New Zealand

Attack Surface Management for New Zealand Organisations

New Zealand agencies and their suppliers face a tightening set of expectations. Knowing your internet-facing estate underpins nearly all of them.

What drives attack surface management here

Minimum Cyber Security Standards

The National Cyber Security Centre released the MCSS in 2025 under the Government Chief Information Security Officer mandate: ten standards assessed on a Capability Maturity Model, with the minimum expectation set at CMM2, described as Planned and Tracked. They apply to the 37 agencies mandated under the PSR, with implementation reported through PSR assurance from April 2026. CMM2 wording matters here, because a control has to be planned, owned and actively tracked rather than merely present. That is difficult to claim for assets nobody has inventoried.

Protective Security Requirements and NZISM

The PSR is the protective security policy framework overseen by the NZSIS, covering governance, personnel, information and physical security. The New Zealand Information Security Manual, issued by the NCSC, provides the detailed technical baseline. Agencies routinely pass equivalent expectations to suppliers by contract, so the reach extends well beyond government itself.

Privacy Act 2020

The Privacy Act carries a notifiable privacy breach scheme where a breach has caused, or is likely to cause, serious harm. Exposed storage, forgotten test environments and unauthenticated endpoints are common causes of exactly that kind of breach, and they are usually assets the organisation did not know it still had.

Critical infrastructure reform, still proposed

The Department of the Prime Minister and Cabinet released a discussion document in February 2026 on enhancing the cyber security of New Zealand critical infrastructure, with consultation closing on 19 April 2026 and submissions informing advice to Cabinet. Nothing is law yet. The direction of travel mirrors Australia, so operators building a defensible asset inventory now will not be compressed into a short transition later.

How EASMLens supports these obligations

  • Discovery of the internet-facing estate underpinning MCSS and NZISM control evidence
  • Continuous monitoring rather than a point-in-time snapshot, which suits annual PSR assurance reporting
  • Detection of exposed storage and unauthenticated endpoints before they become notifiable privacy breaches
  • Supplier exposure visibility for organisations contracted to government agencies

EASMLens supports these obligations with discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Does the MCSS apply to us if we are not a government agency?
The standards apply directly to the 37 PSR-mandated agencies. Suppliers to those agencies commonly receive equivalent requirements through contract terms, so check your contracts rather than assuming you fall outside scope.
Is New Zealand introducing a law like Australia’s SOCI Act?
Reform is under active consideration following consultation that closed in April 2026, but no equivalent statute is in force today. Anyone telling you otherwise is overstating the position.
How does attack surface discovery relate to the Privacy Act?
Most notifiable breaches involve data reachable from the internet through a system the organisation had lost track of. Discovery reduces the number of unknown systems holding personal information.