Skip to main content

Article

People Risk in 2026: What New Zealand employers need to know

Following Marsh’s People Risk webinar, we summarise the People Risk 2026 report through a New Zealand lens - what cyber, cost and wellbeing trends mean for employers and practical actions to build resilience.

In June 2026, Marsh Health and Benefits brought together a panel of specialists for a People Risk webinar exploring the people risks most likely to affect organisations in the next 12–24 months, and what can New Zealand employers do now to stay resilient. The discussion drew on insights from the People Risk 2026 Report, a global study of 4,517 HR and risk professionals across 26 markets, including 104 respondents in New Zealand, and translated the findings into a practical New Zealand lens for local organisations.

The message was clear: the risk environment is not only more uncertain, it’s more connected. Risks that used to sit in separate boxes are now influencing each other in ways that can either strengthen an organisation or strain it. That’s why “people risk” is no longer an HR-only conversation. It’s a resilience and performance conversation, and it belongs on the leadership agenda.

People risks don’t arrive one at a time, they compound

A key theme throughout the report, is that people risks rarely occur in isolation. Leadership gaps, skills shortages, employee financial insecurity, and mental or physical health challenges can compound and escalate, driving disruption and raising the cost of inaction.

This is why many organisations feel as though they are constantly “responding” rather than getting ahead. Resilience doesn’t come from addressing every risk at once, it comes from understanding which risks are linked in your organisation, and tackling the root causes that reduce multiple exposures at the same time.

Cyber and technology change: not just an IT issue, a workforce issue

One of the strongest insights from the report is the prominence of technology-related risks, including cyber threat literacy, technology skills shortages, and the risks associated with data and intellectual property. But what stood out was how these risks show up in day to day operations.

Cyber risk is often framed as technology and controls. Yet many incidents and near misses are shaped by human behaviour: the quality of security habits, the ability to spot suspicious activity, the confidence to escalate concerns, and the simple reality that under pressure people are more likely to miss details. When teams are stretched thin, distracted, or fatigued, the likelihood of mistakes increases and so does vulnerability to social engineering.

Alongside this, technology disruption and AI adoption are reshaping the workforce experience. For some employees, technology change is energising; for others, it creates uncertainty and anxiety. AI and cyber resilience are closely tied to culture: organisations that invest in capability, learning and clarity tend to experience less friction and risk than those who rely on ad hoc adoption.

The practical implication is straightforward: cyber resilience improves fastest when it’s treated as a people capability challenge, not just a systems purchase. 

Rising costs and benefits complexity: short-term savings can create long-term risk

The report focused heavily on cost pressures, particularly the increasing complexity of managing rewards and benefits in an environment where budgets are tight, expectations are rising, and the margin for error is shrinking. 

For many employers, benefits and healthcare decisions can feel binary: “either we can afford it or we can’t.” But the real risk is not simply the price tag, it’s the downstream impact of decisions made without clear visibility of employee outcomes.

Cost management and workforce resilience should not be treated as opposing goals. A more sustainable approach is benefits optimisation: actively managing programs so they continue to meet employee needs while controlling long-term volatility and waste. In practice, that often involves strengthening governance, improving data visibility, and designing benefits around how people actually use them, not only around what was historically provided.

Insurance market pressures: redesign and optimisation are becoming the norm

The report highlighted several approaches organisations are exploring to manage volatility while protecting outcomes, such as redesigning benefits to better reflect claims experience and workforce needs, adjusting excess structures and contribution models thoughtfully, and regularly testing the market. The point was not that every organisation should make changes, it was that passive programs are becoming harder to sustain in a volatile environment. Organisations that actively govern benefits, monitor what is driving costs, and communicate clearly tend to be better placed to maintain value over time.

The takeaway is that there is often more choice than it appears at first glance. Even small adjustments, if well designed and well communicated, can reduce volatility and protect employee outcomes. 

Mental health and psychosocial risk: the “invisible” foundation risk

Mental health was positioned not as a standalone wellbeing topic, but as a foundation risk that can amplify other risks when it deteriorates. Mental health issues can become normalised in workplaces, which can make them harder to “see” until they show up through absence, performance changes, conflict, safety incidents, or turnover.

Managers are typically the first people who can recognise early warning signs in a team, but many don’t feel equipped to have difficult conversations, respond appropriately, or balance empathy with performance needs. When leadership capability is strong, psychosocial risks are more likely to be identified early, addressed constructively, and prevented from escalating. When it’s weak, risk spreads faster and employees often disengage quietly before they leave.

Financial wellbeing: an emerging driver of people risk

Financial stress is increasingly showing up as a material people risk, not only as a personal issue employees deal with outside of work. Financial insecurity can affect focus, mental wellbeing, and productivity, and can shape behaviours that increase organisational exposure. When people are under financial strain, they may be more distracted, more likely to take shortcuts, more likely to leave for marginal pay differences, and in some cases more vulnerable to cyber exploitation.

The message is that financial wellbeing initiatives don’t have to be expensive to be meaningful. Clarity, communication, and practical support can make a difference, particularly when paired with benefits design choices that minimise “financial shocks” for employees at the point of need.

The main message for New Zealand employers: manage people risk as a system

Organisations build resilience when they connect risks across the business and manage them as a system. Cyber exposure, skills shortages, cost pressures, health and wellbeing challenges, and financial insecurity don’t sit in neat categories in real life; they influence each other through workload, culture, leadership, and decision-making.

The challenge is not to build a large, enterprise-style risk framework. It’s to focus on a few integrated actions that reduce risk across multiple areas, such as:

  • strengthening leadership capability as a control (especially in psychosocial risk and change leadership)
  • improving cyber threat literacy and security-minded behaviours across the organisation
  • putting clearer governance around rewards and benefits decisions, supported by better data
  • designing benefits and support in ways that protect employee health and financial resilience, not just short-term cost targets

In 2026, the “human edge” is increasingly the difference between organisations that absorb disruption and those that are derailed by it.

Ready to understand your biggest people risks and where to act first?

Explore the full report here and to discuss a People Risk Diagnostic for your organisation, fill in this form to arrange a confidential conversation.

Page Compliance ID