7 October 2026

Hawke's Bay Business News, Profiles and Expert Advice

83% of NZ leaders worry about data risk. Only 35% have a policy for it

One question I encourage boards and business leaders to ask is: what happens if a critical system becomes unavailable tomorrow?

Datacom’s Data & Digital Resilience research surveyed 155 senior business and technology leaders across New Zealand and found 83% are concerned about the risks of storing data offshore or using overseas providers. Yet only 35% have a formal, written policy governing where critical data should be stored and managed.

That gap matters because data resilience is no longer a technical issue sitting solely with IT. As organisations become increasingly dependent on digital platforms, cloud services and AI-enabled systems, it has become a business continuity issue that belongs on the executive agenda and the boardroom table.

Not all data carries the same risk

The starting point is to stop treating data as one single category. For most organisations, some information is far more critical than the rest. It may be intellectual property the business relies on, customer data the organisation has been trusted to protect, employee information, financial records, health information or operational data needed to keep essential services running.

Our research shows New Zealand leaders are particularly concerned about data breaches, foreign government access, compliance risk and service disruption. Many also believe sensitive data, including financial, customer, employee, health and intellectual property data, should remain under New Zealand jurisdiction.

Boards and business leaders need to ask some key questions about their data: which data is critical, where is it stored, who can access it and can we recover it quickly if something goes wrong?

Confidence needs to be tested

Our research also shows most leaders are confident in their organisation’s resilience: 85% said they were confident they could continue operating critical services if offshore cloud access was disrupted and 79% described their backup strategy as mature.

But only 39% had tested disaster recovery in the past six months and 13% said they had never tested their recovery capabilities.

That is a significant gap between confidence and evidence. For business leaders who haven’t recently tested disaster recovery and business continuity plans, my own experience is that there is nothing like taking part in a cyber simulation or outage exercise to focus the mind. One of the most sobering lessons is how long recovery can take, even when many things are done well. In a serious event, restoration may be measured in weeks rather than hours or days.

Once you understand that reality, the focus becomes much broader than whether the technology team has a backup, but instead how the organisation will serve customers, support staff, manage suppliers and make decisions while critical systems are unavailable.

AI raises the stakes

AI is adding another layer to this challenge. As more processes become automated or AI-enabled, organisations need to understand where their AI tools are hosted, where processing occurs, what data is being used and whether critical services could keep operating if a provider, region or connection failed.

Already, 45% of organisations say AI adoption has influenced their data infrastructure and storage decisions over the past 12 months. Among larger organisations, that rises to 71%. At the same time, 43% say legacy systems, fragmented data platforms or unclear governance are slowing safe AI adoption, and only 15% believe their systems and governance are well positioned for AI.

That tells us something important. AI adoption is not just about tools. It depends on trusted data, clear governance and resilient infrastructure.

Where leaders should start

The good news is that there are some clear steps for improving data resilience.

Start by mapping your most critical data and systems. Ask providers direct questions about where data is stored, where AI processing happens, who has access, what laws apply and what happens if a service is disrupted. Then test the recovery plan under realistic conditions.

Data control is no longer a narrow IT issue. It is a business continuity issue, a customer trust issue and, increasingly, a board-level risk issue. Organisations need to test, challenge and strengthen their ability to keep operating and restore access to critical data when disruption hits.

Peter Nelson Managing Director, Datacom New Zealand

www.datacom.com

Delivering solutions that solve today’s problems, and anticipate tomorrow’s challenges. Datacom proudly brings technology and expertise together, delivering innovative IT solutions that help our customers to streamline operations, raise productivity, enhance service delivery and increase customer engagement. Working with a full range of customers, from small start-ups through to government agencies and multinational corporations, we deliver on our promise: Turning the imaginable into reality.

Search

Like Us On Facebook

Recent posts

Verified by MonsterInsights