GovIS · MBIE Wellington

7 Aug 2026 · The Goodie Bag

From compliance to competitive advantage.

Thanks for joining the session. This is the companion page to Chris Hawksworth's GovIS talk on turning your MCSS position into a funded cyber security programme. Everything referenced (the deck, the take-away prompts, and the source material) is in one download below.

Chris Hawksworth · CyberTeam / Speculo

What we covered

MCSS is mandatory data collection. Most agencies stop there.

Viewed the right way (weighted against risk, measured with real metrics, and built into a funded roadmap), the same mandatory return is the core of a business case. You're already required to collect the inputs. The session was about using them.

10

MCSS standards, mandated for NZ government agencies

78

Speculo controls those 10 standards expand into, out of 354

CMM2

the mandated maturity floor (of 5 capability levels)

$500k

proposed penalty under NZ's 2026 critical infrastructure consultation

Four ideas, in the order we covered them.

The spine of the talk. Each part builds on the last: by the end, a compliance return becomes a funded programme.

Part 1 · Assurance

Compliance isn't continuous assurance

Today's MCSS/PSR assurance is an annual, point-in-time self-assessment. With real regulatory teeth arriving for critical infrastructure, an annual snapshot won't be enough for much longer.

Part 2 · Risk

Controls aren't risk, until you weight them

Ten green ticks tells a Chief Executive nothing. Weighted controls, assessed by business unit and aggregated up, turn a checklist into an actual risk position.

Part 3 · Measurement

Qualitative isn't enough: measure it

"We've done the thing" isn't a control. % of assets inventoried, backup success rate, MFA enrolment: every standard reduces to real numbers, and a properly built risk matrix to put them on.

Part 4 · Funding

A funded case beats a filed report

The problem, in their words. The quantified risk position. The funded intervention. That structure is what turns a mandatory return into a business case that actually gets approved.

Assess by business unit, aggregate up. Score urgency and effort, not just yes/no. Measure it. Fund it.

Before you go

What's in the goodie bag.

The full session deck, three take-away prompts you can run yourself with no Speculo login required, and the actual standards documents behind every claim made on stage, so you're never taking our summary on faith. Start with one standard, weight it against one risk, and go from there.

The talk

  • Full session deck (PDF)

Take the skills away

  • Skill 1: Organisation Risk Discovery (prompt)
  • Skill 2: Control Weighting & Target Maturity (prompt)
  • Skill 3: Business Case Conversion (prompt)
  • A guide to running them, and to making them your own

Standards & primary sources

  • NCSC Minimum Cyber Security Standards, guidance PDF 2025 v3
  • PSR Assurance Framework Guidance
  • The full NZISM
One download, everything included
Download the goodie bag (ZIP)

No sign-up required

The frameworks are free. Turning them into a funded programme is the hard part.

MCSS, the PSR framework, and NZISM are all public documents. That's why they're in the bag, not just our summary of them. If the talk landed and you want help going further, let's carry on the conversation.