The preparedness paradox
One of the strongest themes in this year’s research is what I would call the preparedness paradox.
Businesses report improvements in several areas of cyber resilience. More organisations have backup and recovery capabilities in place (77%, up from 70% last year). Cyber security remains a business priority (52% of organisations). Awareness of cyber risk continues to rise.
Yet vulnerability perceptions have increased, with 43% of organisations feeling vulnerable, up from 34% last year.
It would be easy to interpret these findings as evidence that cyber security investments are not working. I see it differently. In my experience, organisations often become more aware of risk as they improve their understanding of cyber security.
The further you move beyond basic awareness, the more clearly you begin to understand the complexity of the challenge.
A business that knows little about cyber risk may feel relatively confident because it is unaware of its exposure. A business that has invested time into understanding threats, controls, governance, and recovery planning often develops a more realistic view.
I’ve spoken with organisations that have implemented MFA, strengthened backups and improved staff training, only to feel more daunted by the landscape. Those investments did not make them less secure. As they learned more about cyber risk, they became more aware of how much there was still to do.
In many cases, growing concern may be a sign of maturity, not failure.
In my experience, the organisations asking harder questions about cyber risk are often the same organisations taking practical steps to improve their resilience.
And of course, the two explanations are not mutually exclusive; the rise in perceived vulnerability may reflect both greater awareness and a genuine increase in threat activity.
The messy middle
For me, the most significant signal in the research is not overall concern level. It is the concentration of attacks and impacts among organisations with 20 to 49 employees.
This group sits in a particularly challenging position.
Small businesses often have relatively simple technology environments. Larger organisations typically have dedicated security resources, formal governance structures, and more mature operational controls.
Businesses in the middle frequently have neither advantage.
By the time an organisation reaches 20-49 employees, it has usually accumulated a substantial digital footprint. The business may now depend on multiple cloud platforms, remote workers, suppliers with system access and growing volumes of commercially sensitive or personal information.
As a result, they can find themselves carrying enterprise-level risk with SMB-level resources.
This may help explain why the report identifies this segment as having greater exposure to threats and attacks and more significant business impact when attack occurs. The report doesn’t establish why the group appears to be more affected, but the pattern is consistent with what we observe in the market.
Awareness is growing. Action? Not so much
One encouraging aspect of the research is that most organisations appear to recognise the importance of cyber security. The bigger challenge is maintaining focus and translating that awareness into consistent operational practices.
Interestingly, the report suggests that motivation, rather than capability, remains one of the biggest barriers to implementing basic cyber security controls.
A third of SMEs surveyed were taking no action to upskill staff, and of those who did not report cyber threats or attacks, half said they didn’t see the point. These are different behaviours and both suggest that recognising risk doesn’t translate to actions.
Most organisations already know what good cyber hygiene looks like. The fundamentals have been discussed for years. Strong identity controls, multifactor authentication, patch management, reliable backups, staff awareness training, and incident response planning are well established controls.
The difficulty lies in applying those practices consistently and maintaining them as business changes.
Many SMEs understand that cyber security is a risk to the business, but struggle to allocate time, expertise and budget to address it alongside every other business priority. Cyber security competes with growth initiatives, customer demands, operational priorities, and budget constraints. Security also suffers from a visibility problem. When controls are working the outcome is often that nothing happens making it easier to defer investments until an incident or attack exposes the consequences.
Unfortunately, that approach creates unnecessary risk and turns a manageable risk decision into a recovery exercise.
Cyber security is not simply an IT issue. It is a business resilience issue. Decisions about risk appetite, investment, governance, and operational priorities ultimately sit with leadership teams.
In my experience working with organisations across New Zealand, those making meaningful progress tend to treat security as an ongoing business discipline rather than a technical project.
AI changes the threat, not the fundamentals
While AI dominates SME cyber-security concerns, the controls required to defend against AI-enabled attacks remain largely unchanged.
The AI concern is understandable, as artificial intelligence makes social engineering, phishing, impersonation, and fraud more scalable, convincing, and accessible than ever before.
However, it is important to recognise that the survey measures perceptions of AI-related risk rather than confirmed AI-driven incidents.
While attackers are undoubtedly incorporating AI into their operations, the controls required to defend against these threats have not fundamentally changed.
Organisations still need to focus on:
- Strong identity and access controls
- Multifactor authentication
- Email protection
- Staff awareness and training
- Monitoring and detection capabilities for device and identities
- Verification processes for payments, requests, and sensitive information
AI changes the speed and sophistication of attacks, not the need for cyber security fundamentals. In fact, it makes those fundamentals even more important.
Emerging threats can distract from established risks
The report suggests some SMEs may be paying more attention to emerging threats while becoming less familiar with the threats most likely to affect them, including ransomware, data breaches, and unauthorised access.
Are organisations becoming so focused on emerging threats that they are paying less attention to the attacks that continue to cause the majority of real-world harm?
While the threat landscape evolves, many successful attacks still rely on the same underlying weaknesses: stolen credentials, unpatched systems, poor visibility, human error, and inadequate response planning.
The newest threat is not always the most likely threat.
Maintaining awareness of both emerging and established risks remains critical for long-term resilience.
Progress is real, but exposure is growing
Overall, the findings paint a relatively positive picture of New Zealand SMEs.
- Awareness is increasing.
- Preparedness is improving.
- Businesses appear to be focused on their own security.
These are all signs of progress.
At the same time, attackers are more active, and medium-sized organisations appear to be carrying a disproportionate share of the risk.
The lesson from this year’s tracker is not that SMEs need more fear. It is that they need consistency between what they understand, what they prioritise, and what they do
Cyber resilience is rarely built through a single technology purchase or one-off initiative. It comes from executing the fundamentals over time: strong identity controls such as multifactor authentication and privileged access management, effective patching, reliable backups, continuous monitoring, staff awareness, and regularly tested response plans.
Most New Zealand organisations understand that cyber security matters. The real question now is whether businesses can improve their security posture faster than their exposure grows.
That, more than anything else, will determine their resilience in the years ahead.