Urgent Debates — Ransomware Attack—Waikato District Health Board
Thank you, Mr Speaker. I move, That the House take note of a matter of urgent public importance.
Today, we learnt that significant personal information is now available on the dark web. The information I’m referring to is coming from the ransomware cyber-attack that hit the Waikato DHB six weeks ago. The information that can be found on the dark web is patient files, correspondence, and financial information. This is of a huge concern, not only to those people who may be affected but to all New Zealanders who expect a high degree of privacy when it comes to their own personal information, and especially when that information is held by Government departments. This is an ongoing incident that has been occurring for six weeks and it has been labelled as “the biggest cyber-attack in New Zealand history.”
At the first point of the cyber-attack, the Waikato DHB went down. People who had serious cancer scares, people who are undergoing radiation therapy have had to have their treatment moved across New Zealand from the Waikato to Wellington and Tauranga. That is of huge concern not only to those patients who are undergoing serious treatment but to their whole care, for their whānau and their family, who immediately needed to move from their towns, from the care and wraparound support that they had, to a new town to receive their care. But it also is of a huge concern to those near-400,000 New Zealanders who reside in the Waikato, whose information could be at risk and found now online, when they never thought it would. So my thoughts, firstly, go to those people who have been affected—to those people who are undergoing therapy in areas where their family can’t reach out and provide that wraparound support, when they thought they could, in their moments of vulnerability, to those people whose information has been breached. This harm is going to be ongoing for a lot of people.
I think we need to ask, “What is it the Government has been doing, and what should they be doing?” I want to recognise that the Government has put in place a dedicated response team to find out more information about how this cyber-attack was able to happen. The Ministry of Health has also put in place a dedicated response team to see what they could do to improve. But I think we all need to ask the question, “Is there more that the Government could have been doing?” The answer is, simply, “Yes.”
In 2020, we had a review into the district health boards and we looked into their assets. There were some striking points of information that we need to take more note of. It said that the DHBs were lacking vital IT infrastructure, networks, and security. We had “outdated”, “not adequate … to manage increased cyber security issues.” We also had “significant risks to services from a lack of system capacity and resilience.” This should be of huge importance to all New Zealanders, to know that our DHB’s assets were inadequate.
On 30 May, the Ministry of Health reportedly abandoned an effort to secure DHB computer system upgrades, citing budget constraints. Now, the Government also has failed to follow through on its cyber-security strategy. We were supposed to have annual reports on our cyber-security in New Zealand so that we could protect ourselves from cyber-security breaches but, once again, these didn’t happen because of cited budget constraints.
So what are the Government’s priorities when it came to the Budget? The Budget constraints did not stop many, many stupid projects over these last few years, where it could have been prioritising cyber-security. If you think of the $3 billion that we spent on the Provincial Growth Fund, that $3 billion could have helped these budget constraints for the DHBs, for their cyber-security. You know, we’ve put aside a billion dollars for light rail—which everybody knows is going to be a failure—when that money could have gone to cyber-security to protect New Zealanders’ vital private information.
We’ve also had the Government prioritise billions of dollars for “fees-free”, which they themselves admit is a failure. That money could have gone to protect New Zealanders’ private information. Think about all of those things that we could have put aside to fund this vital infrastructure. Now, of course, we have the Minister of Health acknowledging that there are problems with our health system, and so we’ve got a health system reform under way, and we’ve put aside millions to do that, but we’re going and turning up the whole system without asking that question of “How do we make sure that we get the basics right first?” We need to be looking at cyber-security, infrastructure, technology, making sure that our private information held by Government departments is kept secure.
We knew that this could have happened—cyber-security isn’t new. Threats have been happening for years now, and increasing, but the Government didn’t prioritise our needs as New Zealanders. There have been a range of breaches when it comes to cyber-security, where the Government has failed. We had a Reserve Bank breach not that long ago; we’re still looking for more information about what the outcome was on that inquiry. We had the NZX go down in February; we still are looking for more information on what happened there and what the Government’s response will be. This type of crime is increasing, and I want to make this very clear: this is not something that’s come out of the blue: cyber-security threats are increasing around the world, not just in New Zealand. We’ve been seeing this happening in Ireland—their health system went down this year too.
We need to make sure that we don’t erode the trust in Government by not putting in place the priorities, that vital infrastructure that we need to make sure that our information is secure. Because, if you look at a range of priorities that this Government has decided to spend time on, this will be of a huge concern to those people. One example that springs to mind are people who have been told that their private information will be kept on a firearms register because they have access to firearms. Think of that security threat to those people, to think that the New Zealand Government and our health system can’t keep our health information secure when the Government is asking for more access from other people’s information. We need to know—we need that assurance that our information is to be kept private for our own security reasons.
It’s also not good for business confidence. Why would you bring your business here when you know that the Government might not have your back when it comes to cyber-security? You know, there are so many aspects of our society that fail when things go down; it can’t be that we can have an entire DHB that’s set aside to create health systems for an entire population of New Zealand go down. What would happen if our infrastructure—our transport sector—went down and they had a cyber-security attack? We’ve seen it with the Reserve Bank, we’ve seen it with the NZX—it could be that a whole range of our other Government agencies go down because of a cyber-attack. We need to know that the Government is prioritising this area.
So it raises the question of “Well, what could we actually do better?” We need to be making sure that, if we are having a cyber-security strategy, we’re actually reporting on it. The ACT Party would start by making sure that we’re actually writing the annual reports that this Government says it would. We need to be making sure that we’re having a culture of openness and transparency when it comes to the inquiry into how this happened and what we could do better. We need to know, as New Zealanders, that access to that information is made publicly available so other businesses, entities, other areas that work in New Zealand know what went wrong and how they can protect themselves. Because this doesn’t just happen to Government agencies, it happens to small businesses, and some of our large corporates too. We need to know why they were targeted, how they were targeted, and how we can keep our other New Zealand businesses safe.
We, as the ACT Party, believe that we need to have a better IT strategy in New Zealand, in particular for our health system. Our priority there, in the health space, is making sure that we have a national, integrated IT strategy where we are actually having a focus on keeping information safe. So we would tender out to the experts, to people who have expertise in the area of cyber-security and keeping large documents and files of information private. In asking them to do those jobs for us, making sure that we’re setting robust performance standards, including on security issues, this is how we should be looking as a country—not putting in place priorities for spending billions of dollars where we don’t need to, but getting right back to those basics so that New Zealanders know that their information is safe, that they can go about having access to healthcare systems when they need them, that they’re not going to go down. Knowing that we are keeping their information secure, but we’re looking after them first. Thank you.
The member who’s just resumed her seat, Brooke van Velden, is right: in this day and age, cyber-security should not be an afterthought. It is absolutely integral, or it should be absolutely integral, to the design and implementation of information systems, regardless of the enterprise. The bigger the enterprise, the higher the expectation that systems will be well designed, have good architecture, and be able to protect the data that flows through it. Of course, for public organisations that have a public duty to citizens, in some cases who acquire data about individuals because those individuals are compelled to do so, arguably the duty to maintain and to protect the integrity of that data is even greater.
So these are important principles when it comes to the health system. It is important that we have systems, information systems, that protect people’s information, that protect their privacy. We are not immune, and no country and no enterprise is immune, to cyber-attacks, and, indeed, just four days before the ransomware attack on the Waikato District Health Board, a very similar, very comparable, attack took place on the whole of the Irish health system. That system, or the IT systems for the Irish health system, went down and a month later they were still not fully remediated, and it is very comparable to what has happened to just one of our district health boards.
I want to acknowledge the patients and staff whose information was held by the Waikato District Health Board who have now had that information compromised and, we now know, had that information placed on other websites and other platforms now accessible to others around the world. The Waikato District Health Board tell me that they have a system in place so that once they identify the identities of people who have had their information compromised and their privacy breached, a proactive step is taken to contact that person to let them know and, to the best extent possible, to let them know of the nature and extent of the information that has been compromised, and then to work with that person to provide the support that is necessary.
In addition to that, of course, people are entitled to go to the Office of the Privacy Commissioner and exercise their rights under the Privacy Act 2020. One of the things that we did in our previous term in Government was to beef up the Privacy Act and the obligations on information holders to make sure that there are good incentives to afford proper protection. Nevertheless, even with the best protections in the world now, the reality of the world now is that cyber-security—there is no cast-iron guarantee. Cyber-attacks are a reality of the modern-day world, and the expectation is on those stewards of information systems to be taking every possible step, every proportionate and appropriate step, to provide protection to information held by organisations.
The Waikato DHB is still in the process of remediating what has happened. Many systems are back online. Patients were disrupted; their care was disrupted. The staff working for the DHB were clearly disrupted and were put under great pressure in the early days of that system, and actually in the weeks since, reverting to paper-based systems, reverting to more manual systems. But it is pleasing to see that the DHB managed to keep their patient care going. The occupancy rate for the principal Hamilton hospital was kept at around 85 percent—that is pretty standard for that hospital. They managed to continue much of the care that was required, the emergency care and even a large chunk of the elective care. The care for some patients had to be delegated out to other hospitals, to other DHBs. That was naturally a source of inconvenience, but it did mean that care could continue. Now care is gradually being returned to the Waikato DHB, and that includes many of the radiology services that were put out of action, and other services that were interrupted and disrupted are now slowly returning to normal. But there is no question: the Waikato DHB is not back to normal yet.
We have known for some time, and ours would not be the first Government—previous Government would’ve known—that the ongoing need to maintain investment in IT systems is absolutely crucial. What I think is stunning, when the history books come to be written about this time, is just the appalling neglect that the health system suffered under the previous Government. When you look at capital expenditure under the previous Government compared to what we have done, the previous Government scrimped and, frankly, nickelled and dimed capital spending for hospitals. Implementing and upgrading IT systems is a matter of capital spend, and, actually, the DHBs were starved of those resources. If you have a look at two years under the previous Government, no money at all was appropriated for capital spending. No money at all went into upgrading and renewing IT systems in our health sector. That’s how neglectful the previous Government was.
I’m very proud to be part of a Government that has put over $5 billion into capital spending in our health system. There is a major catch-up job to do, and it’s not just buildings. It’s not just the buildings that were neglected and the mental health facilities that were neglected repeatedly year after year by the previous Government; it’s the IT systems as well. Now, we’re in a situation where, across our network of 20 DHBs, we have about 120 different IT platforms operating. Somehow, we’re trying to make sense, and the front-line clinical staff and other staff are trying to make sense, of that cobbled-together network of systems. You talk to those who are on the front line, they turn up to a hospital and they tell you about just the stress that is associated simply with having to skip from one platform to another just to get the job done.
Well, that position is under review, has been for a wee while now, under this Government. That is why we appropriated this year $385 million for a serious upgrade of all of the IT systems across our DHB network. Not because we can start from scratch with a super-duper brand new, kind of, from-the-ground-up IT system for our health system—that would be a phenomenal exercise—but we can do better at upgrading what we’ve got and making what we’ve got, the systems we’ve got, talk to each other so we can get some coherence and coordination when it comes to IT systems across our health sector.
But as part of that, and as the member who has moved this motion and raised this urgent debate identifies, you can’t do that without making sure that cyber-security is woven into every aspect of the upgrade of the system that we now have to embark upon. Security of information is a fundamental foundation and principle of IT systems. It’s no longer an add-on and it can no longer be an afterthought. So the approach we are taking is to make sure that security is embedded in the design of information systems.
As I said, the growing sophistication and just the constancy of cyber-offensive activity is such there will never be a cast-iron guarantee, and, as we know of IT systems, at least of software, no software design is ever complete. It is the best it possibly can be at a point in time, and then it is constantly upgraded, renewed, patched, and repaired when that is necessary to keep it current and, hopefully, to keep it safe. But it is incumbent on system owners, system stewards, to make sure that they are doing the basics every step of the way to keep their systems going and to keep their systems safe and, ultimately, to protect the integrity of those whose data they are holding at any particular point in time.
That’s where we’re going with IT and IT security. It’s where we’re going with systems that have to be installed not only in our health system but across all Government agencies. In fact, we know, of course, that it’s not just public organisations that are victims of and subject to cyber-attacks; it’s private organisations as well. The member who has resumed her seat expresses surprise about some of these things, but the reality is there are plenty of organisations, public and private, who have still not wised up to the threat that cyber-offensive activity now poses here and around the world. The whole nature of information technology now is it doesn’t matter where you are in the world, no one is immune. Those attacks can come from any quarter of the world at any time, and so we must be prepared.
Once the Waikato DHB has remediated their systems, returned to business as usual, then there will be—because there has to be—an appropriate inquiry, an independent inquiry into the state of the system before the ransomware attack, and then the quality of their response to it. At that point, and only at that point, will we have an understanding about the extent to which that system was vulnerable, the extent to which any steps that might have been taken to provide further protection could have been taken, or whether indeed it was a DHB that had done everything expected of it and had met the appropriate standards expected of it.
We have in Government the protective security standards that apply to a whole range of activities, but also including in information technology. Those standards are promulgated throughout the public sector and organisations, and particularly organisations of significance and scale are expected to meet those standards, to comply with those standards, as they run their information systems. Most organisations have, and make sure they have installed, appropriate protective software. But it is, of course, the case that, once installed, those programmes, those platforms, also have to be maintained so that protection is maintained and a standard of protection is maintained throughout.
So whenever we suffer an attack like this, it is always timely to provide appropriate scrutiny to understand what has happened. And I am confident that once the Waikato DHB is back operating as expected, then the thoroughgoing independent inquiry that will need to take place will take place and will give us a very clear picture about what happened, why it happened, and what more could be done. Of course, as we embark on the health reforms and we prepare ourselves for a new entity that will be responsible for all of our hospitals, there will be stuff that we can learn that will apply.
But I might add, for those who worried at the time that “Gee, this was an attack on the Waikato DHB. What if there had been a nationwide organisation in place?”, well, we have nationwide organisations with nationwide systems throughout Government, the ACC, the Ministry of Social Development, and IRD. They’re all large organisations. They are duty bound to make sure that the platforms that they operate have proper protections in place for proper security, because of the extraordinary amount of personal information that they hold. We expect nothing less of every public organisation, and for those organisations holding the most sort of intimate details of our citizenry, then we expect a very high standard to be kept. That’s what we expect of those Government agencies. It’s what we expect of health organisations, public and private, and it is the standard that we must ensure applies and is complied with.
In the health sector, we’ve had major data breaches before. We had the Tū Ora Compass Health breach a couple of years ago, where the details of up to 1 million patients were compromised and an appropriate response was set up in relation to that. Obviously, that organisation, that private organisation, found then that actually you don’t take cyber-security for granted; you actually have to keep at it. That is a lesson that we know is now abroad in the health sector in New Zealand. It’s abroad in the health sector worldwide, thanks to what’s happened in Ireland, and it’ll be once again a reminder that we must always be on our mettle and do the best, because the people who suffer when we get it wrong or when systems get it wrong are citizens who put their faith in organisations to keep their data safe.
This scrutiny is welcome. It is important that this House also understands its role in ensuring that at least public agencies are supported morally and in other ways to make sure that they are maintaining the integrity of their information systems. So we eagerly await the conclusions of the inquiry into the Waikato DHB. We support the Privacy Commissioner in the work that his office will do to support those whose privacy has been breached, and we hope that all people affected by this dreadful action will get the proper support and their minds put at rest about their details.
Thank you, Mr Speaker. I’d like to begin by saying that the Minister’s speech started off, I thought, in some ways as quite a concerted effort in trying to address the issues that were raised by myself and Ms Brooke van Velden on the exposure of personal details on the dark net as a result of the hacking that actually took place, but then he changed tack and decided to actually blame the previous National Government for the failures in the health ministry. I thought he was the Minister of Health now and it was, in fact, the Labour Government who has been in Government for the last almost four years. It seems rather ironic that he actually hasn’t answered anything in relation to the hack or what the Government is doing about it.
So on the day when I found out about the Waikato District Health Board’s massive ransomware attack, there was language that was uttered from my lips that my mother would not be very happy with, nor would my church minister. And then there was a sigh of relief, thinking that had the Government in fact implemented the whole idea of not just having one district health board but one health agency, it wouldn’t have been just the Waikato District Health Board’s reach of about 435,000 people’s information, but it would be 5 million - plus people’s information that would have been hacked. So that was, in a way, a bit of a sigh. And when today I heard the news that the information that was hacked has now been released as a result of us not paying the ransom—and I applaud the Government for not bowing down to the ransom of having to pay for that information, and I totally support that. Having said that, there were a few choice words uttered again today when I saw that it has actually been released, because it is the people living in the Waikato District Health Board’s catchment—whether they actually live in Hamilton or nearby areas—that’ll be rather concerned that not only did the ransomware hacking mean that their surgeries could not go ahead but it is their information about their health, information about their prescriptions, potentially information as to why they saw a particular health provider at the district health board’s mandate that they may not necessarily want made public for the whole world to see.
So I actually asked Minister Dr David Clark about this issue, because, according to the incoming Minister’s briefing, he is, in fact, the Minister responsible and in charge of the cyber-security policy for this Government. And yet he, basically, decided that he wasn’t responsible and said I needed to chase another Minister for that information, and the person who actually rose to his feet and spoke first today from the Government’s side is Minister Andrew Little, and he didn’t seem to have any answers. Considering the fact that cyber-security, even according to the Government, and I quote Dr David Clark from the Estimates hearing, where he actually says there are literally hundreds of thousands, if not more attacks across Government every day—if that is knowledge that the Minister who has responsibility for cyber-security has and is, in fact, aware that it is happening, and he has responsibility over CERT New Zealand as well, why did this Government not boost cyber-security resilience through their Budget process?
Australia did. Australia put in place $1.6 billion, announced this year in their Budget, to deal with cyber-security. Every day, I know members in this House would also be quite aware that we have scams and ransomware and emails that come through our parliamentary system that we have to report as well to say to our ICT people, “Oh, I think this is actually problematic. It is actually a questionable email. I think it’s actually a scam.” And sometimes we actually get, “Congratulations, you spotted a really good one.” I mean, I think it’s ironic that we are being aware, and I think all of us need to be vigilant about the way we deal with ransomware scams and internet—
💬 Hon Scott Simpson: That’s right!
Ha, ha! Thank you, Mr Scott Simpson. I wasn’t expecting that.
But the thing is that some of us are—for me, personally, I am even fearful of clicking any gif that friends actually send through Facebook, for example, or even videos that I am actually being sent through Facebook, or even emails, for fear that it is laden with viruses, laden with scams or ransomware, malware, anything possible.
But the thing is that these criminals who actually attack our Government departments, they know the weaknesses, and they know that when the Minister also says at the Estimates hearing that he hasn’t actually put too much money into this area, they might actually attack some other Government departments—I’m not so sure. But it’s like criminals, when they go out committing their actions, they do it like most of us: when we go to work, we prepare for it, go to select committee, we read our papers. When criminals go out, they prepare for the job that they’re doing. They go there looking for weaknesses. They know that certain Government departments do not update their databases and do not update their malware software or anything. If that is the case, we need to make sure that these Government departments do what they’re supposed to do. Same thing with the Reserve Bank. When the patch was actually given, it never even arrived because they never updated their software. When Waikato District Health Board did not actually update their software, blaming, “Oh, we didn’t have the money.” Hmm, really? I’m not so sure that is, in fact, fact.
All of us need to be aware. What has this Government done to reach out to the public in terms of awareness campaigns about malware? I know CERT New Zealand is actually in charge of that. I think, for what they get in terms of the budget, they do well, but what has this Government done to boost the work that they’re supposed to do? I don’t think it’s actually enough that the Minister says, “We need to keep on building our cyber-security capacity.” Well, I don’t think that Minister or this Government has actually built any cyber-security resilience and capacity when you consider the fact that the digital services area in one Vote—let’s say Vote Internal Affairs—they in fact reduced the budget by $11 million. And the reasoning why they reduced that is because they said, “Oh, they’ve completed the e-invoicing system.” Really? Because they’ve completed the e-invoicing system, they reduced the budget from $55 million to $44 million.
What about the response from the Government, seeing that we’ve actually had the stock exchange, we’ve had the Reserve Bank, we’ve had the Waikato District Health Board, we’ve even had the Health Research Council hacks and cyber-hack breaches that we’ve actually had? Why is the Government not putting their money where their mouth is, saying that they take cyber-security seriously—that the Ministers actually know what they’re talking about, or at least have people who are experts in this field to give them proper advice?
Well, the Waikato District Health Board cyber-security hack means that the people of Waikato, the families, the businesses, are probably very worried now. People who have patients’ blood types—sensitive information about their health is not something that people want the rest of the world to know. These are issues for private consumption only, usually for the person and their medical specialist or the doctor that they actually see. Patient and doctor privilege exists because of that private nature of the reason why people actually go and seek medical help. And when district health boards and Government departments who hold this data get hacked, there should be some responsibility on the Government who actually runs this country, who should have the responsibility to make sure that Government entities like the district health board do their very best to secure that data. Did Waikato District Health Board do that? I don’t think so. Did this Government do it? I don’t think so.
💬 Hon Dr David Clark: Mr Speaker?
💬 DEPUTY SPEAKER: It’s a Green Party call. Teanau Tuiono.
Thank you, Mr Speaker. I just need to take a call in this urgent debate on what happened at Waikato, and, like all the members around the House, I’m deeply concerned about what happened in terms of the ransomware attack.
I actually had to find out what “ransomware” meant; it sounded like “randomware”. When you think about hackers, you think that they just kind of, like, try to find somebody quite random who is vulnerable so that they can attack it. But ransomware, as I understand it, is that they wanted people to pay them money, in terms of the hack that they carried out. I think that’s all the more concerning here, because the place that was hacked was the Waikato District Health Board and it’s related to a hospital—we are talking about people that are patients; personal information in terms of people needing to access surgery, possibly urgent surgery as well: all of their different details. So the fact that this also had been used to put on to the dark web, as well, is, I think, equally disturbing in this case, as well, because these hackers are clearly punching down to the less privileged and the vulnerable in our society. So it is very important that we all take this very seriously in terms of this hack.
It is really concerning that people’s personal information has been leaked online as a result of this attack. And, as I’ve said, it is very important that the House traverses what this means for all of us.
Ransomware and cyber-attacks are something that we need to ensure people in Aotearoa are protected against in a world that is increasingly digitally focused, and there’s a responsibility on Government to keep up to date and review its cyber-security strategies and institutions, particularly in something like healthcare. I hope this is a wake-up call for the Government, but also, in particular, for all of us in terms of the way that we prioritise things.
I do take a different view, as well, that when we continually run down the public sector, and run it down so that even its computer systems are not up to scratch, that also makes us incredibly vulnerable, as well. So making sure that those funding regimes are in place to ensure that that is there so that these hacks don’t happen, I think is also really important, as well.
I think we also have to think about prioritisation, as well. Our intelligence and security agencies need to have a focus on not just the very real threats in our real life but also these cyber-attacks, as well, and ensuring that they are adequately covered, especially given recent issues with focus in the wrong areas. I was just sort of mindful of the royal commission report that came out in terms of what happened down there in Christchurch: that if we are, and if our security services and Government agencies that are responsible for cyber-security are, so fixated on the wrong people—as they were in the case of Christchurch; instead of focusing on white supremacy, they were focusing on Muslim communities, and, previously in the past, on environmental activists and Māori activists as well—then that is the sort of resource that actually could be better used and spent on protecting our vulnerable against a cyber-attack such as this.
I think it is also important for us to not overreach, as well. It is important that we have the best systems in place for our healthcare services—indeed for all of our Government agencies because they are dealing with the privacy of all of our citizens, as well—but it is just important that those things are not in place and put in a place where Government agencies overstep and overreach. But that will require adequate investment in terms of making sure that those databases are solid and secure in each of our Government agencies, as well, and that there is also a very clear line between the privacy of the individual versus the right of the State to actually go about as doing its job.
So this is very concerning, and the Greens join with everybody else around the House about trying to sort this stuff out sooner rather than later. Thank you, Mr Speaker.
Mr Speaker, thank you, and I acknowledge the member Teanau Tuiono. Apologies to him. I was not trying to take his call. I had the wrong information in front of me, and I do want to acknowledge his contribution.
I also, though, do want to start with a few contributions relating to Melissa Lee’s contribution in the debate earlier. The member seems to be confused about the difference between policy and operations, and this is a confusion that she brings to this conversation every time I have engaged in a debate with her where she announces that it is my responsibility as the Minister for the digital economy to be responding to individual cyber-attacks. That’s not quite as she would present it. The Minister for our intelligence services leads responses where they are matters of national concern, and that is, of course, Minister Little. As we saw, he led the debate today, giving useful updates and information on the Waikato situation. So I just want to put that on the record for Melissa Lee, just as she returns to this debate.
The point of possible confusion arises because the Computer Emergency Response Team (CERT) agency, which does have an operational angle and supplies information to smaller enterprises that may not be of a national scale, does fall within my responsibility, and so she will see that at times, I will be answering on behalf of that agency or in relation to matters that it is concerned with, which do have an operational aspect. So I’m just wanting to clarify that and make it clear, and, obviously, the difference between policy and operations is made really clear in an example like the police, where the Minister is responsible, along with colleagues, for setting the direction of the police, but the police do the arresting. There is an important distinction there, I think we could all agree.
The member Melissa Lee also raised the issue of investment and, again, would have the House believe that this Government has not invested in cyber-security, and of course that is plain wrong. We have, to take one example, invested 60 percent more—that’s 60 percent more; six-zero—in the CERT agency that supports businesses and individuals who experience cyber-attacks, and that’s not a small investment. That’s not to say that we won’t need to invest more in coming years.
The member highlights—rightly—the comments I made at select committee about the thousands and thousands and thousands of attacks that happen every day across the public sector and across the private sector in New Zealand, and the real vulnerability. There’s an article in the most recent edition of The Economist which highlights the rapidly escalating threat of ransomware and malware and other malicious uses of the internet, and so we know very well that we will need to invest more in this area in the future. I think nothing could be clearer, at this point.
Now, having said that, of course, what prevents these incidents from happening is often the most simple and fundamental things. We know that there will be an independent inquiry into the Waikato situation. The Minister of Health and the Minister responsible for the intelligence services, Andrew Little, has made clear that once the DHB’s systems have been fully remediated, there will be an independent inquiry to see what can be learnt to prevent cyber-security incidents like this happening in the future. So that is correct. We do want the Waikato DHB to be focused on making sure it is supporting those whose details have been leaked and that it is preserving private information in the situation it finds itself in and is focused on the outcomes for those patients, both in terms of their wellbeing and their privacy as the first priority right now. But, subsequently, there will be a thorough and independent inquiry to learn for the whole system how we can approach these things better.
We also know, of course, that there has been significant investment by this Government in health and in health infrastructure, including, as Minister Little highlighted, the appropriation of $385 million in the most recent Budget to update IT systems across the health sector, and those things are things which cannot be skipped over by Melissa Lee or anybody in this debate. We have found historical under-investment in many, many areas in health, and this is one more. This does present vulnerability, and that is why this Government is investing in making sure that our systems are up to scratch.
As Minister Little also highlighted, no system is ever perfectly secure, because in the next moment a new malicious actor may come on to the scene or a new vulnerability may be found in software or in anti-virus protections. The system that keeps those malicious actors from accessing private information needs to evolve and change, and so patches are applied. It’s very clear that many of our organisations are concerned about this and yet, often, are not acting as they could be or should be, and that is something we want to see changed. Over half of the folk surveyed in a recent SearchNZ survey said that their organisation is concerned about cyber-security, and 46 percent are trying to learn more about keeping their online businesses safe. Only 38 percent believed that their businesses adequately invested in cyber-security, and just 34 percent believed their businesses had put a lot of thought and planning into being cyber-secure. Most concerningly, under half—45 percent—have processes in place to prevent a cyber-attack.
So these kinds of attacks are a real wake-up call to all of us across New Zealand, both as individuals and as businesses, and as institutions of a national significance across the country, because often the way criminals find their way in is through suppliers of services at one level in a complex computer-integrated system, through to a more significant asset further up the system. So that means it’s all of us who carry responsibility.
Now, CERT, as an agency, which is often the public face of cyber-security, publishes a list of 10 critical controls, and I would encourage members and people watching at home to go to cert.govt.nz to dig out this list. It highlights that some of the most simple things are the things that are the best at preventing this kind of attack: patches on software systems, multifactor authentication and verification—a large number of attacks where these simple things have not been done. Providing and using a password manager—giving people the tools to have a strong and unique password, and configuring logging and alerting so that you can see who’s in the system and doing what, securing internet-exposed services where there are things that have drifted and are no longer used within a computer network so that those things are removed from the system if they present a vulnerability. Segmenting systems, testing back-ups, having back-ups ready to go immediately a problem is identified to replace a system, thus reducing costs on the enterprise and protecting the data that is within that system if the system can be switched over to a back-up version very quickly, and, of course, protecting from ransomware and the malicious effects of it, and so on. There is a list of 10 cyber-security critical controls that can be put into place very easily.
The Government, of course, is taking action across the board, and we’ve been clear that we’re going to join the Budapest Convention. We are involved in international cooperation on cyber-crime because these cyber-criminals generally act across borders, and there’s a focus for the cyber-security strategy, including reporting and encouraging reporting of cyber-crime and improving sharing information about cyber-crime.
We do want people to be very clear that they should not pay ransoms when ransomware is put on to a computer network. We know that those that do pay ransoms may well expose themselves to future attacks because they show then a vulnerability and a willingness to cooperate with criminals. They’re likely to find their systems may be targeted again, and there’s no guarantee in any case that they’ll get their data back if they pay a ransom.
We also know that there are other things that people can be doing that I’ve covered that are really sensible and that are sensible steps and that can be easily accessed. So I want everybody watching this at home to think about whether they themselves are cyber-secure and have taken the steps that they can take to protect themselves from the vulnerabilities we’re seeing around the world.
Look, I’m mindful that time is nearly elapsed, and I’m wanting to just give people comfort at home that the Privacy Commissioner is doing the necessary work for the Waikato situation. We are aware that some information stolen from the DHB has made its way on to the internet, and people are being supported—those staff and patients have been reached out to by the DHB. There will be a clear, independent inquiry once the system is back on its feet to make sure we can learn the lessons from this particular incident.
Thank you, Madam Speaker. It is very disappointing to find ourselves in this situation. Without doubt, we can do better with cyber-security. I’m very concerned that it’s been in this Government’s hands that we’ve had some of the biggest cyber-security breaches ever. In fact, part of the problem probably lies right at the very top, because it turns out the Prime Minister has data breached more young people’s data than any other Minister in the past 10 years. It was called Tuia 250—the Prime Minister’s own portfolio, arts, culture and heritage, and what happened there was there was a website inside the ministry that initially was intended to display information; that was its purpose. It was for those who wanted to go on the Tuia 250 waka—you’d be able to upload passports and driver’s licences, and, it turned out, your rifle licence as well. And they didn’t change the permissions from display only to upload, fundamentally, is what happened. Although actually, in the details there, what really happened was there was someone inside the ministry who was advised—this is what the report tells us—that they had a conflict of interest giving the tender documents for that piece of work to someone who they’d worked with, and that was ignored. So there were some very unsatisfactory dealings in that. Regardless, with Tuia 250, the Prime Minister data breached more young people’s data than any other Minister in any Government in the past 10 years. And when you have that from the top, that filters down as a laissez-faire attitude towards cyber-security.
That’s a real shame that might well contribute to where we are here now. We’ve been very, very constructive as an Opposition towards helping bring the Government towards what might be a more cyber-secure environment. When David Clark was the Minister of Health, we were putting this to him—remember, we actually had a spokesperson for data. I was privileged to have that under Bill English. So I was asking David Clark—and I won’t give you the written parliamentary question (WPQ) numbers, but I’ll just read them—is the Minister up to date with cyber-security in his ministry? Does the Minister have any concerns for cyber-security in his ministry? Does the Minister have responsibility for cyber-security in this ministry? Will the Minister take action if DHBs come under cyber-attack; and, if so, how quickly will the Minister act and how will the Minister act? I won’t go through the wide range of answers to these questions, but there were probably 50 to 60 questions which we were putting to the ministry to try and understand—so this would be the end of 2017—what some of the holes might be so that we could help to get a more secure environment so New Zealanders could believe that their information, their data, was secure in Government hands. That was our purpose. We were asking the health Minister: will he update the Prime Minister on his ministry’s cyber-security testing and cyber-security protection? I would think probably 30 to 40 questions. Is the ministry fit for purpose in their data policies? And then there is one WPQ that I posed: how can the Opposition spokesperson for data help the ministry be more cyber-secure? So if you really want to see an episode of collaboration from us to the ministry once we realised that there was a weakness there, there it is right there in a WPQ for anyone to see.
Yet here we are today, finding ourselves with what may be the single biggest cyber-security event in New Zealand—certainly in the Government sector. And we’re all wondering why, when several years ago we were saying to the ministry, what are your backup policies? What is your policy for power down? Questions like: how often do you back up from archive? Now, that might seem like a simple question. So everyone archives to a backup; that’s fine. How many times do we actually bring that archive back into real data to show that it’s worked? Well, a month or so ago—in fact, just after the cyber-attack—I asked Waikato DHB exactly that: when was the last time they did a full restore from archive? And the answer was over a year ago—over a year ago. You need to be doing these sort of restores at least yearly. Major organisations know this. They know that if you’re not actually testing your archive, how do you know that when you need it—and goodness knows we’ve needed it here now—it’s secure? And yet, for Waikato DHB, it was more than a year since they have tested their restore capability from backup.
This would seem like simple stuff. I do want to have a shout-out to the poor folks at Waikato DHB having, in a previous life, been responsible for designing and implementing electronic health records and rolling them out. This is an invidious position to be in. You know, you think about the laboratory results that you need in real time—radiology, even some of your outpatient clinics, when you’re doing or calculating chemotherapy. There’s a large number of attributes that you take into account for how many milligrams, if you like, per kilogram this person needs and a wide range of attributes; that’s all done in a computerised way. I recall my head of division in Boston when we’d go for funding to the head of medicine. Every year, we’d go through this funding cycle. And my mentor, Professor Charles Safran, would say to the head of medicine, “Our department—the informatics department—can kill more people more quickly than any surgeon could in this hospital. All we’ve got to do is mess around with the oncology formulas, all we’ve got to do is give faulty information—not through our own choosing, but if we mess up the IT, we will kill more people in this hospital than any other mechanism.” Needless to say, we usually got the funding we were asking for after we had that sort of conversation. But I make my point how critical information technology and informatics is in a hospital system.
I think there are a number of questions that Waikato DHB need to answer. We were very interested, had the DHB actually asked, because the media was sort of saying—look, they’d asked for IT funding, and it hadn’t been approved. So I posed that in a WBQ: what IT system upgrades or purchases, if any, have been requested by Waikato DHB in the past five years? And the information came back, there actually weren’t a lot. So it didn’t look like Waikato DHB had actually put their hand up to a lot of information technology. There’s some questions we’ve got around public cloud workloads software at Waikato DHB. Why has it been reported at almost certain risk, with severe impact? How do we explain that? The ISCV, the IntelliSpace Cardiovascular software, had been reported as a highly probable risk, with severe impact. What was being done about that? The data warehouse upgrade at Waikato DHB in the past 12 months had been reported as a possible risk, with significant impact. Who kept their eye on that ball? The “cat 3-5 off shelf applications workplan 16_7” at Waikato DHB had been reported as highly probable risk, with severe impact. Who was watching that? And so it goes on and on across a number of applications. Who was watching that at Waikato DHB?
And when they needed to do the migration from Windows 10, what they had done, which was correct, was they closed down their external perimeter so that if you had a personal email and you went out to Outlook or Gmail, you couldn’t get across the external perimeter. But because they were struggling with the migration to Windows 10, they actually relaxed that external perimeter. I’m really hoping that if this was a phishing attack and it did come across the Waikato DHB external firewall, it didn’t come across when those relaxations were in place.
So we have a number of questions that we want to pose to Waikato DHB. We understand that they will have a review process, or an inquiry, however that may be. But what we really need to do—and I think this is not just symptomatic of the health sector, which I have maybe a closer view of, but across all of Government—can I strongly encourage several things. I’ve always been of a view that cyber-security reporting should stand right alongside workplace safety reporting as a direct report, to a board, every quarter, just like we report workplace health and safety. It is that important. Remember, we can only be attacked in four ways: air, land, sea, and cyber, and we need to elevate the importance of cyber-security across all of Government. We have some expertise; we’d be happy to collaborate with Government to get this right. Certainly, anything we can do to help Waikato DHB fix their problem any way we can, just reach out, and we’ll do that. But we have to lift our collective level of responsiveness and funding to cyber-security across all of the Government sector.
Can I just comment that the $385 million that’s been touted in the Budget, very little of that’s for cyber-security. I challenge the Minister to say how much of that is for cyber-security. It’s for the national health information platform. If you really dig down into the Budget documents, that’s where the money’s going. Oh, and by the way, in the same breath can we maybe have an explanation why the National Oracle Solution failed under this Government and they handed it to the Ministry of Health, despite Treasury saying, “Don’t do that. They’re not capable. They don’t have capacity to do that.”? So it’s a wider story. I want capacity in the Ministry of Health, I want that higher level of security, and I want that lifted right up to the chief executive level, and I think if we do that, we might be starting to get close to really giving some credence and some support to cyber-security. Thank you, Madam Speaker.
I call Jamie Strange—five minutes.
Thank you, Madam Speaker; I appreciate the opportunity to take a five-minute call. As the member of Parliament for Hamilton East, hopefully I can add something of a local context to this debate. But before I drill down to that local aspect, I do just want to touch on a few of the comments I have heard before in this debate, and just reiterate a few things. The first one is that we live in a connected world, which has benefits for our country—you know, we are a small country, so the benefits are obvious in terms of that connectivity—but at times it obviously creates challenges and it makes us vulnerable, at various times.
Last month, the Waikato DHB experienced a ransomware attack, and, as has been previously reported, some information was stolen and has made its way on to the internet. As we’ve heard, the aspect around CERT—and I do want to highlight the work that CERT are doing, because with me wearing another hat as the chair of the Economic Development, Science and Innovation Committee, we recently had a briefing from CERT—in fact, it was about two to three months ago—and it was a fascinating and also worrying briefing that we received from them. As the Minister David Clark has previously noted, there are hundreds, and, at times, thousands of attacks per day on our country. In fact, just as an example, before I came to the House today, someone sent me something via Facebook Messenger. It was clearly some sort of attack—obviously I didn’t click on it, but if I didn’t know that, then I would have clicked on it.
You know, there are thousands of attacks taking place. We are not immune—we are just as vulnerable as any other country—so it’s important that we do have appropriate systems in place. Now, the Waikato DHB, obviously, experienced this attack, and it’s been incredibly disruptive on the services, the fantastic services, that they provide.
In terms of drilling down to a local level, I had the opportunity to visit the DHB; it was around a week after the attack. I was able to walk through some of the wards and speak with some of the staff. Before I talk about this aspect, I’d like to begin by thanking the staff wholeheartedly for the work that they have been doing up there at the Waikato DHB, whether it’s in Hamilton hospital, which is the one I visited, or other hospitals out in the surrounding towns. A lot of people won’t realise, but staff have moved from a completely digital platform to a manual platform, particularly during those early days, which is when I visited. So they went back to things like printing the labels for the medicines and the specimens by hand, and writing on them. They had notepads and pens, pencils. They had whiteboards. They went from computerised to manual. It’s almost like going back sort of 30, 40, 50 years. However, you’ve got the manual system, but obviously a lot more patients than we had 30 to 50 years ago. So the staff had to do many, many extra hours in order to be able to cope, and obviously there were challenges around when you get tired, when it’s easy to make a mistake. The problem is, you know, if you’re handwriting a label, if you accidentally make one mistake, it can have quite serious consequences, as we heard from the Hon Shane Reti.
The staff have done an amazing job in terms of the problem solving. We do know now that a number of the systems are back up and running, which is helping, but there is still a lot of extra work that is being done by their staff. If you fast-forward to just recently, just a matter of a few days ago, I was speaking to some patients who had just been into the Waikato DHB, and they had some minor surgery done, and they said that it all went well, that the staff were relatively confident and, actually, relatively comfortable. However, that’s just one area of the DHB, and I know that other areas, other aspects—you know, they’re at different stages depending on their reliance on digital technologies. I know there are still challenges in the ED and other departments, and as a Government, I know the Ministry of Health are continuing to support that.
There’s ongoing discussions around various forms of IT services—you know, whether it’s hardware, computer systems, or whether it’s the cloud. Those discussions will no doubt continue, and the inquiry that’s undertaken will certainly be important in terms of policy discussions moving forward. Thank you.
Simon Watts—a five-minute call.
I rise on behalf of National as the MP for North Shore to speak on the urgent debate in regards to private information being released from the ransomware attack at Waikato District Health Board. I must say this is a national security incident and deserves the appropriate focus that we have simply not heard from that side of the House so far today. This is an attack on Kiwis—people who live in Hamilton, in Cambridge, in Thames, and Tokoroa, and Te Kūiti, and in Taumarunui—and what this needs is a high degree of urgency and focus in order to deal with the issue.
What we heard from before, from Minister Little, was basically a normalisation of this event happening—it’s happening here and there around the world—and blaming the previous Government for inaction. Well, I’m sorry, Minister, you’ve had four years in that role and have not delivered the solutions required to mitigate this risk. We are spending nearly half a billion dollars on restructuring costs of the reforms that you’re implementing—$486 million—none of that is going in terms of the cyber-security improvements within our DHBs. You note around $385 million going into IT. I questioned you on 9 June at select committee in regards to that, and the answer is that money is not all going into cyber-security. So I think you need to be up front with Kiwis out there. We need a comprehensive digital infrastructure programme, and it is simply not good enough for some of our Ministers to stand up here and, basically, give a speech around updating your passwords and sort of a basic thing when we are dealing with organisations that are under significant pressure.
This incident has shown us—and has had—a significant impact on our healthcare system. Emergency department staff, elective surgery, outpatient clinics, diagnostics, radiology were all significantly impacted by this incident and are still not back to normal levels. I’ve had conversations with staff who were working on the ground at that DHB. They are recording information on paper and they have noted that in some areas, it may take up to two years for that information to be put back into the systems. That is simply not good enough in a country like New Zealand, which should aspire to be one of the best in the world in this area.
Our front-line healthcare staff are under immense pressure. We are hearing daily of the significant issues that our nursing staff across this country are having in regards to workload and dealing with the issues of health vacancies. At Waikato DHB alone, there are 942 vacancies at that district health board. There are 453 vacancies for nurses. There are 159 vacancies for allied health. There are 180 back-office staff vacancies. There are 125 medical vacancies. There are 25 support vacancies. Those are vacancies that are distracting from the delivery of front-line healthcare services, and this incident has only made that situation worse. The challenge and the issue that we are not talking about but needs to be spoken about is that all these issues will lead to adverse patient outcomes and patient events. That is going to be impacting our most vulnerable people within the communities that I talked about today. And they deserve a voice from this Parliament in terms of ensuring that this issue is dealt with.
Not only are there issues within the healthcare system in the Waikato, we are also seeing a health system across the board that is at breaking point. And, again, this Government has had four long years to start to put in place the mitigations in order to fix this issue but they have not done that, as proven by this. The ambulance service here, Wellington Free Ambulance—WorkSafe have put them on notice. Fatigue is a key issue. Within our aged-care sector, their front-line registered nurses are being poached by district health boards because the workforce pot is not being increased. And lastly, we’re dealing with a vaccination roll-out that is putting more pressure on our workforce because we’re trying to do a whole lot of things, but we’re not actually doing anything well.
Lastly, the costs of this incident are significant for this country, not only disruption but also productivity. And as we all know, those two factors, sadly, lead to adverse patient outcomes. And that is going to be the cost paid by all Kiwis as a result of this incident.
Madam Speaker, as a worker in a district health board, I’ve been trusted with the personal information of thousands of New Zealanders—information on their illness, their family situation, the investigations that they’ve had. Some of that information is particularly sensitive. I was an infectious diseases doctor, and some of the information we collect in our histories of patients tell details of their sex life, of their drug use, many things people wouldn’t want shared publicly. Sometimes, it is that particularly sensitive information that harms people when their privacy is breached, but sometimes it’s not even that—it’s the very fact that you were in hospital that you do not want to have known. The information we have, when we provide care to people, is extensive now, because of the large amount of information that can be stored and collected in modern information systems—it is still personal, and patients rightfully expect for it to be protected when they come to hospitals.
I want to acknowledge the patients in Waikato DHB affected by this cyber-attack. They came to the district health board because they were ill and they sought care. They expected to have their privacy respected. I imagine this event is very upsetting for many people. I take heart in the fact that the DHB is reaching out to the patients, notifying them whenever they hear of the information being shared by these criminals, as it has been in some cases, and working with the Privacy Commissioner to make sure that the people affected are treated well. There is also a 24/7 helpline available for people who have been affected by the cyber-attack. I also want to acknowledge the staff, some of whom are my former colleagues. I know they are working hard, working with paper-based systems, and yet despite the challenges to work around the fact that IT systems are either compromised or are being built back in a slightly different way, they have none the less got elective surgery at full capacity, and they have got their outpatients at full service. Congratulations to the staff of Waikato DHB for their excellent efforts in that regard. I know they are working hard, and it must be stressful. I want to thank them so much for their efforts in continuing to provide these services.
Waikato DHB is working to remediate the effects of this cyber-attack, and bringing many of its foundational systems back online. Initial concerns about the treatment of cancer patients have been addressed, and the radiation therapy is also back online. Urgent breast-screening is occurring because of mobile units being brought into Waikato DHB. The DHB is working closely with the Government Communications Security Bureau to make sure that this attack is ameliorated and responded to.
But the point I want to make is that this attack occurs in the context of a long period of under-investment in district health board information technology. Let me tell you a little bit about my experience as a consultant physician in the DHB system. On a regular day, I could interact with at least 20 information systems. There was the emergency department system that contains the patient’s triage data; the x-ray system, where we would look up x-rays; the clinical information system that might contain the clinical notes, sometimes—they’re often also on paper—as well as investigation results. That system had patchy linkage to primary care data, so it was hard to know, if your patient was too unwell to tell you what medicines they were on, what their general practitioner had prescribed them, which creates a risk, obviously, in terms of safe prescriptions of medicines. We had no system for electronic ordering within the hospital, and a patchy one for outpatients. Vital signs were measured by electronic monitoring systems, but this was not captured in any sort of data system that might, for example, allow us to identify deteriorating patients early. That’s not to mention the hundreds of bespoke systems that clinicians set up in order to get particular parts of their work done—for example, the systems to make sure that kidney patients were monitored adequately, or the type of system described by Dr Reti earlier for calculating chemotherapy doses. In other words, after decades of under-investment, we have a patchwork of IT systems in the health system that are, in many cases, old, and as a result of under-investment they can cease to be serviced, in some cases, by their provider, which does create a cyber-security risk.
During my time in Government, I’ve come to learn of this problem in much wider context. In my area of responsibility for public health, for example, contact tracing and information technology systems have been developed by this Government, linking up 20 systems across the country, some sometimes run on software like Excel, for managing case contacts. We’ve invested in that system, and you’ll note that the very fact that we can trace 2,600 from one case results from us having an integrated system across the entire country. We have an out-of-date system for breast cancer screening, which risks not being capable of being updated, and for cervical screening. Improvements to both of those systems have been funded in the last Budget. I’d also like to congratulate Minister Little on turning this pattern of under-investment around. In Budget 2021 he secured $384 million investment in the health information system.
I do take exception to the comments from the former member for Whangārei. Cyber-security modernisation, as is proposed by this Government, does ensure cyber-security. It gets you away from multiple out-of-date systems with their pattern of patches, and many of them no longer capable of being updated by their supplier. Funding for information technology in the health system has been neglected, as part of the National Government’s overall neglect of capital expenditure. In two years, there was absolutely no money spent on capital infrastructure in the entire health system. I worked in that health system, I remember exactly what it is like. Modern systems to look after vulnerable New Zealanders were not prioritised, and we have now put over $5 billion into capital expenditure in the health system.
In addition, we are improving the cyber-security system. The director-general, in June 2020, wrote to all DHBs to ask them to consider greater investment in information technology. A maturity assessment to direct future investment is also under way. I’ve already mentioned Minister Little’s planned investment through the most recent Budget, and there will be a national asset management plan developed to direct the roll-out. Following this attack, we have also taken specific action. The Ministry of Health has written to all district health boards to instruct them, with specific information on how to strengthen their systems in light of this attack. There is an ongoing criminal investigation under way, and the Government will also have an investigation into the precise circumstances that occurred at Waikato DHB. More broadly, Minister Clark has mentioned the 60 percent increase in investment in the CERT agency, and our efforts to fight cyber-crime through global collaboration, including joining the Budapest Convention.
This Government has been working closely with Waikato DHB to get their information technology systems back online. We respect the hard work done by the staff in that DHB to keep patient care going, even through what must be an incredibly stressful time. The Government is reversing the decade of under-investment in the health system capital, particularly in health system information technology. My thoughts are very much with the patients and staff at Waikato at this time.
The debate having concluded, the motion lapsed.
🗣️ Spoke in this debate (10)
- Hon Dr David Clark (New Zealand Labour Party — Member for Dunedin)
- Hon Jacqui Dean (New Zealand National Party — Member for Waitaki)
- Melissa Lee (New Zealand National Party — List Member)
- Hon Andrew Little (New Zealand Labour Party — List Member)
- Dr Shane Reti (New Zealand National Party — List Member)
- Jamie Strange (New Zealand Labour Party — Member for Hamilton East)
- Teanau Tuiono (Green Party of Aotearoa / New Zealand — List Member)
- Brooke Van Velden (ACT New Zealand — List Member)
- Hon Dr Ayesha Verrall (New Zealand Labour Party — List Member)
- Simon Watts (New Zealand National Party — Member for North Shore)