ASIC alleges “Missing Cybersecurity Measures” against AFS Licensee – A Curse and a Blessing: Australian Securities and Investments Commission v FIIG Securities Limited ACN 085 661 632

The Australian Securities and Investment Commission (ASIC) has brought proceedings against an Australian Financial Services (AFS) licensee alleging “Missing Cybersecurity Measures” in the period prior to suffering a significant cyber incident.
April 4 2025

By Jason Symons, Partner, Mitchell Riley-Meijer, Incident Response Manager, Max Feng, Lawyer, Carolyn Nguyen, Lawyer, Zein El Hassan, Partner, Giulianna Kharoufeh, Senior Associate and Evelyn Levers, Associate

The Australian Securities and Investment Commission (ASIC) has brought proceedings against an Australian Financial Services (AFS) licensee alleging “Missing Cybersecurity Measures” in the period prior to suffering a significant cyber incident.  This follows the landmark decision in ASIC v RI Advice Group Pty Ltd [1] (RI Advice) in 2022.

The ASIC v FIIG Securities Limited (FIIG Securities) proceedings[2] are a curse and a blessing to corporate Australia, in particular to AFS licensees.  The corporate regulator has made it abundantly clear that a Licensee will face regulatory action, including potential monetary penalties, if it does not have “Adequate Cybersecurity Measures” in place to protect itself and its clients against cybersecurity risks.

However, adding to the lessons learned from RI Advice, FIIG Securities may also provide helpful guidance to boards as to ASIC’s expectations when it comes to adequate resourcing of cybersecurity and the specific measures that should be in place. The importance of corporations (and their boards) proactively addressing cybersecurity capability and risk management can no longer be ignored.

The Incident

On 23 May 2023, FIIG Securities Limited (FIIG) experienced a significant cyber incident resulting in the unauthorised access and exfiltration of approximately 385GB of data, including client personal information containing names, contact details, copies of Government identifiers (copies of driver licences, Medicare card details and passports), Tax File Numbers and bank account details.

The cyber intrusion followed a FIIG employee inadvertently downloading a .zip file containing malware while browsing the Internet, which enabled a threat actor to gain remote access to FIIG’s network, move laterally within its systems, and escalate access privileges.

Importantly, whilst FIIG had in place internal cybersecurity controls which identified the suspicious activities, these suspicious activities were not investigated by FIIG’s internal IT resources.

Moreover, FIIG did not initiate its investigation of the incident until 8 June 2023, 6 days after being notified by the Australian Cyber Security Centre (ACSC) of the incident, and 17 days after first being identified by the internal cybersecurity controls.  On 9 June 2023, FIIG took its systems offline. On 10 June 2023, some of the personal information was leaked on the dark web.

It subsequently took FIIG several months to restore its IT systems, compromising its ability to deliver financial services to its customers.

The Allegations

FIIG is an AFS licensee specialising in fixed income financial products and services. As an AFS licence holder, FIIG is subject to the “general obligations” of s 912A(1) of the Corporations Act 2001 (Cth) (the Act).

According to ASIC, FIIG failed to:

  • do all things necessary to ensure that the financial services covered by its licence were provided efficiently, honestly and fairly as required by s 912A(1)(a);
  • have available adequate resources (including financial, technological, and human resources) to provide the financial services covered by its licence as required by s 912A(1)(d); and
  • have adequate risk management systems as required by s 912A(1)(h).

These failures meant FIIG contravened s 912A(5A), making it subject to a civil penalty as prescribed by s 1317E of the Act.

ASIC is seeking certain declarations regarding these failures and an order requiring FIIG to complete a compliance programme involving the review of its cybersecurity measures and an independent expert report on those measures to ASIC.

Significantly, ASIC is further seeking an order that FIIG pay a pecuniary penalty pursuant to s 1317G in respect of its contraventions of s 912A(5A).  The maximum size of such penalty being $16.5 million (or more if based on any benefit received by FIIG or its annual turnover[3]).

The Failures in Cybersecurity

ASIC framed FIIG’s alleged failures against what the regulator considered to be “Adequate Cybersecurity Measures” that FIIG ought to have had in place “to protect its clients from the risks and consequences of a cyber intrusion” for the 4 years prior to the cyber incident.

These measures include:

  • a cyber incident response plan that is approved by the organisation, is communicated to all employees and addresses regulatory notification requirements;
  • privileged access management across networks, computer systems and applications to ensure least privilege is assigned, managed appropriately and revoked when access is no longer required;
  • vulnerability scanning capabilities to identify security vulnerabilities within the network and on endpoints, with processes to ensure they are appropriately reviewed (at least quarterly) and identified vulnerabilities addressed;
  • Next-Generation Firewalls configured to impose outbound traffic rules for endpoints and servers, with firewall rules preventing access to file transfer protocol services;
  • group policy settings configured for Active Directory to disable legacy authentication protocols;
  • Endpoint Detection and Response (EDR) capabilities installed on all endpoints and servers, which is monitored on a daily basis by an appropriately qualified person;
  • Security Information and Event Management (SIEM) software appropriately configured to collect (in real-time) security event logs, as well as logs produced by firewall and EDR controls;
  • SIEM software configured to enable analysis of logs to identify suspicious behaviour, and to store security information logs online for 90 days and on an archive for 12 months;
  • implementation of a patch management plan to ensure patches and software updates are applied to all applications, operating systems and firmware, within 1 month if critical/high importance (3 months otherwise);
  • ensuring that operating systems are updated to vendor supported versions;
  • Multi-Factor Authentication (MFA) for all remote access users;
  • mandatory security awareness training; and
  • quarterly review and evaluation of technical cybersecurity controls.

ASIC stated that the Adequate Cybersecurity Measures that FIIG ought to have had in place included those listed above, or such of those measures as would provide adequate protection from the risk and consequences of a cyber intrusion. This is collectively referred to as the “Missing Cybersecurity Measures”.

ASIC alleges that FIIG’s failure to have the Missing Cybersecurity Measures in place meant it failed to meet its obligations under s 912A(1)(a).

In turn, by not having adequate “financial, technological or human resources” available to ensure it had in place the Missing Cybersecurity Measures, and to ensure it had implemented risk management measures (including those in FIIG’s risk management system), ASIC alleged that FIIG did not meet its obligations under s 912(1)(d) and (h).

The Further Significance

ASIC’s proceedings against FIIG are significant, and warrant ongoing monitoring, for several further reasons:

  • ASIC’s detailed framing of the regulator’s expectations of its licensees when it comes to cybersecurity highlights the regulator’s increasing capabilities to identify and consider cybersecurity within the remit of s 912A of the Act.
  • Human error is one of the leading contributors of a cyber incident. Whilst 385GB of data may sound very high, our experience in dealing with malware extortion and exfiltration shows that small and medium enterprises (SMEs) often hold similarly large amounts of data due to weak data retention and deletion strategies.
  • The Missing Cybersecurity Measures do not conform to any single cyber risk maturity framework such as Australian Signal Directorate’s (ASD) Essential 8. Without clearly identifying a cybersecurity standard that ASIC expects organisations to conform to, SMEs and other entities with limited resources are increasingly left without practical guidance on how to meet ASIC’s expectations.
  • Licensees must consider compliance with their legal obligations with equal importance as service continuity and restoration during a cyber incident. Integration of internal/external legal counsel into incident response strategies and planning is critical to effective cyber incident response.
  • ASIC expects entities to allocate sufficient resources (financial, technological and human) to meet their obligations under s 912A, and governance and oversight of internal policies and controls are key to maintaining adequate risk management systems. Internal policies and procedures must reflect current practices and be regularly tested.

Please reach out to our Cyber Risk team here or our Financial Services team here if you would like to discuss further this case or your compliance with the s 912A obligations as they relate to your cybersecurity.

[1] [2022] FCA 496.

[2] Concise Statement found here; Originating Process found here.

[3] See ASIC’s guidance on fines and penalties here.