9302 (2025). Francisco Hernandez to the Prime Minister
Written Question
Published date: 26 Mar 2025
9302 (2025). Francisco Hernandez to the Prime Minister: Why has DPMC pivoted from disaster-proofing critical infrastructure from natural disasters towards 'managing national security risk, particularly cyber security risks,' and what advice, if any led to this change?
Rt Hon Christopher Luxon: Rather than taking a wide regulatory approach, the Department of the Prime Minister and Cabinet’s policy work on critical infrastructure resilience is now focussed on developing regulatory and non-regulatory options to improve the cyber security of critical infrastructure. As cyber threats continue to escalate, there is an immediate need to support critical infrastructure entities to collectively manage cyber risks.
The Government continues to take a broad approach to strengthening critical infrastructure resilience. Disruption or failure of critical infrastructure, including as a result of a cyber incident, is one of the 33 National Risks government continues to manage under the National Risk and Resilience Framework. This coordinated approach to critical infrastructure resilience includes resilience to natural hazards and disasters, which continues through other important policy programmes such as the emergency management system improvements and the Adaption Framework.