CFOtech New Zealand - Technology news for CFOs & financial decision-makers
New Zealand
QBE: Mooted critical infrastructure penalties hint at cyber regulatory future

QBE: Mooted critical infrastructure penalties hint at cyber regulatory future

Fri, 11th Sep 2026 (Today)
Donovan Jackson
DONOVAN JACKSON Interview Editor

The market for cybersecurity insurance is maturing as company directors wise up to the realities of pervasive threats on the one hand, and the regulatory environment coalesces on the other. With New Zealand's incoming Cyber Security Strategy introducing mandatory obligations for some sectors along with severe fines and even personal criminal liabilities, the only question remaining is perhaps why every business at wouldn't at the very least seek advice on adding this type of insurance to the protection portfolio.

That's because while 'critical infrastructure' is necessary on a national scale, the communications and computing infrastructure every business relies on, is no less critical to its own ongoing success.

Miro Dordevich, Head of QBE Insurance's Cyber Portfolio in New Zealand, said that while those penalties certainly sharpen the senses, they are somewhat besides - or alongside - the point, which is adequate protection of essential assets. "Our regulator and privacy commissioner have done a great job of making available the tenets of privacy so any business can see where they stack up against a baseline. It's part of a cooperative undertone which has emerged in terms of building resilience and particularly around critical infrastructure," he said.

While the global cyber insurance market originated in the United States during the late 1990s, New Zealand saw the first stirrings around a decade ago. That does mean cyber insurance is still a relatively new product; providing this cover is challenging, depending as it does on intricate knowledge of a dynamic risk environment that even those in the technology space occasionally come up short against. Like any other business, insurers seek to run profitable operations and getting it wrong can be costly.

Which is also the case for organisations which are increasingly recognising the necessity for insurance as a standard part of their cyber defenses. "When you see a major international hack, it might not be so relatable in New Zealand, but the concern is the same. We have to consider how we are exposed, where are our risks, and how are we building toward a resilient cyber economy. That is the name of the game. And a good part of that is [if hacked] how quickly you bounce back."

Achieving that bounce back, he added, depends on a combination of good governance, sound cybersecurity, and, because there are no guarantees of complete protection, insurance solutions. "It's all hand in hand."

Pointing to the government Cyber Security Strategy 2026–2030 strategy (and noting that QBE Insurance provided a submission in the development of the plan), Dordevich said the framework focuses on approximately 200 to 300 significant entities across sectors including communications and data, defence, energy, finance, health, transport and water and wastewater. "Our submission reiterated that we prefer cooperation over punitive measures, as we are all learning. But we broadly agree that there needs to be a next evolution [of regulation].

"Let's consider things like managing cyber insurance for small businesses and controls that need to be required. That critical infrastructure bill is important because it shows the direction in which we are heading, so whatever shape it takes, it is likely to be the start of a broader conversation."

While legislation is likely to emerge from the Cyber Security Strategy (consultation closed in April), and while regulations bring clarity, no amount of laws prevent a compromise, or are likely to offer relief when a business needs it most.

That's a gap into which insurance neatly fits, as Dordevich explained by using a local example from QBE's claims department. "A client had a large-scale ransom event, where they took personal data, with a demand for a ridiculous amount of money which just kept escalating. The approach as the insurer is multidisciplinary: let's secure the environment and take it from there. While there were negotiations, the client didn't want to pay, and the policy would have responded with either course of action."

He said the affected company, while resting on its processes and IT team, held out. "They said we've got our processes and governance, but we need immediate help from QBE and your incident response partners." And that, he added, brought about a successful resolution getting the company back to work, without rewarding the hackers.

Finally, asked if a $5-million penalty is excessive, Dordevich said that while it is a heavy stick, it should be seen in context. "It is a big number, but look at GDPR fines, at up to 4% of turnover as opposed to a punitive number. There needs to be some type of consequence but look for the words 'gross negligence'. It isn't like this will occur because something just happened to go wrong."

In other words, if you don't like speeding fines, don't drive fast? "Absolutely."