21/08/2026
Standard 5 has never been more important and the stakes in New Zealand just got significantly higher.
The NZ Government's Cyber Security Strategy 2026–2030 is now in effect, introducing:
🔴 Mandatory cybersecurity obligations for businesses holding sensitive data
🔴 Personal director liability of up to $500,000 for a critical breach
🔴 Stricter Privacy Act enforcement and mandatory breach reporting
For financial advisers, the risks are real:
📁 You hold client bank statements, tax records, income details and personal ID
📧 Phishing emails targeting advisers are increasingly sophisticated in 2026
💻 The average cost of a data breach for a NZ SME is now $173,000
⚠️ A serious breach could result in loss of your FAP licence
What Standard 5 requires:
✅ Encrypted, secure, backed-up client file storage
✅ Two-factor authentication on every business tool
✅ A written privacy policy and data breach response plan
✅ Declaring any provider-supplied CRM as an outsourcing arrangement in your regulatory return
✅ Staff training on phishing, password hygiene and device security
💡 Tip: When did you last review your cyber security setup? This week is a good time.
💾 Save this and share it with your team
Standard 6 coming next week.