NZ school principal and IT lead reviewing an incident response checklist on a laptop — first-response playbook for a school cyber incident.

Quick answer

A New Zealand school that suspects a cyber incident — phishing account compromise, ransomware, data exposure, or a third-party tool breach — should act in this order: contain the immediate access, preserve evidence, notify the right internal people, report externally where required, and assess Privacy Act 2020 obligations. The first hour matters far more than the first day. This guide gives principals, school leaders, and IT leads a clear first-response playbook grounded in NZ-primary guidance from CERT NZ, Netsafe, the NCSC, and the Office of the Privacy Commissioner.

What counts as a cyber incident at a school?

A cyber incident is any event that affects the confidentiality, integrity, or availability of a school's information or systems. Common shapes include:

  • a staff or student account has been used to send phishing messages, often to other staff or parents
  • a school account password has been entered into a fake login page, and the attacker is now signed in
  • a laptop, server, or cloud platform has ransomware or other malicious software on it
  • a school file share, learning management system, or student information system has been exposed to the wrong audience
  • a third-party tool the school uses (a learning platform, an assessment tool, an AI service) reports a breach that may include school data
  • a parent or staff member reports that they have paid money to someone impersonating the school

Not every suspicious message is an incident. The threshold for treating something as an incident is reasonable suspicion that a school system, account, or data has actually been affected. If in doubt, treat it as a possible incident early. The cost of starting the response a few hours too early is small; the cost of starting it a day too late is much larger.

First 60 minutes: contain the immediate access

The first goal of incident response is to stop the bleeding, not to understand everything that happened. Practical containment steps in the first hour:

  • if an account is suspected of being compromised, change the password from a device the attacker is not on and force a sign-out of all active sessions where the platform supports it
  • if a phishing message is still arriving in staff inboxes, capture a copy for evidence and then have IT block the sender, the link, or the sending domain at the mail gateway
  • if a school device is suspected of malware or ransomware, disconnect it from the network but leave it powered on so logs and memory state are preserved for analysis
  • if a public link or shared document has been exposed to the wrong audience, revoke access or take the file down
  • if money has been paid under a scam, contact the school's bank immediately and ask whether a recall is possible

Avoid the temptation to wipe a device, delete messages, or change everything at once. Some of that evidence is what the school, CERT NZ, and the Privacy Commissioner will need later [1][2].

A New Zealand school IT coordinator reviewing an incident response checklist during a cyber incident — practical first-response guide for NZ schools.

First 24 hours: preserve evidence and notify internally

Once the immediate access is contained, focus on preserving evidence and alerting the right internal people.

  • write down a short incident timeline while it is fresh: what was noticed, by whom, when, and what has been done so far
  • preserve the original phishing message, the malicious file, the exposed link, or the suspicious log entry — do not just rely on screenshots
  • identify which systems, accounts, or information may have been affected, and which students, whānau, or staff may be involved
  • notify the principal, the school's IT lead, and the board chair or a senior leader with delegated authority. If the school does not have an internal IT lead, the school's managed IT provider is the first external call
  • if a third-party supplier is involved (a learning platform, an SMS provider, an AI tool), open a ticket with them and ask for written confirmation of what happened and what data was involved
  • if the school has cyber insurance, notify the insurer per the policy's incident notification terms. Most policies require notice within a short window

The internal record matters as much as the technical containment. If the school later needs to notify the Privacy Commissioner, support an affected student, or respond to a media enquiry, the timeline is the single most useful document [3][4].

Reporting externally: who to contact in New Zealand

Three New Zealand organisations handle most school incident reports. They have different roles and are usually contacted together.

  • CERT NZ is the government cyber security incident response team. Report incidents with significant impact, including account compromise affecting multiple users, ransomware, data exposure, and financial loss. Reports are confidential and can be made at cert.govt.nz/report. CERT NZ helps with containment, technical advice, and downstream law-enforcement referral [1].
  • Netsafe handles online harm affecting individuals, including scams, impersonation, harassment, and fraud. Schools, staff, and parents can report at netsafe.org.nz. Netsafe is the right first call for incidents where a student or whānau member is the direct target [2].
  • The school's IT provider or IT managed service is the right first call for anything involving school systems, student data, or school-managed accounts. They can reset accounts, pull logs, and check whether the incident extends beyond the single account that was first reported.

For incidents affecting critical infrastructure, essential services, or nationally significant systems, the NCSC operates a separate reporting channel. Most NZ schools will not need this, but if CERT NZ advises escalation, follow their guidance.

Privacy Act 2020 obligations: when does a school have to notify the Privacy Commissioner?

The Privacy Act 2020 applies to every NZ school, including state, integrated, and private schools [3]. A notifiable privacy breach occurs when personal information has been lost or accessed by an unauthorised person, the breach is caused by a failure of the school's security or procedures, and the breach is likely to cause serious harm to an affected individual.

In a school context, that can look like:

  • a staff account compromise that exposed student records, learning support notes, or assessment data
  • a ransomware attack that locked access to a student information system containing personal information
  • a third-party tool breach that included school data — the school may still have a notification obligation even if the breach was on the supplier's side [3][4]
  • a public link or shared document that exposed identifiable information about a student, whānau, or staff member

If any of these apply, the school should use the Privacy Commissioner's privacy tools for agencies to assess the breach and determine whether notification is required. As a working rule, treat the school privacy lead or principal as the decision-maker, and the Privacy Commissioner's tools as the reference rather than relying on the IT provider to make the call. The Privacy in Education — What Teachers and Students Should Check resource covers this in more detail [4].

The school does not need to be certain the breach is notifiable before reporting. Asking the Privacy Commissioner's office for guidance is part of the response, not a sign that the school handled things badly.

Talking to the school community without creating panic

Communicating well during an incident is part of the response. The goal is to give the school community enough information to act on without creating panic, blame, or speculation.

A useful working pattern:

  • tell staff first, in a short written brief that names the incident, the immediate steps, and who to contact
  • tell whānau next, in a calm letter that explains what is known, what is being done, and what they can do at home
  • tell students in age-appropriate language, ideally through the classroom teacher rather than a school-wide notice
  • keep a single point of contact for media or external enquiries, usually the principal or board chair
  • do not speculate publicly about cause or blame while the incident is still being understood [2][4]

Avoid the temptation to say nothing until everything is clear. People fill silence with worse assumptions than the truth, and the school will lose the chance to set the narrative. The Privacy in Education — What Teachers and Students Should Check resource has a parent-letter template that can be adapted for incident communication [4].

Post-incident: review, document, and improve

Once the immediate incident is resolved, a short post-incident review is one of the most valuable things the school can do. It does not need to be long. The review should cover:

  • what happened, in plain language
  • what worked in the response, and what slowed it down
  • whether the right people were notified quickly enough
  • what change would have prevented the incident, or made the response faster
  • what the school will do in the next 30, 60, and 90 days to address those gaps

Share the review with senior leadership and the board. If the school has cyber insurance, the insurer may also want a copy. The most useful output is a small number of concrete changes with named owners and dates, not a long report that sits in a shared drive.

When should a school call in outside help?

Outside help is appropriate when the incident extends beyond the school's own capacity. Common triggers include:

  • ransomware that has affected more than a single device
  • a confirmed data breach involving student or whānau personal information
  • an incident where the school does not have a clear internal owner for the response
  • a financial loss or a scam involving a payment to an attacker
  • an incident that may attract media attention

CERT NZ can advise on whether the school needs incident response support, and the Privacy Commissioner's office can guide the school through breach assessment and notification. For a school without an internal IT lead, the managed IT provider is the first call; for a school with one, CERT NZ and the Privacy Commissioner are the right first external calls.

Build a written incident response plan before the next incident

The cheapest time to write an incident response plan is when the school has not just had an incident. A simple one-page plan that names an incident lead, lists the first containment steps, and gives the phone numbers for CERT NZ, Netsafe, the school's IT provider, and the Privacy Commissioner will save hours during a real event. Test the plan once a year with a short tabletop exercise. The CERT NZ Critical Controls framework is a useful starting point for the technical side, and the Privacy Commissioner's privacy tools for agencies is the starting point for the privacy side [1][3][4].

Knowledge check

Q1A staff member has just realised they entered their school password into a fake Office 365 login page. What is the safest first step?tap to flip
Answer: Change the password from a device the attacker is not on, force a sign-out of all active sessions, and then notify the school's IT lead or managed IT provider. Treat any inbox, sent items, or file activity since the click as potentially exposed [1][4].
Q2A school laptop is showing a ransomware note and the student's assessment files are encrypted. The school is not sure which student files are affected. What is the first action?tap to flip
Answer: Disconnect the device from the network but leave it powered on so logs and memory state are preserved, then call the school's IT provider and CERT NZ. Do not wipe the device or pay any ransom before getting advice [1].
Q3A learning platform the school uses reports a data breach that may include student names and email addresses. Does the school still have a Privacy Act 2020 notification obligation?tap to flip
Answer: Yes. The school is the agency that collected the personal information, so the obligation to assess and notify sits with the school even when the breach happened on the supplier's side. Use the Privacy Commissioner's privacy tools for agencies to assess the breach and decide whether notification is required [3][4].

Sources and references

[1] CERT NZ. (2025). Critical controls for small organisations. https://www.cert.govt.nz/

[2] Netsafe New Zealand. (2025). Reporting online harm. https://www.netsafe.org.nz/

[3] New Zealand. Parliament. (2020). Privacy Act 2020. https://www.legislation.govt.nz/act/public/2020/0031/latest/whole.html

[4] New Zealand. Office of the Privacy Commissioner. (2025). Privacy tools for agencies. https://www.privacy.org.nz/responsibilities/privacy-tools-for-agencies/

[5] New Zealand. National Cyber Security Centre. (2026). Resources for schools and kura. https://www.ncsc.govt.nz/resources/

Key takeaways

  • A cyber incident at an NZ school is any event that affects the confidentiality, integrity, or availability of school information or systems, from a single compromised account to a full ransomware event.
  • First 60 minutes: contain access, preserve evidence, and avoid wiping or resetting everything before the timeline is recorded.
  • First 24 hours: notify the principal, the IT lead, the board chair, and the school's IT provider. Preserve a written timeline as the single most useful incident document.
  • External reporting in New Zealand: CERT NZ for cyber incidents, Netsafe for online harm, and the Privacy Commissioner when personal information is involved.
  • The Privacy Act 2020 can require notification even when the breach happened on a supplier's side — the school remains the agency responsible for the personal information.
  • Bottom line: write the one-page incident response plan now, before the next incident — name an incident lead, list the first containment steps, and pin the CERT NZ, Netsafe, IT provider, and Privacy Commissioner contact details. Pair this with Cyber Security for New Zealand Educators for the prevention side and Privacy in Education — What Teachers and Students Should Check for the privacy decision framework.

For the everyday prevention side, read Cyber Security for New Zealand Educators.

For the privacy decision framework, read Privacy in Education — What Teachers and Students Should Check and Privacy Act 2020 for NZ Schools.

For phishing incidents, use How to Spot Phishing Emails, Scams, and Fake Messages and What To Do When a Student Clicks a Phishing Link.

For the wider public-data picture, read the NZ Schools Cybersecurity 2026 Report and the NZ Cyber Threat Report for Schools.