TL;DR
- New NCSC New Zealand research (published ahead of Cyber Smart Week, 5–11 October 2026) found 43% of SMEs now believe they’re vulnerable to a cyber attack, up from 34% a year ago, rising to 59% among businesses with 20 to 49 staff, the group also most likely to have been directly attacked (76% in the past six months).
- Despite that rising awareness, the range of preventative steps SMEs take hasn’t meaningfully changed, and 32% are still doing no staff training or upskilling at all, even as AI-generated scams and deepfakes climb to the fourth most prominent threat category.
- This is exactly the gap KnowBe4, the security awareness training platform ITogether delivers as a partner, is built to close: turning staff from an unmeasured risk into a monitored, coached line of defence.
What the NCSC’s Research Found
The National Cyber Security Centre runs an annual tracker with research agency TRA, surveying IT and operational decision-makers at New Zealand businesses with up to 49 employees, this year’s wave covered 373 respondents. The headline shift is a sharp rise in perceived vulnerability, and it isn’t evenly spread:
| Business size | Believe they’re vulnerable to attack |
| SMEs overall | 43% (up from 34% last year) |
| 6–19 employees | 55% |
| 20–49 employees | 59% |
The direct-attack figures track the same pattern. 76% of businesses with 20 to 49 employees reported a cyber threat or attack in the previous six months, against 53% of SMEs overall, and 44% of those medium-sized businesses said the impact was moderate to severe, financial loss, damaged devices and stress among the reported effects.
Why the 20 to 49 Employee Bracket Is Bearing the Brunt
The NCSC’s own analysis points to a positioning problem rather than bad luck: businesses at this size typically handle meaningfully more customer data, payments and supplier relationships than very small firms, but still lack the dedicated security resourcing available to larger corporates. Growth outpaces security maturity, and the gap in between is where attackers land.
Our reading of this: if your organisation has recently crossed from a handful of staff into the 20 to 49 range, or beyond, this data is a direct signal to revisit your security posture rather than assume last year’s controls still fit this year’s exposure.
AI Is Changing the Threat, Not the Fundamentals
AI-generated scams, deepfakes and more convincing attacks now rank as the fourth most prominent cyber threat category for NZ SMEs. Kevin Moar, Acting Deputy Director-General at the NCSC, was direct about what’s changed and what hasn’t:
“AI is making it easier for cyber criminals to carry out attacks and increase their effectiveness. We’re seeing it used to make scams, phishing attempts and impersonation more sophisticated and convincing, which can make it much harder for people to recognise when something isn’t right. The technology used by criminals continues to evolve, but the fundamentals of good cyber security do not.” — Kevin Moar, NCSC New Zealand
The fundamentals he lists, current software, multi-factor authentication, tested backups and staff who can recognise and respond to threats, are unchanged by AI. What’s changed is how much harder the last one, staff recognition, has become, and how much more that single control now has to carry.
The Training Gap and the Reporting Gap
- 32% of SMEs are taking no action at all to train or upskill staff in cyber security, effectively betting the organisation’s human-layer defence on nothing.
- The range of preventative steps SMEs take overall was broadly unchanged year on year, awareness of risk is rising faster than action against it.
- 68% of SMEs that experienced a cyber threat reported or disclosed it, but almost a third did not.
- Of those that didn’t report, 58% said it wasn’t significant enough and 51% said they didn’t see the point, treating lower-level incidents as isolated events rather than useful intelligence.
Moar’s point on reporting is worth taking at face value: even minor incidents help the NCSC build a clearer national threat picture, and under-reporting doesn’t just limit that visibility, it removes the early warning signs an SME could have used itself.
Introducing KnowBe4: Your Human Firewall
This is squarely the gap KnowBe4 is built to close, and it’s why ITogether partners with them: not as a single training video staff click through once a year, but as an ongoing, measurable programme that treats your people as a monitored line of defence rather than an unmeasured risk.
- Security Awareness Training: role-based, continuously updated training content (KnowBe4’s ModStore added over 200 new modules in 2026 alone) that keeps pace with current scam and social engineering techniques, rather than a static annual module.
- Threat and phishing simulation: realistic, ongoing simulated phishing, vishing and smishing campaigns that measure who actually recognises an attack, not just who completed a course.
- Real-Time Coaching: in-the-moment nudges when risky behaviour happens, shifting security from a once-a-year event to a continuous habit.
- Compliance Training: built-in modules that map training delivery to regulatory and compliance obligations, useful evidence for cyber insurance renewals and, in NZ’s case, standards like the NCSC’s own Minimum Cyber Security Standards.
- Email and collaboration security (Defend, Prevent, PhishER Plus): AI-driven inbound and outbound email protection plus a structured incident response workflow for anything staff report or flag.
- AI Defense Agents (AIDA) and Agent Risk Manager: newer additions addressing a risk most SMEs haven’t considered yet, visibility and governance over their own AI agent usage, not just human staff.
The scale of the platform is part of the case for it:
- Used by more than 70,000 organisations worldwide.
- Risk Score built from 316 real-world indicators across an organisation’s security ecosystem, replacing vague “completion rate” metrics with something a board can actually act on.
- Independent research cited by KnowBe4 found 95% of professionals find AI-powered phishing nearly impossible to spot on sight, underlining why simulation and coaching matter more than a once-a-year policy read.
Key Benefits for Senior Leaders
For a CISO, CIO or business owner deciding whether this is worth prioritising, the senior-level case is straightforward:
- Turns an unmeasured risk into a reported one: a Risk Score and phishing simulation results give leadership an actual number to track quarter on quarter, rather than a training completion tick-box.
- Directly answers the NCSC’s own findings: 32% of NZ SMEs are doing nothing here, closing that gap is a low-cost, high-visibility way to move ahead of a third of the market.
- Supports compliance and insurance conversations: documented, ongoing training evidence is increasingly expected by cyber insurers and referenced in frameworks like the NCSC’s Minimum Cyber Security Standards.
- Reduces the load on IT: as ITogether’s delivery partner engagement, we handle configuration, campaign scheduling and reporting, so this doesn’t become another platform your internal team has to run themselves.
- Addresses the AI-era threat directly: simulation content and coaching are updated as attacker techniques evolve, rather than staff being trained against threats that are already out of date.
ITogether’s Independent Verdict
The NCSC’s data is a useful corrective to a common assumption: that cyber risk scales down with company size. It doesn’t. Businesses in the 20 to 49 employee range are currently the most exposed segment of the NZ SME market, with the data and supplier relationships to make an attack costly, but not yet the dedicated security resourcing to match.
Staff training is the one control in the NCSC’s own list that’s a people problem, not a technology problem, and it’s also the one nearly a third of SMEs are doing nothing about. A platform like KnowBe4, delivered and managed properly, closes that specific gap without requiring an in-house security awareness programme to be built from scratch.
This applies just as directly in the UK, where the same pattern, smaller and mid-sized organisations underestimating exposure relative to larger enterprises, is well established. The NCSC New Zealand data simply gives it hard, current numbers.
👉 Curious what a KnowBe4-based security awareness programme would look like for your team, get in touch.
📞 UK +44 (0) 113 341 0123
📞 NZ +64 (0)9 802 2444
📧 hello@itogether.com
FAQs
What Did the NCSC’s Research Actually Find?
43% of NZ SMEs now believe they’re vulnerable to a cyber attack (up from 34% last year), rising to 59% among businesses with 20 to 49 employees. That same group reported the highest direct attack rate, 76% in the past six months, and 44% of those said the impact was moderate to severe.
Why Are Medium-Sized Businesses (20 to 49 Staff) Most at Risk?
They typically handle more customer data, payments and supplier relationships than very small firms, but haven’t yet built the dedicated security resourcing that larger corporates have. Growth in exposure is outpacing growth in security maturity.
What Is KnowBe4 and What Does It Actually Include?
A security awareness and human risk management platform combining ongoing phishing and social engineering simulation, role-based training content, real-time behavioural coaching, compliance training modules, inbound and outbound email security, and a structured incident response workflow. ITogether delivers it as a managed programme, not a self-serve tool.

0 Comments