Tompkins Wake Hosts GCSB and NCSC on National Cyber Resilience
Tompkins Wake Hosts GCSB and NCSC on National Cyber Resilience
Monday 10 November, 2025
Tompkins Wake was pleased to host the Trans-Tasman Business Circle at its Hamilton office for a briefing on cybersecurity and national resilience. The event was the final session in a national series run by the Business Circle, bringing senior business and government leaders together to discuss the security challenges facing New Zealand organisations.
The principal speaker was Andrew Clark, Director-General of the GCSB. The GCSB sits at the centre of Aotearoa New Zealand's national security and cyber defence framework, and Andrew's remarks gave attendees a rare, direct insight into how the agency views the current threat environment and its role in protecting government and critical national infrastructure.
Andrew was joined by Michael Jagusch, Chief Operating Officer of the National Cyber Security Centre (NCSC), for a panel discussion facilitated by Joshua Alcock (Regional OT Cybersecurity & Threat Intelligence Manager) of Fortinet. The panel explored the evolving threat landscape, the importance of public-private partnership, and the shared responsibility that businesses, government agencies, and critical infrastructure providers carry for strengthening New Zealand's collective cyber defences.
Tompkins Wake thanks Sharron Lloyd and the Trans-Tasman Business Circle for the invitation to partner on this event, and all attendees who contributed questions and perspectives from the floor.

Left: Michael Jagusch (COO NCSB), Jon Calder (CEO Tompkins Wake), Andrew Clarke (Director General GCSB), Joshua Alcock (Fortinet), Sharon Lloyd, CEO Trans Tasman Business Circle Right: Andrew Clarke and Michael Jagusch
Key discussion themes
The GCSB's role in New Zealand's security framework
Andrew Clark outlined the GCSB's function within New Zealand's national security and cyber defence architecture, including how the agency works alongside other government bodies to identify and respond to threats affecting national interests. For business leaders, this framing underscored that state-level threat actors and organised cybercrime groups increasingly target private-sector organisations, not only government systems.
The evolving threat landscape
The panel discussion, informed by NCSC's operational visibility into cyber incidents affecting New Zealand organisations, addressed how the nature and sophistication of cyber threats continue to change. Attendees heard perspectives on the interplay between geopolitical tension, ransomware, and supply chain vulnerabilities, and why no sector should consider itself outside the risk profile.
Partnership and shared responsibility
A recurring theme was that effective cyber defence depends on collaboration between government agencies and the private sector. The NCSC's role in supporting nationally significant organisations, combined with GCSB's broader security mandate, reflects a model in which businesses are expected to actively contribute to, and benefit from, national resilience efforts rather than treating cybersecurity as a purely internal concern.
Governance, not just IT
The floor discussion reinforced a message increasingly heard across the governance community: digital resilience is now a board-level responsibility. Cyber risk sits alongside financial, operational, and reputational risk in board risk registers, and directors are expected to understand their organisation's exposure and oversight arrangements, even where day-to-day management sits with IT and security teams.
Why it matters, by audience
Boards and directors Cyber risk oversight is an increasingly visible aspect of directors' general duties of care and diligence. Boards should be able to demonstrate that they understand their organisation's cyber risk profile, have visibility of incident response arrangements, and receive regular reporting on cybersecurity posture.
Executive and risk teams Organisations should periodically test whether their incident response plans, data breach notification processes, and third-party/supply chain risk assessments remain fit for purpose against a threat landscape that is changing quickly.
Regulated and critical infrastructure entities Entities operating in regulated sectors, or considered nationally significant, should be aware of the NCSC's role in supporting incident response and threat intelligence sharing, and should understand how to engage with the agency when needed.
All organisations Every business, regardless of size, is a potential target. Basic cyber hygiene, staff awareness, and a clear escalation pathway remain the most effective and accessible risk mitigations available.
Actions checklist
- Confirm your board receives regular, plain-English reporting on cybersecurity posture and incident response readiness.
- Review whether your incident response and business continuity plans have been tested within the last 12 months.
- Assess third-party and supply chain cyber risk exposure, particularly for critical service providers.
- Confirm your organisation's understanding of its obligations under the Privacy Act 2020 in the event of a notifiable privacy breach.
- Identify whether your organisation would be considered nationally significant for NCSC engagement purposes, and understand how to make contact if an incident occurs.
Cyber risk oversight is now a standing item for well-governed boards, not a topic to revisit only after an incident. Tompkins Wake's Technology, Privacy and Data Protection team advises boards and executive teams on governance frameworks, incident response planning, and compliance obligations under the Privacy Act 2020.
Tompkins Wake was proud to support the Trans-Tasman Business Circle in hosting this important national conversation.
If you would like to discuss your organisation's cyber governance arrangements, contact one of our Technology & Digital and Privacy and Data Protection experts below
