Georgina Bond
New Zealand law firms are increasingly being targeted by cybercriminals and experts warn that too many are still playing catch-up.
They say the professional services sector sits in the sweet spot for cyber attackers, holding significant sums of money in trust accounts, managing highly sensitive client data that can be sold or used for extortion and depending on trust-based reputations that can be destroyed by a single breach.
Cybercrime industry
The biggest development is the persistence of cyber-criminals and the scale and volume of attacks, says Michael Wallmansberger, who previously led security at ASB and Air New Zealand before co-founding the advisory practice Trust Hound.

Michael Wallmansberger
“Cybercrime is an industry now, it’s not just one solo actor,” he says. “Ten years ago, a business might have faced the odd cyber threat. Today, the chance of being exposed to a cyber threat to compromise your organisation is increasingly high.”
Invoice redirection fraud, where attackers compromise email accounts to manipulate payment instructions, is one of the most common and costly scams. Although most finance teams are alert to invoice scams these days, attackers continue to exploit trust.
“Many still get hit by invoice scams where a cyber attacker has compromised an email conversation by getting into the inbox of one of the parties and used the information they found to establish trust with one party in the transaction, causing them to make a payment to the wrong place,” he says.
“In the case of a family-owned or small-to-medium-sized business, the payments can be large in comparison to the balance sheet or capacity to pay.”
These sorts of scams demonstrate the need for vigilance, investment in email security and strong internal processes to verify payment instructions, Wallmansberger says.
Risk tolerance

Geordie Stewart
Geordie Stewart, chief information security officer at consultancy NSP, says one of the biggest problems for New Zealand companies is mindset. After two decades leading cybersecurity functions for major European organisations, he’s observed New Zealand firms tolerate far higher levels of cyber risk than businesses overseas.
“In Europe, boardroom decisions were driven by data and risk analysis. Here, action is often triggered only by an incident, or the fear of being the last to act,” Stewart says.
“I see businesses carry high levels of risk until something goes wrong, then they overcorrect and spend far more than they needed to.”
This reactive approach has left New Zealand five to 10 years behind international best practice, he says. And in many cases, basic protections such as multi-factor authentication are adopted only because technology vendors have enforced them.
“Your data’s safety may depend on whether the firm you’re dealing with has already had an incident,” Stewart says.
Cyber-attacks are far more common than many businesses realise, he says. “Last year saw a significant rise in attacks on New Zealand businesses and 2025 has already seen that trend accelerate further. For every incident that makes the news, there are 10 more you’ll never hear about.”
Instead of simply locking files for ransom, many criminals now steal sensitive data and threaten to release it. For law firms, this shift is particularly worrying.
“Ransomware disrupts operations, but if confidential client files are stolen and threatened with release, the reputational damage can be irreversible.”
Cyber insurance offers limited protection, he says.
“You can insure your systems and restore operations, but you can’t insure against the loss of client trust. That’s why for law firms we recommend weighting cybersecurity spend towards preventative controls, because it’s reputation that needs protecting.”
Smarter scammers
Social engineering, where cyber attackers exploit predictable human behaviour to bypass security, is becoming increasingly sophisticated, putting frontline staff such as payroll and contact-centre workers at greater risk, Wallmansberger says.
“Social engineering is when a cyber attacker is really good at understanding the way people normally behave and uses that knowledge to get someone to do something that undermines security,” he says.
AI and deepfakes make these scams even harder to detect. “Even if you speak to someone on the telephone, it’s difficult to be sure it is the person you think you are speaking to. The imitations are really good,” he says.
Read about the deepfake experience of TLANZ President Tony Herring here.
The red flags typically include urgency or authority, where attackers may impersonate senior executives to pressure staff. “If you feel that sense of urgency in a request, stop and think twice,” Wallmansberger says.
The basics
“The most effective defences are still the basics,” Wallmansberger says. His top recommendations include:
- Multi-factor authentication, especially for email;
- Regular software updates and secure devices;
- Unique passwords, never reused; and
- Staff training to pause when urgency or authority is used to pressure them.
Stewart says firms need to make “preventative controls” standard practice:
- Multi-Factor Authentication (MFA): Essential for all remote and privileged access. “Attackers probably have a better idea of your staff’s passwords than you do. That’s why logins must be protected by more than just a password and require an extra factor such as a code sent to a phone or access restricted to an approved device,” Stewart says.
- Managed Detection and Response (MDR): 24/7 monitoring to detect and respond to threats.
- Phishing resilience training: Regular exercises to strengthen staff awareness.
- Supply chain due diligence: Ensuring third-party providers do not become back doors into firm systems. “Attackers know the easiest way into a target is often through trusted partners,” Stewart says. “If suppliers have access to your systems or data, or even your buildings, you need to be confident their security measures aren’t creating a back door into your organisation.”
Cybersecurity as business risk
Both experts say cyber risk is not just an IT issue – it’s part of the whole package of business risk.
“For businesses where trust and credibility of the brand is a big component of what makes it successful, a breach can undermine reputation,” Wallmansberger says.
Or as Stewart says: “In today’s threat landscape, it’s not just your systems at risk, it’s your firm’s reputation and once lost, it cannot be insured back.”

0 Comments