NZ Incident Response Bulletin – July 2026

38th Annual FIRST Conference

Key Takeaway: Our attendance at FIRSTCON26 confirmed that New Zealand is tracking well against international incident response practices. Organisations are adopting current technologies, adapting to emerging threats, and placing greater emphasis on cyber resilience. However, preparedness must continue to evolve as artificial intelligence, identity-based attacks, and cloud environments shift the frontline reality of cyber incidents.

The 38th Annual FIRST Conference was held in Denver in June and brought together approximately 700 cybersecurity professionals from around the world. The conference provided a vital opportunity for incident responders, researchers, government agencies, and cybersecurity leaders to share practical experiences and strengthen trusted international relationships. These cross-border relationships are increasingly critical. A single modern cyber event may involve a cloud provider in one country, infrastructure hosted in another, affected customers across several jurisdictions, and a threat actor operating from elsewhere. Effective response depends not only on technical capability, but on timely information sharing and access to trusted global contacts.

The Dual-Edged Sword of AI in Incident Response

A consistent theme throughout the conference was the growing use of artificial intelligence (AI) by both threat actors and incident defenders.

  • The Threat: AI is allowing threat actors to automate reconnaissance, identify vulnerabilities faster, develop highly convincing phishing content, and increase the speed and scale of attacks.
  • The Defence: Conversely, defenders are leveraging AI to analyse massive volumes of log data, identify malicious patterns, summarise technical evidence, and accelerate investigative workflows.

While these defensive capabilities offer clear benefits, they do not remove the need for experienced human judgement. AI-generated findings must still be verified against underlying forensic evidence – particularly when conclusions support regulatory reporting, legal proceedings, insurance claims, or public communications. Organisations adopting AI-enabled forensic tools must carefully consider how evidence is collected, where data is processed, and whether findings can be independently reproduced.

Shifting Frontiers: Identity and Cloud Evidence

The conference reinforced a clear shift in attacker behaviour: threat actors are increasingly targeting user accounts, session tokens, authentication processes, and administrative workflows rather than relying solely on traditional malware. Once an attacker obtains valid credentials, their activity initially mirrors that of a legitimate user. This fundamentally changes the nature of a forensic investigation. To respond effectively, organisations require immediate access to cloud audit records, authentication logs, privileged access events, endpoint data, and third-party service logs. Without this evidence, determining how an attacker gained access, what information was compromised, and whether the incident has been fully contained becomes exceptionally difficult.

The Vulnerability Bottleneck

FIRST forecasts approximately 66,000 CVE disclosures in 2026. The increase reflects a combination of AI-assisted vulnerability discovery and structural changes in the vulnerability ecosystem, including expanded advisory curation, retrospective CVE assignment and reporting backlogs. However, the number showing strong indicators of near-term exploitation remains comparatively stable, reinforcing the need for risk-based prioritisation.

The Frontline Reality for New Zealand Organisations

Based on our discussions and observations at FIRSTCON26, we know that New Zealand organisations that are mature in their IR program align with current international incident-response practices. Many are actively improving visibility across cloud and identity systems, updating incident response plans, and testing their preparedness through simulations. However, alignment should provide confidence, not complacency. Technology alone does not equal readiness. A security platform has limited value if it is improperly configured, or if an incident response plan is executed by a team that has never practised responding under pressure. To ensure your preparedness is demonstrated through operational reality rather than policy alone, organisations should actively review the following areas:

  • Log Retention & Accessibility: Confirm that critical cloud, identity, and authentication logs are retained for an adequate duration and can be exported in a usable format during a crisis.
  • Vulnerability Governance: Move away from blanket patching cycles and implement risk-based prioritisation that factors in your specific business context.
  • Executive Exercises: Test incident response arrangements not just with IT, but through tabletop simulations involving executives, legal advisers, and communications teams.
  • Evidence-Based Assurance: Ensure you can actively demonstrate that controls are operating, alerts are actively investigated, and backups can be successfully restored under pressure.

We welcome the opportunity to meet with clients to share further insights from FIRSTCON26 and discuss how these developments apply to your cybersecurity, forensic readiness, and incident response programmes.

About the Bulletin:

The NZ Incident Response Bulletin is a monthly high-level executive summary containing some of the most important news articles that have been published on Forensic and Cyber Security matters during the last month. Also included are articles written by Incident Response Solutions, covering topical matters. Each article contains a brief summary and if possible, includes a linked reference on the web for detailed information. The purpose of this resource is to assist Executives in keeping up to date from a high-level perspective with a sample of the latest Forensic and Cyber Security news.

To subscribe or to submit a contribution for an upcoming Bulletin, please either visit https://incidentresponse.co.nz/bulletin or send an email to bulletin@incidentresponse.co.nz with the subject line either “Subscribe”, “Unsubscribe”, or if you think there is something worth reporting, “Contribution”, along with the Webpage or URL in the contents. Access our Privacy Policy.

This Bulletin is prepared for general guidance and does not constitute formal advice. This information should not be relied on without obtaining specific formal advice. We do not make any representation as to the accuracy or completeness of the information contained within this Bulletin. Incident Response Solutions Limited does not accept any liability, responsibility or duty of care for any consequences of you or anyone else acting, or refraining to act, when relying on the information contained in this Bulletin or for any decision based on it.