14 September 2026
Security usually gets talked about as a systems problem, something for the IT team and the firewall to handle. Two reports released this year suggest that thinking is out of date. The National Cyber Security Centre's cyber insights for the second quarter of 2026 and the New Zealand Security Intelligence Service's Security Threat Environment 2026 report point to the same shift: the target has moved from the network to the person.
If you use a work account, a phone, or an inbox, this is about you. Here is what both reports show, and what it means for your everyday habits.
The NCSC data makes the point plainly. Scams and fraud were the most common category of incident this quarter, and this year has seen more New Zealanders reporting that they have been caught by malware scams, where attackers get creative about tricking people into downloading something harmful. (Source: NCSC, Quarter Two Cyber Security Insights 2026)
QR code phishing is spreading too, and it recently turned up on parking meters in Christchurch, sending people to fake sites built to harvest their details. It is a reminder that an attack no longer must arrive as an obvious dodgy email. It can be a sticker on a machine you use without a second thought. (Source: NCSC, Quarter Two Cyber Security Insights 2026)
The NZSIS report shows this is not only about opportunistic scammers. It describes foreign intelligence services targeting people through professional networking sites and online job platforms, posing as consultants or recruiters and offering lucrative work to those with useful access. The offers look legitimate, and people are often encouraged to stay in their current job, so the information keeps flowing. (Source: NZSIS, New Zealand's Security Threat Environment 2026)
It also describes the unwitting insider: someone who causes harm with no ill intent at all. In one case, a person took on a second job without checking who they were really working for, and a few simple checks would have shown the company was not legitimate. An insider, in the report's words, is anyone who has access to information and systems, which means most of us. (Source: NZSIS, New Zealand's Security Threat Environment 2026)
Attackers go where it is easiest, and technical defences have improved. People, on the other hand, are approachable at scale. Across both reports the common thread is the same: the way in is usually a person. An inbox. A login. A moment of trust given to the wrong message, code, or offer.
That is not a comfortable thought, but it comes with an upside. If people are where attacks land, people are also where they can be stopped.
None of this requires being a security expert. A handful of everyday habits make a real difference.
Slow down when a message, request, or QR code is unexpected, especially if it creates urgency. Be sceptical of job offers and recruiters that seem too generous or too eager, particularly if they move the conversation to a private app. Use strong, unique passwords and turn on multi-factor authentication wherever you can, so one stolen password does not open everything. Be careful about advertising your exact role, clearances, or access on public profiles. And if something feels off, say so early, because the unwitting insider in the report simply did not check.
At Manux Solutions, we work with New Zealand organisations to protect the people behind the screens, not just the systems around them.
That means the cybersecurity foundations that catch what slips past, and the awareness that helps everyday users recognise a scam, a suspect QR code, or an approach that is not what it claims to be. The most effective security treats people as the first line of defence, not the weak link.
Both are worth reading in full.
If you want your team to feel confident spotting the threats in these reports rather than fearing them, that is exactly the kind of thing we can help with.
Get in touch with the Manux Solutions team, and we can help your people become the strongest part of your security, not the softest.