tested capability to contain and recover from a breach.
6. Security awareness training — Staff must be trained to recognise and respond to human-targeted attacks. This requirement is specific about *ongoing* training — not just induction. Phishing simulation is explicitly referenced as a best practice mechanism.
Who the standards currently apply to
Currently, the minimum standards apply directly to:
- Public service departments
- Crown entities
- Organisations with a Government Cloud certification or connected to All-of-Government services
- Suppliers and vendors under government contracts that include security requirements
However, the NCSC has signalled that these standards represent minimum expectations for any organisation handling sensitive data, and they're increasingly being referenced in contract requirements from large private sector organisations as well.
The gap most organisations have
The most common finding when organisations assess themselves against these standards is in governance and documentation. The technical controls often exist — patching happens, MFA is on for most accounts, backups run — but the evidence doesn't.
A security auditor doesn't take your word for it. They look for:
- A documented security policy, signed off by leadership, dated within the last 12 months
- An asset register showing what systems hold what data
- Patch records showing when vulnerabilities were identified and remediated
- Training completion records showing who was trained and when
- An incident response plan that's been tested, not just written
If you can't produce these, you fail the audit regardless of what your technical controls actually do.
How to assess your current position
A practical self-assessment against the NCSC minimum standards takes a few hours and gives you a clear gap list:
- Governance — Does a named executive own security? Is there a security policy dated within 12 months? Does the board receive regular security reporting?
- Access — Is MFA enabled for all remote access and privileged accounts? Is there an onboarding/offboarding process for system access?
- Patching — What's your current patch cadence? Are there any systems running end-of-life software?
- Data — Do you have a data classification scheme? Is sensitive data encrypted at rest?
- Incidents — Is there a written incident response plan? Has it been tested (tabletop exercise, simulation)?
- Training — When was the last security awareness training? Do you have completion records? Have you run a phishing simulation?
See our post on cyber security compliance for NZ and Australian businesses for a broader comparison of frameworks your organisation may need to align with.
What the standards mean for cyber insurance
Cyber insurers are increasingly using the NCSC minimum standards as their baseline underwriting checklist. Businesses that can demonstrate compliance with all six domains are better positioned for:
- Lower premiums — reduced risk profile is a direct input to pricing
- Fewer exclusions — insurers carve out coverage for incidents caused by failures in documented controls
- Faster claims — documented evidence of controls shortens the investigation phase after an incident
The inverse is also true. An organisation that can't demonstrate MFA on remote access, documented training, or a tested incident response plan may be denied a claim for an incident that those controls would have prevented.
SecureAZ covers the staff training domain of the NCSC minimum standards — with role-based awareness modules, phishing simulations, and completion records. Start a free trial to see how quickly you can close that gap.