New Zealand organisations have been told to prepare for a significant rise in cyber risk tied to AI-enabled attacks, according to guidance highlighted this month by national broadcaster RNZ. Officials say attackers are already using AI tools to scale phishing campaigns and automate the reconnaissance work that used to require a human analyst manually researching a target — work that AI can now do faster and across far more potential victims at once.

The more pointed part of the warning is about where New Zealand organisations actually stand today, not where AI threats are heading. Cyber officials say many local organisations still lack basic security fundamentals: consistent patching schedules, properly managed access controls, and multi-factor authentication rolled out consistently across their systems. That gap matters because AI-enabled attacks tend to succeed by finding the same old unpatched systems and weak credentials faster and at greater scale, not by exploiting some fundamentally new vulnerability that better basic hygiene wouldn't have already closed.

The guidance echoes a message cybersecurity officials have been repeating internationally as AI hype has intensified: that the priority for most organisations right now should be shoring up fundamentals rather than chasing AI-specific defensive tools before the basics are covered. For New Zealand's mix of small and mid-sized businesses, many of which operate with limited dedicated IT security staff, that framing is meant as a relief as much as a warning — it suggests the highest-leverage response to a more dangerous AI-powered threat landscape is not a complex new AI security product, but finishing work most organisations already know they should have done years ago.

AdvertisementIn-Article