
This Cyber Risk Library provides general practices with a structured starting point for identifying, documenting, and governing cyber risks within their risk register. It supports a shift from ad hoc awareness to consistent, accountable risk management aligned with the Privacy Act 2020 and Health Information Privacy Code. The resource includes 63 example risk statements (aligned to Privacy Principles and AI PIA domains), practical mitigations for NZ practices, and ready-to-use formats for risk registers, helping strengthen cyber resilience over time.