Skip to main content


      Cyber security is rapidly becoming a frontline issue for New Zealand’s water providers. The Government’s 2026 discussion document ‘Enhancing the cyber security of New Zealand’s critical infrastructure system’ signals a clear shift from voluntary guidance to mandatory obligations for critical infrastructure, with water service providers over 25,000 connections likely to face new requirements for incident reporting, formal risk management programmes, and board-level accountability. The proposed regime will enforce minimum cyber security standards, introduce stricter rules for the most critical assets, and enable targeted government intervention in extreme scenarios, marking a move to a far more prescriptive and coordinated system.
       
      At the same time, Local Water Done Well is fundamentally reshaping the sector, driving major changes in operating models, regulation, and investment alongside increased digitalisation and ageing infrastructure. This combination is heightening exposure to cyber risk, as more connected systems expand potential attack pathways while legacy assets remain vulnerable. The result is a narrowing window for action, with water providers needing to embed cyber security into transformation programmes now to manage growing threats, regulatory expectations, and system-wide dependencies.

      Cyber security is only part of the risk picture

      While the proposed regime focuses on cyber risk, there is a danger it becomes a proxy for overall infrastructure resilience and other threats are overlooked. New Zealand’s exposure to natural hazards and recent events like Cyclone Gabrielle show how disruptions can cascade across interconnected systems, reinforcing the need to look beyond cyber alone. There are several key challenges facing the water sector:

      • Ageing technology and operational technology (OT) risk: Many providers rely on legacy control systems not designed for today’s threat environment, with a large proportion nearing end-of-life and becoming increasingly exposed to risk. Integrating new digital tools can further widen security gaps if not carefully managed.
      • Capability and culture gaps: Cyber security has not traditionally been a core capability, leaving organisations without the skills, processes, or mindset to manage risk effectively. Limited resources and reluctance to surface issues can slow progress and increase reliance on external support.
      • Funding and competing priorities: Providers face pressure to fund major upgrades and meet regulatory expectations, making it difficult to prioritise cyber security investment. The benefits of investing are less visible, which has historically led to underinvestment.
      • Fragmentation and interdependence: A more distributed sector makes it harder to maintain consistent standards and share information effectively. At the same time, shared suppliers and tight interdependencies mean a single weak point can have cascading impacts across multiple providers and essential services.

      Lessons from abroad

      New Zealand’s proposed critical infrastructure security approach explicitly builds on Australia’s Security of Critical Infrastructure (SOCI) framework, signalling a similar direction of travel across asset identification, reporting obligations, risk management, and government intervention powers. Australia’s experience since 2018 offers useful, tested lessons for water providers preparing for a more regulated environment.

      Key lessons for New Zealand water providers include:

      • Start early, not at compliance: Australian utilities that prepared ahead of time achieved better outcomes and lower costs than those that delayed. Early alignment to recognised frameworks and proactive gap assessments will reduce the risk of rushed and costly uplift later.
      • Go beyond a tick‑box approach: Treating risk management as a genuine operational tool, rather than a compliance exercise, delivered stronger resilience and better visibility of vulnerabilities. Embedding cyber security into asset management, capital delivery, and emergency planning strengthens both performance and trust.
      • Understand and manage the supply chain: Australian organisations found hidden dependencies when mapping suppliers, particularly across OT systems. New Zealand providers should strengthen oversight of vendors and shared services, ensuring clear accountability for security and incident response.
      • Build a culture of collaboration: Both the SOCI regime and New Zealand proposals emphasise information sharing. Improving transparency, sharing incident insights, and working across sector networks will be critical to lifting resilience at a system level.

      What comes next

      The combined impact of regulatory change and sector transformation means cyber security has become a core governance issue for water providers. Water service provider leadership need to act now by embedding cyber risk into governance frameworks, allocating targeted investment as part of capital programmes, building internal capability and partnerships, and preparing early for likely compliance requirements. Strengthening response and recovery plans is also critical to ensure readiness for real incidents.

      For water sector executives, the call to action is clear: Take stock of your current maturity, prioritise the gaps that matter most, and start integrating cyber security into the decisions you are already making on infrastructure, operations, and transformation. Acting early will reduce risk, avoid costly remediation, and position your organisation as a leader in resilience.

      KPMG works alongside water organisations to take a practical, structured approach to cyber security uplift. We help boards and executives assess current capability, prioritise investment, design fit‑for‑purpose operating models, and embed cyber security into asset management, capital delivery, and governance. If you would like to understand what this means for your organisation and where to start, get in touch with our team to continue the conversation.


      Let’s continue the conversation 

      KPMG works alongside water organisations to take a practical, structured approach to cyber security uplift. We help boards and executives assess current capability, prioritise investment, design fit for purpose operating models, and embed cyber security into asset management, capital delivery, and governance.

      Every organisation’s journey is different. To explore what this means in your context and where to focus first, reach out to our team to continue the conversation.


      Philip Whitmore

      Partner - KPMG Cyber

      KPMG in New Zealand

      Peter Bailey

      Director - KPMG Cyber

      KPMG in New Zealand

      Mair Brooks

      Partner, Infrastructure Advisory – Major Projects and Infrastructure

      KPMG in New Zealand