AFQY | A Few Quiet Yarns
← All newsSecurity

TUANZ wants security by design, not security only for those who can afford it

26 July 2026· AFQY News

TUANZ wants security by design, not security only for those who can afford it

New Zealand has made real gains in cyber security. TUANZ’s argument, in its new Trust and Safety position paper, is that the current model leans too heavily on the people least equipped to carry it: individuals and small businesses. The Tech Users Association wants a more proactive, enforceable approach, built so systems are secure by default.

The paper, released on 30 June 2026 as part of the association’s 2026 policy programme, comes alongside a discussion paper on social media age assurance. It lands against a sobering backdrop. New Zealanders lose an estimated $200 million a year to scams, generative AI is making attacks more personalised and convincing, and many small and medium businesses report they simply are not resilient enough.

TUANZ Chair Paul Littlefair credited the progress so far while warning it is not keeping pace. “New Zealand has made real progress in strengthening its cyber defences. Better coordination through the National Cyber Security Centre (NCSC) and initiatives like Malware Free Networks are delivering results. But the threat environment is evolving quickly, and our response needs to keep pace,” he said.

His central point is about where the burden sits. “Expecting individuals and small businesses to carry the burden of managing these risks is no longer tenable. We need to design systems that are secure by default, not secure only for those with the time, expertise or resources to protect themselves,” he said.

He put it more plainly on the balance of responsibility. “We certainly have the view at the moment that it’s a bit too much of user beware, and the amount of accountability that you have to take as an individual to look after your own safety is probably a little too high at the moment,” Littlefair said.

The paper sets out four moves:

  • Develop an enforceable national cyber security approach, shifting from voluntary guidelines to legislation with mandatory reporting for major attacks.
  • Close the SME gap with “cyber health incentives”, such as tax rebates or grants for essentials like multi-factor authentication and secure cloud backups.
  • Mandate platform and provider accountability, requiring telcos and social media platforms to proactively detect and block fraud and deepfakes.
  • Embed cyber safety as a core life skill, with technology upskilling built into school curricula.

On the harder question of protecting young people online, Littlefair was careful not to reach for easy answers. “This is a complex issue with no simple answers. What matters is that we have a clear, informed national conversation, and that we don’t default to solutions that shift responsibility back onto families without addressing system-level risks,” he said.

He said there should also be a greater focus on education for young people, in the way that financial literacy is being introduced into the curriculum. “Cyber safety is a core life skill. Our children are going to be growing up to be digital natives, and this sort of thing is really important,” he said.

He tied it back to why any of this matters for adoption. “Trust is fundamental to digital adoption. If people don’t feel safe online, they will not fully engage with new technologies, including AI,” he said.

For the tech leaders AFQY is built around, the framing will feel familiar. Security that only works for the well-resourced is not really security at all, and the case TUANZ is making is that the default, not the exception, has to change.