Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- Step 1: Contain the incident without destroying evidence
- Step 2: Work out whether personal information is involved
- Step 3: Decide who needs to be notified
- Step 4: Prepare a practical communication plan
- Step 5: Review contracts, insurance, and internal documents
- Step 6: Fix the legal and operational gaps that caused the problem
- Common mistakes SMEs make after a hack
FAQs
- Do all cyber incidents need to be reported in New Zealand?
- What if the breach happened through a software provider or IT contractor?
- Should we tell customers before we know every detail?
- Does ransomware count as a data breach if nothing was obviously stolen?
- What documents should an SME review after a breach?
- Key Takeaways
A cyber incident rarely looks like the movies. For most small and medium businesses, it starts with a strange invoice, a staff member locked out of email, customer complaints about odd messages, or a supplier saying your account details have changed when they have not. The first few hours matter, but many SMEs make the same mistakes. They wait too long to investigate, they delete evidence while trying to fix the problem, or they assume they only need to worry if credit card details were stolen.
That approach can make a bad situation worse. In New Zealand, a hack can trigger privacy obligations, contract issues, insurance questions, customer communications, and urgent decisions about staff access, suppliers, and systems. You may need to assess whether the incident is a notifiable privacy breach, preserve evidence, and explain what happened without misleading customers or overpromising what you can fix.
This guide explains what usually happens after an SME is hacked, what New Zealand businesses need to do first, where owners commonly get caught out, and how to respond in a way that protects the business as well as affected people.
Overview
After a cyber attack, the legal and practical response often runs in parallel. You need to contain the incident, understand what data or systems were affected, work out whether individuals are at risk of serious harm, and decide who needs to be told.
- Confirm what happened, when it started, and which systems, accounts, or devices were affected.
- Preserve records and evidence before resetting accounts or wiping devices.
- Assess whether personal information was involved and whether the breach is likely to cause serious harm under the Privacy Act 2020.
- Consider whether you need to notify the Office of the Privacy Commissioner and affected individuals.
- Check customer, supplier, software, payment processor, and insurer contracts for notification or security obligations.
- Manage internal communications carefully so staff know what to say and what not to say.
- Fix immediate security weaknesses, but do not guess publicly about the scope of the problem before you know the facts.
What Data Breaches in SMEs Means For New Zealand Businesses
For a New Zealand SME, a data breach is not just an IT problem. It can become a privacy issue, a contract issue, a reputation issue, and sometimes a governance issue all at once.
A breach may involve personal information, commercially sensitive information, account credentials, payment details, payroll records, health information, or confidential customer files. Even where the hack seems limited, the knock-on effects can spread across your business quickly. Orders may pause, customer support load may jump, and suppliers may start asking questions before you have clear answers.
What counts as a data breach?
A data breach is broader than stolen data posted online. It generally covers unauthorised access to, disclosure of, alteration of, loss of, or inability to access information.
For SMEs, common examples include:
- a phishing email that gives an attacker access to your Microsoft 365 or Google Workspace account
- ransomware that encrypts files and stops you accessing customer or staff records
- a compromised website form that leaks enquiry details
- an employee sending a spreadsheet to the wrong client
- a cloud storage folder being left publicly accessible
- an attacker changing supplier bank details in email conversations
Some incidents are accidental, some are malicious, and some are a mix of both. The legal response often depends less on how it happened and more on what information was affected and whether people could suffer harm.
The Privacy Act 2020 and notifiable privacy breaches
New Zealand businesses that hold personal information are generally subject to the Privacy Act 2020. If a privacy breach has caused serious harm to an affected person, or is likely to do so, the business usually needs to notify the Office of the Privacy Commissioner and affected individuals as soon as practicable.
Serious harm is not limited to financial loss. It can include identity fraud, humiliation, loss of employment opportunities, physical safety concerns, significant distress, or damage arising from the exposure of sensitive information.
When assessing likely serious harm, businesses often need to look at several factors together, including:
- the type of information involved, such as health details, identity documents, or payroll data
- whether the data was encrypted or otherwise protected
- who has obtained or may obtain the information
- what the recipient is likely to do with it
- how many people are affected
- whether the breach has been contained
This is where founders often get caught. They focus only on whether names and card numbers were leaked, when the actual issue may be payroll details, passport scans, addresses, or email access that could be used for fraud.
Other legal and commercial consequences
A hack may also expose gaps in your contracts, policies, and internal processes. For example, your contracts with enterprise customers may require you to notify them quickly after a security incident. Your software provider agreement may say who is responsible for investigating the event. Your cyber insurer may require prompt notice and specific steps before outside experts are engaged.
You may also need to think about your public statements. If you tell customers that no data was affected before you have checked properly, that can create trust issues and may raise Fair Trading Act concerns if statements are misleading in trade.
For company directors and business owners, the practical point is simple: treat the incident as a business risk issue, not just an IT clean-up job.
When This Issue Comes Up
Most SME data breaches happen during ordinary business activity, not during a dramatic system collapse. The trigger is often a rushed decision, an overlooked setting, or a supplier process that no one checked closely enough.
Common founder and manager moments
These incidents often surface:
- after a staff member clicks a fake login page and email forwarding rules are secretly set up
- when finance teams receive a realistic invoice redirection scam
- after a departing employee keeps access to cloud tools or customer databases
- when customer records are stored in shared folders without proper permissions
- after a website plugin or app integration is left unpatched
- when a lost laptop or phone contains unprotected business information
- during migration to a new CRM, payroll platform, or e-commerce system
These are not just technical slip-ups. They are operational decisions that affect privacy, customer communications, employment processes, and supplier relationships.
Why SMEs are often hit harder than expected
Small businesses sometimes assume they are too small to be targeted. In practice, attackers often prefer SMEs because security settings may be weaker, approval processes are less formal, and one compromised inbox can expose years of customer conversations.
SMEs also tend to have lean teams. The owner may be trying to manage the incident, reassure staff, speak to customers, and keep trading, all while the actual facts are still emerging. That pressure often leads to mistakes such as:
- telling everyone the issue is resolved before an investigation is finished
- failing to document decisions and timelines
- forgetting to review legal obligations in customer or supplier contracts
- not involving the right people early enough, such as IT specialists, management, or legal advisers
- using informal staff messages that later contradict official updates
Incidents involving third-party providers
Many breaches involve outsourced systems. Your business might use a cloud accounting platform, booking software, payroll provider, managed IT support, or e-commerce plugin. If one of those providers is compromised, customers may still look to your business first.
That does not automatically mean you are legally responsible for everything the provider did or failed to do. But it does mean you need to understand your own contractual position, your privacy obligations, and what your privacy policy or customer terms say about data handling.
Before you sign a new software, hosting, or managed services contract, this is worth checking closely. A low-cost provider with vague security commitments can become an expensive problem later.
Practical Steps And Common Mistakes
The best immediate response is structured, calm, and evidence-based. You do not need to know everything on day one, but you do need to make sensible early decisions and keep a clear record.
Step 1: Contain the incident without destroying evidence
Your first goal is to stop the damage spreading. That may mean disabling compromised accounts, forcing password resets, isolating affected devices, pausing certain integrations, or restricting admin access.
At the same time, preserve evidence. A common mistake is wiping devices, deleting emails, or rebuilding systems before anyone has worked out what happened. That can make forensic review much harder and weaken your position with insurers, customers, or regulators.
Document basic facts as they emerge, including:
- when the incident was discovered
- who discovered it
- what systems appear affected
- what immediate actions were taken
- who approved those actions
Step 2: Work out whether personal information is involved
You need to identify what information may have been accessed, lost, altered, or locked up. Do not assume there is no privacy issue because the attacker targeted email or operations rather than a customer database.
Email accounts often contain:
- customer names and contact details
- quoted prices and purchase history
- identity documents sent for onboarding
- employee leave and payroll records
- bank account information
- complaints, disputes, or sensitive personal context
If personal information is involved, assess the likelihood of serious harm under the Privacy Act 2020. That assessment should be reasoned and recorded, even if you conclude that notification is not required.
Step 3: Decide who needs to be notified
If the breach is notifiable, notify the Office of the Privacy Commissioner and affected individuals as soon as practicable. Even where the legal threshold is unclear at first, it is usually better to assess it promptly than to let the issue drift for days while the business hopes the problem will disappear.
Your customer and supplier contracts may also require notice. This is especially common where you process information for another business, provide digital services, or hold client data as part of your service delivery.
Think carefully about the order and wording of notifications. You want to be transparent, but you also want statements to be accurate. A rushed message can create panic or lock you into facts that later turn out to be wrong.
Step 4: Prepare a practical communication plan
Most businesses need separate communications for staff, affected customers, key suppliers, and sometimes the public. Each audience needs different information.
A useful customer notification often covers:
- what happened, in plain English
- what information may have been involved
- what the business has done so far
- what affected people should do next, such as changing passwords or being alert to scams
- how they can contact your business with questions
Do not overstate certainty. If you are still investigating, say so clearly. Avoid promising outcomes you cannot control, such as guaranteeing that no misuse will occur.
Internally, tell staff who is authorised to speak externally. An off-the-cuff reply from a team member can undermine the whole response.
Step 5: Review contracts, insurance, and internal documents
After the immediate response, the next job is to work through the paperwork that governs the incident. This is often where hidden obligations appear.
Key documents to check include:
- customer terms and service agreements
- supplier and technology contracts
- confidentiality obligations
- privacy policies, collection statements, and any data processing agreements
- employment agreements and workplace policies
- cyber insurance or business insurance policies
Your contracts may deal with:
- notification timeframes
- security standards or minimum controls
- limits on liability
- indemnities
- who pays for investigation and remediation
- subcontracting and overseas storage of information
If your current terms are silent or vague, that is a sign to tighten them before the next incident.
Step 6: Fix the legal and operational gaps that caused the problem
The incident response is not finished when passwords are reset. The business should identify what failed and update its documents and processes.
That may include:
- rewriting internal access and device policies
- adding approval controls for payment detail changes
- improving onboarding and offboarding steps for staff
- refreshing privacy notices so they accurately describe how information is handled
- updating customer contracts and supplier agreements
- reviewing data retention practices so old information is not kept longer than needed
For some businesses, this also prompts a broader governance review. If the company has grown quickly, security responsibilities may never have been clearly assigned. A breach exposes that gap fast.
Common mistakes SMEs make after a hack
The pattern is surprisingly consistent. Businesses often create extra risk by reacting informally.
- They treat the issue as purely technical and miss privacy or contract obligations.
- They wait for perfect information before doing anything, instead of making an early, documented assessment.
- They notify too late, or send broad messages without enough factual checking.
- They blame a staff member publicly before the investigation is complete.
- They forget to preserve evidence and lose the ability to confirm what really happened.
- They rely on outdated privacy policies that do not match actual data practices.
- They move on without fixing internal controls, training, and contract wording.
The businesses that recover best usually have one thing in common. They respond in a disciplined way, even if they are still gathering facts.
FAQs
Do all cyber incidents need to be reported in New Zealand?
No. The key privacy question is whether the incident is a notifiable privacy breach, meaning it has caused serious harm or is likely to cause serious harm. Even if notification is not required, you should still assess the incident properly and keep a record of that assessment.
What if the breach happened through a software provider or IT contractor?
You may still have obligations to customers or individuals whose information you hold. Check your contracts, confirm what the provider is doing, and assess whether your own business needs to notify anyone under the Privacy Act 2020 or under commercial agreements.
Should we tell customers before we know every detail?
Sometimes yes, but only after a careful early assessment. If notification is legally required or delay increases the risk to affected people, waiting for perfect certainty can be the wrong call. The message should be accurate about what is known, what is still being investigated, and what steps people should take.
Does ransomware count as a data breach if nothing was obviously stolen?
It can. A data breach is not limited to confirmed exfiltration. If information was accessed, altered, lost, or made unavailable without authority, privacy and contractual issues can still arise.
What documents should an SME review after a breach?
Start with your privacy policy, customer terms, supplier contracts, employment contracts and IT policies, and insurance documents. Those usually contain the practical obligations and risk allocation clauses that matter most after an incident.
Key Takeaways
- A hack affecting an SME is usually more than an IT problem, it can trigger privacy, contract, insurance, and reputation issues at the same time.
- Under New Zealand's Privacy Act 2020, some incidents will be notifiable privacy breaches if serious harm has occurred or is likely.
- The first priorities are to contain the incident, preserve evidence, identify affected information, and record decisions as facts develop.
- Customer, supplier, and technology contracts can impose separate notification or security obligations, so review them early.
- Clear, accurate communications matter. Do not speculate, minimise the issue, or make promises before you know the position.
- After the immediate response, update your contracts, privacy documents, staff processes, and security controls so the same gap does not reopen.
If your business is dealing with data breaches in SMEs and wants help with privacy breach notifications, customer and supplier contract reviews, privacy policy updates, and incident response communications, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







