The New Zealand Protective Security Requirements (PSR) set the baseline security standards for NZ government agencies and their suppliers. While much of the PSR focuses on physical security and personnel vetting, the people security component — which directly addresses awareness training — is one of the most practical and auditable requirements in the framework.
If your organisation is a government agency, a supplier to government, or in the process of becoming one, understanding what PSR requires for security awareness is essential.
What the PSR Says About Awareness Training
The PSR states clearly: security awareness training should be an ongoing, regular part of an organisation's operations, starting as soon as new people join as part of induction, with regular refresher sessions and targeted training when the threat environment changes.
That's a remarkably specific mandate. It covers:
Induction — training must begin when new staff join, before they have unsupervised access to sensitive systems or information. This isn't aspirational — it's a baseline requirement.
Ongoing regular training — the PSR explicitly rejects once-a-year compliance theatre. The intent is continuous reinforcement of security behaviours.
Threat-responsive training — when the threat environment changes (a new campaign targeting NZ government, for example), the training should respond. This requires a training platform that can be updated quickly with relevant content.
The PSR's people security requirements sit alongside NZISM and NCSC guidelines as the three core frameworks governing information security in NZ government. They are designed to work together — and an organisation that satisfies PSR awareness requirements will generally satisfy NCSC minimum cyber security standards in the same stroke.
Who the PSR Applies To
The PSR applies directly to all NZ government agencies — departments, ministries, Crown entities, and intelligence agencies. It also applies to suppliers and contractors who handle government information classified RESTRICTED or above.
For private sector organisations working with government — IT providers, consultancies, professional services firms — PSR compliance is increasingly a procurement requirement. Government agencies are required to ensure their suppliers maintain security standards commensurate with the information they access.
If you're bidding for government contracts, expect to be asked about your security awareness programme. The ability to produce completion records and a documented training schedule is often a differentiator.
The Threat Environment PSR Was Built For
The NZ government threat landscape is specific. The NCSC's annual cyber threat reports consistently identify state-sponsored actors, business email compromise targeting government procurement, and spear-phishing campaigns against ministerial and executive staff as the primary threats.
Generic cybersecurity training doesn't adequately address these. Staff need to understand:
- New Zealand-specific phishing lures — IRD, NZTA, ACC, and government-branded impersonation
- Business email compromise patterns targeting NZ procurement processes
- The specific handling requirements for RESTRICTED and SENSITIVE information
- What to do when they receive a suspicious communication from an apparent government agency
Phishing simulations using NZ-localised templates are the most effective way to translate awareness training into changed behaviour — and they produce the measurable outcomes the PSR's "regular refresher" intent requires.
Building a PSR-Compliant Programme
A programme that satisfies PSR people security requirements needs:
- Induction training — completed before or on first day, covering data handling, classification, incident reporting, and phishing identification
- Regular refreshers — minimum annually, ideally quarterly
- Threat-responsive updates — a mechanism to push new training when the NCSC or CERT NZ issues threat advisories
- Completion records — exportable reports showing who completed what and when
- Simulation testing — phishing simulations that test whether training translates to behaviour
The documentation requirement is critical. PSR audits look for evidence of a functioning programme — not just a policy document asserting that one exists.
Supplier and Contractor Obligations
If your organisation is a supplier to government, your awareness training programme will be assessed as part of the security assurance process. Agencies are required under the PSR to verify that suppliers handling government information maintain appropriate controls.
In practice, this means producing:
- Your training completion report for the current period
- Evidence that all staff with government system access have completed training
- Your training schedule showing refresh frequency
- Phishing simulation records if available
Cyber insurance documentation and PSR compliance evidence often use the same underlying reports — a well-run training programme generates the evidence for both.
SecureAZ holds NZ Government approved supplier status and provides PSR-aligned training with NZ-specific content, completion records, and documentation designed for government sector compliance. 45-day free trial, no credit card required.
External references: