Skip to content
Government Data Vulnerabilities Linked to Unvetted Third Parties

Government Data Vulnerabilities Linked to Unvetted Third Parties

First seen 22 Mar 2026, 12:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 22, 2026 at 22:28 UTC
  • •Government data is managed by unvetted third parties, increasing cybersecurity risks.
  • •GCSB's delayed response to inquiries about vulnerabilities took six times longer than required.
  • •High reliance on a few vendors poses a risk to service delivery across public sector agencies.

A Treasury report revealed that government data in New Zealand is being managed by unvetted third parties, raising significant cybersecurity concerns. The Government Communications Security Bureau (GCSB) took 120 working days to respond to inquiries about these vulnerabilities, far exceeding the statutory 20 days. Director-general Andrew Clark cited the need for confidentiality regarding incidents and vulnerabilities to maintain trust in reporting. The report highlighted issues such as poor security controls and unpatched software among third-party vendors, with some services being offshored without prior approval. This situation has led to a high reliance on a few vendors, increasing the risk of service disruption across government agencies. The GCSB refused to disclose the identities of the problematic vendors or the agencies that raised alarms, citing commercial implications and confidentiality. The ongoing reliance on cloud services from major US tech companies further complicates the security landscape. As of now, the GCSB is working on digital investment and procurement strategies to address these issues.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 202d ago How this analysis works

Timeline

2025-12-31
Treasury report identifies unvetted third parties managing government data.
2026-03-21
RNZ publishes article on GCSB's delayed response to Treasury report.
2026-03-22
Business Scoop publishes article on GCSB's refusal to disclose vendor identities.

More articles in this cluster (2)