Sharp on Cyber

Cyber Security Horizon Scanning and Business Resilience Insights for New Zealand Directors

Cyber Insight for NZ Directors

Cyber resilience should now sit on every board agenda, but staying current with this fast moving field is hard. The threat landscape shifts with geopolitics, emerging technologies and regulation, and most of what’s written about it is too technical or too tactical to help boards make decisions.

Sharp on Cyber is intended to close that gap. It gives Kiwi directors and executives regular, plain-English analysis of what’s changing in cyber security, why it matters to your organisation, and what questions you should be asking.

About Me: Sharp on Cyber

I’m Patrick Sharp.  I’ve worked in information technology for almost 30 years, and in cyber security for thirteen. I lead a trans-Tasman cyber security consultancy spanning governance, risk and penetration testing.

I hold an MBA, and am a Certified Information Security Manager (CISM), and Certified Information Security Systems Security Professional (CISSP), which reflect my work at the intersection of technical risk and business strategy. I speak regularly to boards and to the Institute of Directors (IOD) on cyber risk governance, and my work on cyber trends has been published in the NZ Herald, Business Desk, Security Brief and the IOD Boardroom Magazine, and I’ve appear on RNZ Radio and TV1 news.

Some of my articles can be found here:

This site, however, is for you. I will be writing new articles fortnightly to keep you up to date with the latest trends. Subscribe to get them in your inbox.

I’ve deliberately made it independent and not affiliated with my employer, so that you are getting analysis, not sales.

But, is there a need for this?

Staying current with cyber security is hard!

The rate of change in geopolitics, artificial intelligence, legislation and cyber security, means that directors must maintain constant up-to-date awareness.

There are three elements to this, explored in the research below.

Directors usually don’t come from cyber backgrounds

This is not just a New Zealand issue, In April 2026, The Harvard Business Review ran an article called “Boards are Falling Short on Cybersecurity” which expresses concern that boards are now placing greater emphasis on cyber risk but have only marginally improved their ability to mitigate it.

It observes that there are three factors driving this:

  1. Lack of cyber expertise,
  2. Board level conversations about AI ignore cyber security, and
  3. Boards mistake regulatory compliance for security.

Cyber professionals are not good at communicating implications to directors,

While the HBR focused on how Directors are engaging, a survey on CISO-Board Engagement by IANs, Artico and CAP Group  found that reporting to the Board was falling short, particularly in the areas of:

  1. Impact of evolving threats,
  2. AI and emerging tech, and
  3. Cyber business risk assessment.

While tactical updates are sufficient, boards are missing the horizon scanning and emerging threat scenario analysis, and an understanding of the impact on business strategy.

Cyber is complex, deeply technical, and rapidly changing.

Meanwhile, the US National Association for Corporate Directors notes that, unlike financial risk, cyber risk is an “…adversarial, adaptive contest against artificial intelligence-assisted human opponents who change tactics constantly.” They call for appointing a Director with cybersecurity expertise, and for all Board members to improve their understanding and draw from diverse information sources.

So, we have a communication problem between cyber security experts and board members. But, in New Zealand, we have additional complexity. 

NZ has light regulation, limited threat awareness, and scale doesn’t help

NZ legislation is very light touch

NZ is a long way behind the rest of the developed world in Government cyber security capacity and regulation. In September, we are at No. 69 in the National Cyber Security Index – a global index of national cyber security readiness. Our Digital Adoption is very similar to Australia, who is No. 25 on the list, but our Cyber Security Readiness is just below Rwanda.

We’re a small country with limited regulatory capacity, and businesses have not been getting as much support as they need.

But, we’re also a rich, western country, so we are a target!

NZ Companies are small

Many New Zealand companies are too small to employ a cyber security professional, and rely on information technology professionals, or even managed service providers for their cyber updates. Unfortunately, this often results in blind spots, tactical advice, and less business-focused reporting.

These small companies also means Directors have bless opportunities to develop cyber experience. But that is what has inspired me to create this site.

She’ll be right, mate!

Kiwis also have a reputation for self-sufficiency, but we are just not very risk-aware. We live on remote islands; our closest neighbour is friendly and culturally aligned, and we have no geopolitical threats. We have no snakes and just one venomous spider, no dangerous predators. Our businesses are notoriously underinsured.

The 2026 Kordia survey on cyber security demonstrates that about half of all businesses will suffer a cyber attack in the coming year, but there is a prevailing attitude amongst survey respondents that ‘it won’t happen to them’, often with the rationale that they have a smart IT guy.

Unfortunately, directors cannot have that attitude; you’re accountable to shareholders, regulators, insurers, and customers, and regardless of whether Government releases its 2026 Cyber Security Strategy, you need to be doing the right thing and demonstrating that you have acted properly.

Helping you stay up to date

I am regularly asked to present to directors, boards, executives, and their professional groups, on the subject of cyber security, and I am an associate Member of the Institute of Directors New Zealand. This brings me into contact with many NZ directors and I am inspired by their passion and ability. I created this site to help those Directors, to help them keep up to date.

But, an annual refresher and the odd article is not enough.  To maintain a current understanding of the latest trends, directors need a cadence of updates that focus on horizon scanning and business impact.

This site is intended to give you a resource with:

  • Incident Reports: Analysis into the latest incident, and what it means for your business(es), and you as a director,
  • Explainers: Explanations about how cyber works and how it impacts on business risk,
  • Opinions:

I hope it will be good enough to be a reliable anchor for cyber information, but I am here to serve you; so your feedback and your questions are very welcome.  If you submit a question, I will endeavour to explain it in an article; it will be anonymous and as broad as possible to explain the principle and make it relevant to readers. 

There are no bad questions, and others may be seeking the same answer.

Leave a comment

Navigation

About

Sharp on Cyber is an independent newsletter intended to help NZ Directors develop their understanding of cyber security concepts and current events.