sign up log in
Want to go ad-free? Find out how, here.

'This is quite a turbulent time' - NZ's cyber security chief Catriona Robinson on AI, hacks, the country's cyber blind spots and the Five Eyes warning

Technology / news
'This is quite a turbulent time' - NZ's cyber security chief Catriona Robinson on AI, hacks, the country's cyber blind spots and the Five Eyes warning
Head of the National Cyber Security Centre (NCSC) Catriona Robinson.
Head of the National Cyber Security Centre (NCSC) Catriona Robinson. Image source: Mandy Te

Interest.co.nz is unpacking how AI will change your everyday life - the risks, the opportunities, and what to actually expect. Our series brings you the policymakers, experts and industry leaders from New Zealand and overseas.

By Anna Whyte

Earlier this year, the Five Eyes intelligence alliance took a rare step in issuing a joint warning on artificial intelligence (AI), urging action now as the threat Frontier AI poses escalates.

In Wellington, the woman in charge of New Zealand's part of that warning is Catriona Robinson, Deputy Director General Cyber Security, who leads the National Cyber Security Centre (NCSC), which sits in the Government Communications Security Bureau (GCSB).

The judgements of the 2025 Cyber Threat Report make for worrying reading - 'state sponsored actors are actively targeting New Zealand', 'activists are targeting NZ organisations as global conflicts escalate', 'known weaknesses and unpatched vulnerabilities are providing threat actors with easy access.' 

Part of Robinson's job is to guard the Government's most closely held secrets. She's also watching a new kind of problem arrive, cybersecurity threats that can bypass the moat and fortress and walk in the front door.

Robinson spoke to Interest.co.nz about the role the NCSC plays in keeping the public and government's data safe, and how they are preparing for the escalating threat of AI development in cybersecurity.

What is the NCSC?

The cyber security centre is responsible for keeping the government's most secret secrets safe - diplomatic information, military commands, exchange of intelligence - "the stuff that needs really, really strong encryption, we provide that encryption."

They are also responsible for the cybersecurity of the central government and public agencies. And with the Government putting AI in the public service into turbo-drive, keeping the public's private information safe in an increasingly unsafe digital environment is paramount.

"It is a time of turbulence in terms of the development of that technology, and it is moving fast," she says. "We, as regulators in government, are thinking about what it all means. New Zealand is a country which has had a relatively light touch approach to regulation, and we haven't rolled out any regulation on AI specifically yet," Robinson said.

The NCSC have though rolled out 10 minimum cyber security standards that government agencies have to meet, and they've just reported back for the first time. Those measures include knowing what equipment the agencies are using for their information, where it's kept, who is using it, what software is being used, having good governance over cybersecurity, and having response plans if systems get taken over. 

NCSC also runs a Vulnerability Insights Programme, or VIP, where the systems of government agencies and Crown entities are proactively scanned to detect vulnerabilities.

"That gives us a really great system view of what's going on in government. We've got a similar programme. It's old now. It's from 2014, called Cortex, which is a programme that looks for vulnerabilities on the systems of critically significant organisations, so not just government at that point, but critical infrastructure and others.

"We work with telecommunications providers and cyber security vendors. We have a programme called Malware Free Networks, or MFN, which is where we tell them things that we know about threats, and they can use that to scan their own networks, and that keeps New Zealanders safe from threats that they didn't even know because it's happening at the telecoms provider level."

Robinson said they had disrupted more than one billion threats through that programme, and it's getting bigger as more providers are being brought in.

"And then we've got an incident response function. So we don't respond to every cyber incident that gets reported to us because there's far too many. But we triage them, and the really significant ones we will lean in and try to help with the particular expertise that we have, including our access to clever tools and classified information to help investigate and remedy really significant incidents."

They've moved away from the fortress and moat mentality when it comes to cybersecurity and are working towards zero trust architecture; "so that the system knows who you are and what you're doing on the system at all times, and whether you're permitted to do it or not."

"We're working with government agencies on how to build in new cybersecurity approaches that mean that people have to verify who they are more often, even once they're into their own system. Working with the [the Government Digital Delivery Agency, which sits inside the Public Service Commission] on what our ambition is for government in that space, and how we might potentially build one, for use in multiple places, rather than individual chief executives each having to build their own cybersecurity posture, if you like."

Image: Visual Content. Licence: CC BY 2.0.

The basic hacks

The public's private health data was breached twice earlier this year, when Manage My Health faced a largescale privacy breach, followed by the more recent MediMap breach. Even this week the Ministry of Education apologised after a technical breach exposed information, including assessment scores, of almost 300 students.

Robinson described the health breaches as non-sophisticated attacks.

"It reinforces the importance of just doing the cyber basics really well."

Despite prior warnings in the ManageMyHealth case, it raised questions regarding the strength of security and privacy of public data held by third parties, which the government agency has less control over.

"That’s a tricky one, right? And the core responsibility would have sat with the health sector rather than with us."

If government agencies had the ability to require third parties to be scanned by NCSC for vulnerabilities, like departments and Crown entities are, Robinson said it would need to be by consent for a start.

But agencies could put expectations at the contract stage with the third party about minimum cyber security standards that are expected and they could use the NCSC framework, or the New Zealand Information Security Manual (NZISM), which is being updated now to take account new developments in AI.

And the Department of Prime Minister and Cabinet is consulting now on; "being more mandatory about critical infrastructure providers, setting them expectations about cybersecurity that they must meet."

Head of the National Cyber Security Centre (NCSC) Catriona Robinson.

It also raises the question, when the basics aren't even being done well at the expense of the public's private information, how much is the country at risk from more sophisticated AI hacking tools?

The Five Eyes warning

"We, the cyber heads, are concerned enough to have said to all of our five countries, these tools are here now, and they are going to massively amplify the ability of those who mean us harm to do that faster and easier... You won't need necessarily a technical background to be able to use the tools to develop exploits for vulnerabilities," Robinson said.

Robinson was part of the recent Five Eyes warning of AI's rapidly transforming cyber risk, urging leaders to act swiftly to minimise the brunt of attacks.

"It's pretty rare for the five of us to do something like that in that way," she said.

It came about from discussions around Frontier AI tools.

"This has been coming for a while, it didn't come out of nowhere. It was just that suddenly [the tools] were capable of the things that we knew they were going to get to eventually."

Robinson said the agentic AI [autonomous systems that can take and act on instructions] they were worried about - the Mythos, the ChatGPT 5.5 - she sees as an amplifier of human endeavour, rather than being able to do tasks a human couldn't do.

"... but just exponentially faster. For example, it feels like the Anthropic tool, the Mythos tool that we're looking at through Glasswing, can do in a matter of days or weeks what a human might take months or years to do."

New Zealand's part in Project Glasswing

When Anthropic, which runs Claude, first announced their new tool Mythos, it was said to be "so powerful that they were going to withhold it from public release for a while."

"So [they] said, 'this tool, we didn't mean it to, but... it's very good with technical data, which was what it was trained on, and it's very good at chaining different vulnerabilities together to tunnel through and and find big vulnerabilities in systems'. Other tools can do that too. They're as capable as Mythos, but Mythos was, I guess, the first to be talked about publicly," she said.

So Anthropic set up Project Glasswing, inviting some Government departments - including New Zealand - and big industry players to have a go before it was released.

"We're thinking about it in a variety of ways. Number one, can we use it to test New Zealand government-owned code? To use the tool for its power to find vulnerabilities in code that might otherwise take a long time to find, and therefore hopefully fix it," Robinson said.

"But also, what does it mean for a cybersecurity agency like ours to use these really powerful tools. How does it amplify our work, and how might we use it in a [business as usual] sense going forward?"

"And then, and we've already started doing this. what can we tell others about these tools? What advice and guidance can we issue? And so we publish that on our NCSC website for not just government but across industry and across New Zealand's businesses."

The offshore data problem

Then there's data sovereignty, which is an issue for a country like New Zealand where data is being stored offshore and outside local control.

Robinson said when it comes to data sovereignty, the answer is complicated.

"A big agentic AI tool like Claude, for example, will be run on probably a large cloud provider, and that's probably going to be offshore. That's something that our government agencies need to think really hard about before they think about what information they put into those tools."

"But there are other tools that we can use, which we can sandbox if you like - so you may only operate on this information within this extension, within this particular system, and and that gives us more control over where it can go and what data it can access."

"The whole question of AI sovereignty and data sovereignty is a live one for us, and one that we collectively are interested in, more than interested - concerned about," Robinson said.

"The big cloud providers tend to be offshore; they tend to be in Australia, and so we might look at if data is going offshore, how far offshore is it going, and what are the legal frameworks in the countries that New Zealand data is being held."

The next year

As the development of AI has moved data sovereignty, privacy and security issues from technical footnotes to matters of national security, the question now isn't whether governments need to act, but how much they need to act in the next year. 

"Within six to 12 months, the New Zealand government - in particular [NCSC], the Department of Prime Minister and Cabinet, and the Government Digital Delivery Agency - will have got our arms much more around what does this mean for government, what do we need to do next about it?"

"We're having those conversations now. But like I said, this is quite a turbulent time for this technology."

We welcome your comments below. If you are not already registered, please register to comment

Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.