The NCSC's 2025 Annual Threat Report: Key Findings
Each year, the National Cyber Security Centre (NCSC) — the government's cyber defence agency operating under the GCSB — publishes a detailed threat landscape report based on incidents reported to its systems and intelligence gathered from its monitoring of nationally significant networks. The 2025 report, covering incidents from the 2024–25 financial year, presents a detailed picture of the threat environment facing businesses and government organisations across the country. The picture it paints is sobering.
Ransomware Remains the Dominant Threat
For the fourth consecutive year, ransomware was identified as the most disruptive threat to businesses with operations here. The NCSC documented a significant increase in incidents where attackers achieved meaningful dwell time inside victim networks before deploying ransomware — often weeks or months — allowing them to exfiltrate sensitive data and map backup systems before encrypting files. This dual-extortion approach, threatening both operational disruption and data publication, substantially increases the pressure on organisations to pay ransoms.
The report notes a concerning shift toward targeting mid-market businesses — those with revenue between $5 million and $50 million — which attackers have identified as having enough revenue to make ransom payments feasible but typically lacking the dedicated security operations of larger enterprises. If your business falls into this category, you are squarely in the crosshairs of the most active ransomware groups.
Business Email Compromise Losses Exceed Ransomware
While ransomware generates headlines, the NCSC report highlights that business email compromise (BEC) continues to cause greater total financial losses than ransomware when measured in dollar terms. BEC attacks — where criminals impersonate executives or suppliers to redirect payments — are harder to detect, require no technical sophistication to execute, and in many cases are not covered by traditional insurance policies. The average BEC loss documented in the 2025 report was substantially higher than in previous years, reflecting increasingly targeted and sophisticated attacks on larger transactions.
Supply Chain Attacks: The Growing Threat
The 2025 report identifies third-party and supply chain attacks as one of the fastest-growing threat vectors. Rather than attacking a well-defended target directly, criminal groups and state-sponsored actors are targeting the software vendors, IT service providers, and managed security providers that service multiple organisations. A single successful compromise of a widely-used software platform or IT provider can provide access to hundreds of client environments simultaneously — as demonstrated by several major incidents affecting NZ organisations in the 2024–25 period.
State-Sponsored Actors: An Elevated Warning
For the first time, the 2025 NCSC report included a specific warning about state-sponsored cyber actors conducting espionage operations against private sector entities beyond the traditional targets of government agencies and critical infrastructure. Professional service firms, technology companies, agricultural businesses, and sectors with involvement in strategically significant supply chains were all cited. The objective in these cases is typically intellectual property theft rather than financial gain — but the business disruption and remediation costs are equally real.
Sectors Most Targeted in 2025
The report identifies the top five targeted sectors as: healthcare (including aged care and allied health), professional services (legal, accounting, consulting), retail and e-commerce, local government, and financial services. Notably, the healthcare and professional services categories both saw significantly increased incident volumes compared to the prior year. The NCSC attributes this to the high value and volume of personal data held in these sectors and the relatively slow adoption of multi-factor authentication across them.
What This Means for Cyber Insurance
Two practical implications flow from the NCSC's 2025 findings. First, the risk of a cyber incident affecting your business is higher than it was 12 months ago — for most sectors, materially so. Second, the nature of attacks has evolved in ways that make the gaps in standard business insurance policies more dangerous: ransomware losses, BEC fraud, and supply chain incident costs are generally not covered by general liability, property, or standard professional indemnity policies.
Cyber insurance that specifically addresses these risks — incident response costs, forensic investigation, business interruption, BEC fraud losses, and third-party liability — has become a core risk management tool rather than an optional extra. Given the NCSC's documented increase in mid-market targeting, businesses that have previously regarded themselves as "too small to be a target" should review that assumption carefully.
About the Author
CyberCover Team is part of the CyberCover team — dedicated to making cyber insurance transparent and accessible for NZ businesses of all sizes.