Twice in the past 3 years I have contacted a NZ financial institution to alert them to internet issues. The first was a bank style institution and the latest a registered bank.
First time was a matter which fell under PCIDSS and would have caused a fail if that area had been assessed. The latest issue was not a security matter, but not a good look either (and certainly didn't speak well for the competence of the people running their IT).
On both occasions these were met with brazen denial and a air on invincibility.
With the first issue I contacted the FMA and discovered the IT side of financial institutions in NZ is totally unregulated by them.
It's a bit of a worry...