4 August 2026

These days there are many organisations that hold a considerable amount of information related to individuals – some of it very personal, such as medical records and financial history. In many instances this information is held by a third party supplier, rather than the organisation themselves. Organisations are required by the New Zealand Privacy Act 2020 to implement "reasonable security safeguards" to protect personal information against unauthorised access, loss, or disclosure.

This sensitive data is attractive to cyber criminals as it can be used to extort the companies responsible or the individuals concerned and third party suppliers may be considered an easier target if adequate cyber security controls have not been implemented. As cyber criminals do not need sophisticated techniques to compromise an organisations security, ensuring that fundamental security controls are in place can provide a strong basis for protection from common attacks.

Following a number of cyber security incidents involving third party suppliers earlier this year, NCSC has released cyber security guidance for organisations who use third parties to collect and store information for them.  

Read the guidance here.

This guidance is designed to help organisations implement appropriate controls when working with third party suppliers and is important for most businesses, regardless of size, as supply chain and data held isn’t always related to size. Along with detailing key steps for data protection the guidance also provides questions to consider when working with third party suppliers.

Managing a third party supplier is an ongoing process, and it is important that cyber security is considered right from the beginning of working with them.