New Zealand’s Security Threat Environment

New Zealand's Security Threat Environment 2026

An assessment by the New Zealand Security Intelligence Service.

04. Insider Threat

More insiders in organisations are causing harm to their organisations and to our national security through actions that are either deliberate, influenced by others or unwitting.

Both public and private sector organisations in New Zealand are vulnerable to harm from insider threat activity such as unauthorised disclosure of sensitive information, theft of intellectual property, process corruption, compromise or misuse of assets, or sabotage.

Foreign states are increasingly targeting insiders for espionage opportunities but sometimes an insider might be motivated by personal reasons or because they have been incentivised or coerced by another third-party.

An “insider” is considered anyone who has, or previously had, access to knowledge of an organisation’s resources. Knowledge may include information about people, processes, information, technology, and facilities that is not accessible to the general public. Very few employees will become an insider threat, but it is an important risk to manage due to the harm that can be caused.

Over the previous 12 months, we have seen instances of deliberate, influenced, and unwitting insider acts.

Deliberate insiders

Deliberate insiders purposely cause harm to their organisation for a variety of reasons. They may have developed a grievance, or the job has not met their expectations. Sometimes the motivation is simply for personal gain.

In many cases, the insider act follows a period where they have been under pressure or have been exhibiting out-of-character behaviour.

Case study

An employee at a government agency had a change in their personal life that started to affect their judgement at work. The person never told their peers or managers what was happening out of fear it would tarnish their image as work was central to their identity.

Their job involved working closely with another agency where they held a position of trust. They did not admit they were under strain and their behaviour eventually culminated in an insider act when they misused privileged access to the other agency’s system for a personal reason.

The breach caused reputational damage to both agencies. A security investigation followed where the individual deliberately hid details of their actions. They were subsequently dismissed from their role. The person’s focus on saving face, and their reticence to ask for help has harmed them personally as well as the two government agencies.

If you notice any of these behaviours or activities, let us know.

18 Influenced insiders

Influenced insiders

Influenced insiders may be coerced or incentivised to cause harm. They might face external pressure from foreign states or criminal entities, or from individuals who wish to harm the New Zealand government or our national security.

NZSIS has seen examples where an insider has been incentivised with a financial reward or the promise of an increase in status.

Vulnerable people can be manipulated by skilled actors to misuse their privileged access as an employee to support a criminal group or foreign state. Such deception can have a wide spectrum of serious consequences, including compromising our national security, degrading a system or capability, eroding trust in New Zealand’s institutions, economic damage, and, in some cases, physical destruction or injury.

Case study

A New Zealander put themselves at risk by advertising their security clearance on their social media profile. This captured the attention of a foreign state actor, who used a cover company to offer them a lucrative contract. The person suspected the recruiter may not be a legitimate employer, but the high salary and attractive job offer incentivised them to continue the recruitment process. The NZSIS worked with their employer to raise awareness of the security concerns it generated and to mitigate the risk.

Unwitting insiders

Unwitting insiders cause harm through negligence, poor practices or naivety. Even though there is no intent to cause harm, the consequences of their actions can be widespread and long-lasting.

Case study

NZSIS investigated an individual working for the New Zealand Government who responded to an online job offer and unknowingly agreed to work on behalf of a foreign state. The person did not tell their employer they were taking on secondary employment and neglected to carry out proper due diligence on the company they agreed to work for. A few simple checks would have identified this was not a legitimate company. Even though they did not mean to, the person shared insights and perspectives that were in part informed by their role in the New Zealand Government. Reckless sharing of such insights can still harm New Zealand’s national security – even if not expressly drawn from classified documents. NZSIS worked with the employer and made sure the individual had advice on how to spot employment traps by foreign states.

Common factors in New Zealand insider threat cases

Generally, no single factor can lead an insider to undertake an insider threat act. Instead, a series of events and pressures can make an insider become more vulnerable.

Examples NZSIS has observed include financial stress, challenges at work, concern about international conflict and global instability, or mental health challenges.

Motivations for undertaking an insider threat act are complex and varied, and can include a combination of disgruntlement, grievance, ambition, financial motivation, complacency, or naivety.

If you notice any of these behaviours or activities, let us know.

Five principles for a shared approach to insider risk

The NZSIS encourages all organisations to develop an insider threat programme both to help identify potential threats early and to support staff who may be vulnerable.

Five principles underpin the advice we provide government agencies and the private sector.

  1. Adopt a shared language

    Definitions encourage consistency and help you understand the harm.

  2. Broaden your understanding of potential insider threats

    What assets need protecting and what could happen to them.

  3. Consider the ‘spectrum of intent’ from unintentional to intentional insider activity

    Develop systems that target all types of insider risk.

  4. Detect signs of insider threat and act to de-escalate

    Signs are often visible, so what are the opportunities to intervene?

  5. Learn the foundations for effective interventions

    Build an effective security culture with measures that shape the environment and limit the opportunities for insider events to take place.

Our guidance, Secure Your Team: Five principles for managing insider risk is available at:

Secure your team [PDF, 1.4 MB]