CERT NZ's quarterly and annual reports have consistently shown ransomware as one of the highest-financial-impact incident categories reported by NZ businesses. The 2024-2025 data shows no reversal of this trend — if anything, the targeting of NZ SMEs has increased as ransomware groups have moved down-market following improved defences among larger enterprises and more aggressive law enforcement action against groups targeting critical infrastructure.
This post covers what the CERT NZ data shows about ransomware in NZ, how attacks are getting into SME environments, and the response steps that matter in the first 24 hours.
---
What the Data Shows
CERT NZ's reporting captures incidents that are voluntarily disclosed. The actual incidence of ransomware is believed to be significantly higher than reported numbers suggest, since many businesses choose not to report for reputational and insurance reasons.
From the available data, several patterns are consistent:
- Initial access is predominantly credential theft and phishing. The overwhelming majority of ransomware incidents in NZ begin with a phished credential, a brute-forced RDP port, or a credential stolen from a prior breach and reused. Strong authentication controls and phishing simulation address the most common entry point directly.
- SMEs are being targeted specifically, not just caught in the crossfire. Ransomware groups have identified NZ SMEs as high-value targets — they hold valuable data, they have limited security resources, and they are more likely to pay than to have effective backup and recovery capability.
- Healthcare, professional services, and construction are over-represented. Healthcare organisations hold sensitive personal information with high ransom leverage. Professional services firms hold client data that cannot be publicly released. Construction businesses often have project data that is time-critical.
- Payment does not reliably restore access. CERT NZ and international incident response firms consistently find that a significant proportion of ransom payments do not result in full data recovery. Paying buys a decryption key; it does not fix the underlying compromise, and it does not guarantee all data is returned.
How Attacks Get In
The entry point distribution for NZ ransomware incidents:
Phishing leading to credential theft. An employee receives a credential harvesting email — often themed around Microsoft 365, DocuSign, or a financial institution — and enters their username and password on a fake login page. The attacker uses the credential to access the environment, establish persistence, and deploy ransomware days or weeks later. This is the single most common pathway and the one addressed most directly by phishing simulation and MFA.
Exposed RDP. Remote Desktop Protocol exposed to the internet, often on a non-standard port, is brute-forced or exploited using stolen credentials. Many NZ SMEs have legacy RDP exposure from pandemic-era remote access setups that was never properly secured.
Unpatched internet-facing systems. VPN appliances, firewall management interfaces, and web applications with known vulnerabilities are exploited before patches are applied. The gap between vulnerability disclosure and exploitation is now measured in days for the highest-severity vulnerabilities.
Compromised MSP access. Managed service providers with access to multiple client environments are high-value targets. A compromised MSP credential or RMM tool can propagate ransomware across dozens of clients simultaneously.
The First 24 Hours
The first 24 hours of a ransomware incident determine the outcome more than anything that comes after. The steps that matter:
Hour 0-2: Isolate, do not shut down. Isolate affected systems from the network to stop lateral spread. Do not shut affected machines down — forensic evidence in memory may be critical. Pull the network cable or disable the network adapter rather than powering off.
Hour 0-2: Notify. Notify CERT NZ through the reportcyber portal and your cyber insurer. Both have response resources available. The insurer notification window is typically 24-72 hours — check your policy now, before you need it.
Hour 2-6: Assess scope. Identify which systems are encrypted, which are clean, and whether the attacker still has active access. An incident response retainer holder can provide expert help with this assessment. Without expert help, the risk is either under-containing (leaving infected systems online) or over-containing (taking down systems that were clean).
Hour 2-6: Check backups. Can your backups actually be restored? Are they offline and unaffected by the encryption? This is the question that determines whether you need to consider paying. If the answer is yes to both, recovery is possible without paying.
Hour 6-24: Recovery decision. If backups are intact and clean, begin recovery. If backups are compromised, involve your insurer, legal counsel, and an incident response firm before making any payment decision. Payment decisions made under time pressure without expert guidance regularly result in paying and not recovering.
The detailed first-24-hours playbook is in ransomware: what to do in the first 24 hours.
What Stops Ransomware Getting In
The controls that have the highest impact on ransomware prevention:
- Phishing-resistant MFA on all accounts — passkeys or hardware tokens preferred; SMS MFA is better than nothing but interceptable
- No exposed RDP — RDP behind a VPN at minimum; remove direct internet exposure entirely where possible
- Patching within 48 hours for critical internet-facing vulnerabilities
- Phishing simulation and awareness training — most entry points begin with a human clicking something
- EDR on all endpoints — modern endpoint detection tools catch ransomware behaviour patterns before encryption begins
- Offline backups with tested restoration — the recovery option that makes paying unnecessary
The NCSC minimum cyber security standards and CERT NZ critical controls both align on these six. An SME with all six in place is not immune, but is dramatically less likely to become a victim and dramatically more likely to recover without paying.
The Compliance and Insurance Picture
NZ cyber insurance policies now routinely include:
- MFA as a precondition for cover — policies have been voided post-incident when MFA was not in place
- Sub-limits on ransomware claims separate from the main policy limit
- Ransomware response guidance provisions — requiring use of the insurer's incident response panel
- Reporting obligations — most policies require notification within 24-72 hours of discovery
The real cost of a data breach for NZ SMEs covers the financial picture in full, including the components most businesses do not account for until they are in the middle of one.
Practical Takeaway
- Enable MFA on every account — email, cloud services, VPN, administrative access
- Audit for exposed RDP and remove it or put it behind a VPN
- Patch critical internet-facing systems within 48 hours of vulnerability disclosure
- Test backup restoration now — not when you need it
- Store at least one backup copy offline and offline stays that way
- Run phishing simulations quarterly
- Have a one-page incident response plan that includes CERT NZ and insurer contact details
- Check your cyber insurance for ransomware sub-limits and MFA preconditions
Start your free SecureAZ trial to train your team on ransomware awareness and build the phishing defences that address the most common entry point.
External references: