Kordia report shows AI cyberattacks front of mind
AI attacks were cited as a problem by 28 per cent of respondents to the latest Kordia cybersecurity survey.
Cyber risk is a critical governance issue that demands board-level attention. The increasing reliance on digital connectivity has brought new vulnerabilities, and the scale of cybercrime continues to grow. In New Zealand, cyber incidents have resulted in significant financial and reputational harm, making it essential for boards to take a proactive approach.
Boards are under increasing scrutiny to ensure they have the right oversight and response capabilities in place. Regulatory expectations are evolving, with stricter privacy laws, mandatory breach reporting and rising penalties for poor governance. Meanwhile, emerging threats such as AI-driven phishing scams, deepfake impersonation and supply chain vulnerabilities mean organisations need to stay ahead of evolving risks.
The 2025 edition of Cyber Risk: A Practical Guide retains the five core principles that help boards understand and oversee cybersecurity risks effectively. This update includes guidance on managing quantum computing risks, improving resilience against AI-driven threats and strengthening governance over third-party security. It also presents new questions for directors to ask management about cyber risk frameworks, workforce readiness and incident response planning.
There are five core principles for boards in their oversight of cyber risks.
Cybersecurity is not just an IT issue. Boards must view it as an organisation-wide risk that affects strategy, resilience and business continuity.
A strong risk management framework ensures cybersecurity is embedded across the organisation, with clear accountability and reporting structures.
Boards must prioritise cyber risk, build their own cyber literacy and ensure they have access to the right expertise.
Directors need to be aware of evolving privacy laws, regulatory obligations and the legal consequences of cyber incidents.
Boards should work with management to identify which cyber risks to mitigate, accept, transfer, or avoid, ensuring the organisation is prepared for potential attacks.
Boards that take a structured, informed approach to cybersecurity will be better positioned to protect their organisations and maintain stakeholder trust.
For further understanding on why boards need to prioritise cybersecurity and the risks of holding on to private data.