The Hidden Value in an Organisation’s Information

Estimated reading time: 8 minutes

Cybersecurity risk is not only about what your organisation considers valuable.

It is also about understanding why someone else might value the information, technology and knowledge you hold.

Most organisations know they have information that needs protecting. Customer data, financial information and critical systems are obvious examples. But the information that makes an organisation valuable to someone else can be a good deal less obvious.

On 13 August 2026, the New Zealand Security Intelligence Service released its report on New Zealand's Security Threat Environment 2026. The report finds that New Zealand's public and private sectors are being targeted by foreign states and their proxies seeking access to critical assets, including intellectual property, innovative technology and other non public information. NZSIS also reports that espionage motivated cyber activity detected against New Zealand has increased steadily over the past three years, and the agency expects that activity to increase further over the next twelve months.

For business leaders, this creates a useful question to sit with. What does your organisation hold that someone else might consider valuable? The answer may extend well beyond personal information. It could include intellectual property, research, proprietary technology, commercially sensitive information, strategic plans, datasets or specialist knowledge. Understanding that value can help organisations make better decisions about what deserves the strongest protection.

Sources: New Zealand Security Intelligence Service, New Zealand's Security Threat Environment 2026, 13 August 2026. Full citations in the References section below.

Value Looks Different From the Outside


Cybersecurity risk assessments naturally begin from the organisation's own perspective. What systems are critical? What information is sensitive? What would cause the greatest business impact if it were compromised? These remain important questions. But there is another perspective worth adding to the exercise. What would someone outside the organisation want from us?

The NZSIS report highlights how non public information, intellectual property, datasets, technological innovation and other forms of knowledge can hold strategic value in their own right. This changes the way organisations can think about information. Something that appears entirely routine during day to day operations could still be difficult, expensive or time consuming for someone else to develop independently. Risk assessment should therefore weigh two questions rather than one: what is valuable to us, and what could be valuable to someone else?

The useful cybersecurity question is not only what would hurt us if we lost it.
It is also who could benefit from obtaining it.

Your Most Valuable Information May Not Be Customer Data


Privacy and personal information understandably receive significant cybersecurity attention. But they are only part of the information landscape. Depending on the organisation, valuable information could include:

  • Intellectual property and product designs
  • Proprietary technology and research and development
  • Commercial strategies and strategic plans
  • Sensitive datasets and technical knowledge
  • Specialist business processes
  • Information about customers or partners

The NZSIS report specifically identifies intellectual property, innovative technology and other non public information among the assets that can attract interest. For a growing number of organisations, that technology now includes the AI systems and models trained on their own data, a shift explored in Australia's AI Wake Up Call. The lesson is not that every organisation should assume it is being individually targeted for espionage. It is that information value is broader than personal data. A business cannot make informed protection decisions if it has not first identified what could create value for someone else.

Valuable Information Can Be Exposed in Different Ways


Protecting valuable information is not simply a question of preventing a traditional cyber attack. The NZSIS report describes a broader environment in which information may be sought through cyber activity as well as people, commercial relationships, insiders, front companies and other channels. This matters because valuable information rarely sits in one place. It moves through the organisation and beyond it, and each pathway carries its own considerations.

PathwayWhat Leadership Should Consider
Employees and contractorsWho has access to the information, and does that access reflect their actual role and need?
Suppliers and third partiesWhich external parties receive or process the information on the organisation's behalf?
Research and commercial partnershipsWhat is shared as part of collaboration, and how is it protected once it leaves the organisation?
Cloud platforms and systemsWhere is the information stored, and who can access it beyond the immediate team?

Technical cybersecurity controls remain important. But organisations also need to understand where valuable information exists, who can access it, where it travels and which relationships create additional exposure. This kind of visibility is often what virtual ISM support is built to establish, working alongside existing teams rather than replacing them.

What Business Leaders Can Learn


Start with what creates value. Identify the information, technology, knowledge and capabilities that contribute most to the organisation's competitive or strategic advantage. Some of this will be obvious. Other value may have accumulated quietly through years of research, investment, experience or specialist knowledge.

Consider value from someone else's perspective. Information that appears routine internally may be valuable externally. Research, technical processes, datasets or strategic information could reduce the time, cost or uncertainty another party would otherwise face. This adds a useful second question to risk assessment. Alongside asking what would hurt us if we lost it, also ask who could benefit from obtaining it.

Understand where valuable information travels. Once important information has been identified, leadership should understand how it moves through the organisation. Who has access? Where is it stored? Which systems process it? Which suppliers or partners receive it? Understanding these pathways can reveal exposure that is difficult to see when security is considered only system by system, which is one reason vCISO advisory engagements tend to start with this kind of mapping rather than a controls checklist.

Align protection with actual value. Not every asset requires identical protection. Cybersecurity priorities should reflect the sensitivity, importance and potential business consequence associated with the information. Understanding value helps organisations decide where security investment and leadership attention should be concentrated, and connects directly with broader security leadership and governance decisions rather than sitting apart from them. Where compliance obligations sit alongside that value, compliance leadership can help translate priorities into documented, auditable practice.

The Value Test

Could your leadership team answer these questions today?

What gives our organisation a competitive or strategic advantage?

Where does that information live, and who can reach it?

Do our strongest protections actually sit around it?

If the answers are unclear, the priority may be understanding the asset before adding another control.


Questions Every Executive Should Ask


The following questions offer a practical way to test assumptions about what the organisation actually needs to protect.

  • What information gives our organisation a competitive advantage?
  • What intellectual property or specialist knowledge have we developed?
  • Which information would be difficult or expensive for someone else to reproduce?
  • Where is our most valuable information stored, and who can access it?
  • Which suppliers, partners or third parties also have access to it?
  • Do our security controls reflect its actual value?
  • Would we know if someone was deliberately attempting to obtain it?
  • What would the business consequence be if it was compromised?

If leadership cannot confidently answer these questions, the immediate priority may not be introducing another security control. It may be developing a clearer understanding of what actually needs protecting.

From Protecting Systems to Protecting Value


The broader shift is from asking how secure our systems are, to asking how well we are protecting what creates value for the organisation. This distinction matters. Cybersecurity ultimately exists to protect the organisation, not simply its technology, and that requires an understanding of assets, information, access, dependencies and business consequences working together. It is also the same understanding that underpins the kind of governance evidence discussed in The Evidence Gap, since an organisation cannot document what protects its value until it has identified what that value actually is.

The NZSIS development is a useful reminder that organisations can hold information, innovation and capabilities with value well beyond their immediate business purpose. Security strategy should reflect that reality. At SeComPass, we help organisations understand cybersecurity through the context of business risk, governance and resilience. Through cybersecurity assessments, security leadership and vCISO advisory, we work with leadership teams to identify what matters most, surface meaningful exposure and align cybersecurity priorities with the value the organisation is actually trying to protect. Where new controls are needed to close that gap, our tools and implementation support helps put them in place without adding unnecessary overhead.

Key Takeaways


  • Organisational value extends well beyond customer data, and can include intellectual property, research, proprietary technology and specialist knowledge
  • Risk assessment benefits from asking both what would hurt us if we lost it, and who could benefit from obtaining it
  • Valuable information travels through employees, contractors, suppliers, partnerships and cloud platforms, and each pathway carries its own exposure
  • Protection should be aligned with actual value rather than applied evenly across every asset
  • Executives who cannot confidently answer where valuable information lives and who can access it should treat that as the priority before adding new controls

Understand What Your Organisation Is Protecting

Do You Know the Hidden Value in Your Organisation's Information?

The Executive Readiness Review helps leadership teams understand what matters most to the organisation, where meaningful cybersecurity exposure exists and whether current priorities reflect actual business value. It includes:

  • Identification of the information and assets that create the greatest value
  • Review of where that information exists and who can access it
  • Assessment of whether current protection reflects actual business value
  • Strategic priorities for where security investment should be concentrated

Start by understanding what your organisation actually holds, and why it matters.

Start the Executive Readiness Review →

References


  • New Zealand Security Intelligence Service. "New Zealand's Security Threat Environment 2026," 13 August 2026. nzsis.govt.nz
  • New Zealand Security Intelligence Service. "New Zealand's Espionage Environment," Security Threat Environment 2026. nzsis.govt.nz
  • New Zealand Security Intelligence Service. "NZSIS Releases 2026 Security Threat Environment Report," 13 August 2026. nzsis.govt.nz

This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. The NZSIS findings referenced above describe the broader New Zealand threat environment and should not be read as indicating that any specific organisation is individually being targeted.

Jatinder Oberoi

Founder and Principal Consultant at SeComPass, where he helps organisations across Australia and New Zealand strengthen cybersecurity, governance, risk management, and regulatory compliance. With extensive experience in information security strategy, ISO 27001, SOC 2, AI governance, privacy, and virtual CISO (vCISO) services, Jatinder works with executive teams to align cybersecurity with business objectives, improve organisational resilience, and build lasting customer trust.

https://au.linkedin.com/in/jsoberoi
Previous
Previous

Keeping Data Is a Risk Decision

Next
Next

The Growing Role of AI in Cyber Defence