By Jason Symons, Partner, Mitchell Riley-Meijer, Incident Response Manager, Max Feng, Lawyer, Carolyn Nguyen, Lawyer, Zein El Hassan, Partner, Giulianna Kharoufeh, Senior Associate and Evelyn Levers, Associate
The Australian Securities and Investment Commission (ASIC) has brought proceedings against an Australian Financial Services (AFS) licensee alleging “Missing Cybersecurity Measures” in the period prior to suffering a significant cyber incident. This follows the landmark decision in ASIC v RI Advice Group Pty Ltd [1] (RI Advice) in 2022.
The ASIC v FIIG Securities Limited (FIIG Securities) proceedings[2] are a curse and a blessing to corporate Australia, in particular to AFS licensees. The corporate regulator has made it abundantly clear that a Licensee will face regulatory action, including potential monetary penalties, if it does not have “Adequate Cybersecurity Measures” in place to protect itself and its clients against cybersecurity risks.
However, adding to the lessons learned from RI Advice, FIIG Securities may also provide helpful guidance to boards as to ASIC’s expectations when it comes to adequate resourcing of cybersecurity and the specific measures that should be in place. The importance of corporations (and their boards) proactively addressing cybersecurity capability and risk management can no longer be ignored.
On 23 May 2023, FIIG Securities Limited (FIIG) experienced a significant cyber incident resulting in the unauthorised access and exfiltration of approximately 385GB of data, including client personal information containing names, contact details, copies of Government identifiers (copies of driver licences, Medicare card details and passports), Tax File Numbers and bank account details.
The cyber intrusion followed a FIIG employee inadvertently downloading a .zip file containing malware while browsing the Internet, which enabled a threat actor to gain remote access to FIIG’s network, move laterally within its systems, and escalate access privileges.
Importantly, whilst FIIG had in place internal cybersecurity controls which identified the suspicious activities, these suspicious activities were not investigated by FIIG’s internal IT resources.
Moreover, FIIG did not initiate its investigation of the incident until 8 June 2023, 6 days after being notified by the Australian Cyber Security Centre (ACSC) of the incident, and 17 days after first being identified by the internal cybersecurity controls. On 9 June 2023, FIIG took its systems offline. On 10 June 2023, some of the personal information was leaked on the dark web.
It subsequently took FIIG several months to restore its IT systems, compromising its ability to deliver financial services to its customers.
FIIG is an AFS licensee specialising in fixed income financial products and services. As an AFS licence holder, FIIG is subject to the “general obligations” of s 912A(1) of the Corporations Act 2001 (Cth) (the Act).
According to ASIC, FIIG failed to:
These failures meant FIIG contravened s 912A(5A), making it subject to a civil penalty as prescribed by s 1317E of the Act.
ASIC is seeking certain declarations regarding these failures and an order requiring FIIG to complete a compliance programme involving the review of its cybersecurity measures and an independent expert report on those measures to ASIC.
Significantly, ASIC is further seeking an order that FIIG pay a pecuniary penalty pursuant to s 1317G in respect of its contraventions of s 912A(5A). The maximum size of such penalty being $16.5 million (or more if based on any benefit received by FIIG or its annual turnover[3]).
ASIC framed FIIG’s alleged failures against what the regulator considered to be “Adequate Cybersecurity Measures” that FIIG ought to have had in place “to protect its clients from the risks and consequences of a cyber intrusion” for the 4 years prior to the cyber incident.
These measures include:
ASIC stated that the Adequate Cybersecurity Measures that FIIG ought to have had in place included those listed above, or such of those measures as would provide adequate protection from the risk and consequences of a cyber intrusion. This is collectively referred to as the “Missing Cybersecurity Measures”.
ASIC alleges that FIIG’s failure to have the Missing Cybersecurity Measures in place meant it failed to meet its obligations under s 912A(1)(a).
In turn, by not having adequate “financial, technological or human resources” available to ensure it had in place the Missing Cybersecurity Measures, and to ensure it had implemented risk management measures (including those in FIIG’s risk management system), ASIC alleged that FIIG did not meet its obligations under s 912(1)(d) and (h).
ASIC’s proceedings against FIIG are significant, and warrant ongoing monitoring, for several further reasons:
Please reach out to our Cyber Risk team here or our Financial Services team here if you would like to discuss further this case or your compliance with the s 912A obligations as they relate to your cybersecurity.
—
[1] [2022] FCA 496.
[2] Concise Statement found here; Originating Process found here.
If you would like further information or have any queries regarding other matters, please do not hesitate to contact: