When the Australian Cyber Security Centre alerted FIIG Securities to a breach on June 2, 2023, the firm discovered attackers had been inside its network since March 19. That's 75 days of undetected access, 385GB of compromised data, and 18,000 affected clients. The Federal Court's AUD 2.5 million penalty against FIIG in March 2025 wasn't just about the breach itself. It was about the systematic failures that made the breach inevitable.
ASIC's enforcement action under section 912A of the Corporations Act 2001 represents the first civil penalty case specifically for cyber security failures under Australian Financial Services Licence obligations. The detailed forensic examination that led to this penalty reveals a pattern of mistakes that many financial services firms are still making.
Why These Failures Keep Repeating
Most organizations don't fail catastrophically in one area. They fail incrementally across multiple domains until a breach exposes the accumulated gaps. FIIG's case shows how governance weaknesses, resource constraints, and technical debt compound into regulatory exposure. The court didn't penalize FIIG for being breached. It penalized the firm for failing to meet its obligations under sections 912A(1)(a), (d), and (h) to provide services efficiently and fairly, maintain adequate resources, and implement adequate risk management systems.
Your board and executive team need to understand: ASIC's expectations are minimum obligations with forensic enforcement behind them.
Mistake 1: Treating Cyber Risk as an IT Problem, Not a Licence Obligation
Why it happens: Many firms still compartmentalize cyber security as a technology function separate from compliance and risk. The CISO reports to the CIO, not the Chief Risk Officer. Board papers mention cyber in passing. Risk registers list it alongside operational issues rather than as a fundamental licence-to-operate requirement.
Real consequence: When cyber sits in IT, it competes with infrastructure projects and digital initiatives for budget and attention. Compliance teams don't audit it with the same rigor they apply to financial controls or conduct obligations. The result is exactly what ASIC found at FIIG: cyber measures that weren't proportionate to the sensitivity of data held, the scale of operations (AUD 2.99 to 3.7 billion in client assets), or the magnitude of potential harm.
The fix: Embed cyber resilience into your AFSL compliance framework explicitly. Your section 912A(1)(h) risk management system must include cyber as a first-order risk, not a supporting process. Document how your cyber controls map to your obligations to provide services "efficiently, honestly and fairly" under section 912A(1)(a). When assessing the adequacy of resources under section 912A(1)(d), cyber capability must be part of that assessment with the same weight as capital adequacy or professional indemnity insurance.
Mistake 2: Underfunding Detection and Response While Overspending on Prevention
Why it happens: Prevention technologies are easier to budget and procure. Firewalls, endpoint protection, and email filters have clear price tags and vendor roadmaps. Detection and response capabilities require skilled analysts, 24/7 monitoring, threat intelligence integration, and regular testing. These are ongoing operational costs that don't produce visible outputs until something goes wrong.
Real consequence: FIIG was unaware of the breach for 75 days. The ACSC had to notify them. This wasn't a sophisticated zero-day exploit that evaded all detection. It was a failure of basic visibility into what was happening inside the network. When you can't detect anomalous behavior, you can't contain it. The court found this represented inadequate technological and human resources under section 912A(1)(d).
The fix: Allocate resources proportionately across the NIST Cybersecurity Framework 2.0 functions: Identify, Protect, Detect, Respond, Recover, and Govern. If you're spending 80% on Protect and 5% on Detect, you're building a system that fails silently. Implement continuous monitoring with defined detection use cases for your environment. Establish baseline behavior for privileged accounts, data egress, and authentication patterns. Test detection capabilities quarterly with simulated attack scenarios, not just annual penetration tests.
Mistake 3: Assigning Cyber Responsibility Without Authority or Resources
Why it happens: Organizations create cyber security roles without restructuring decision rights or budget authority. The CISO has accountability for outcomes but depends on other departments for implementation. Infrastructure teams control patching schedules. Application owners decide when to remediate vulnerabilities. The security team can recommend but not enforce.
Real consequence: ASIC's decision emphasizes that employees with responsibility for cyber security "must be appropriately experienced and given sufficient time and resources to properly discharge their responsibilities." When your cyber lead is experienced but under-resourced, or empowered but inexperienced, you haven't met the adequacy standard. Controls exist on paper but aren't implemented consistently.
The fix: Map decision rights explicitly. Who can approve exceptions to patching policies? Who can authorize new internet-facing services? Who can override security architecture requirements? Your cyber security function needs either direct authority over these decisions or an escalation path that resolves in days, not months. Resource the function to conduct regular control testing, not just respond to incidents. If your cyber team's capacity is consumed by BAU support tickets, they can't perform the strategic risk management the licence requires.
Mistake 4: Implementing Controls Without Testing Whether They Work
Why it happens: Compliance programs focus on evidence of control existence: policies documented, tools deployed, training completed. Auditors check for artifacts. The assumption is that if the control exists, it functions. But controls degrade. Configurations drift. Exceptions accumulate. What worked at implementation may not work 18 months later.
Real consequence: ASIC didn't just evaluate whether FIIG had controls. It examined whether those controls were "properly and consistently implemented by way of effective controls" and "tested and reviewed on a regular basis." Having a vulnerability management policy doesn't satisfy the obligation if critical vulnerabilities remain unpatched for months. Having an incident response plan doesn't help if responders discover during a real incident that it's untested and incomplete.
The fix: Shift from control existence to control effectiveness. Schedule quarterly control testing that simulates real attack scenarios: Can you detect a compromised privileged account? How long does it take to identify unauthorized data exfiltration? Does your incident response plan work when the primary contact is unavailable? Document not just what controls you have, but when you last validated they work as intended. Treat failed control tests as material findings requiring executive reporting and remediation tracking.
Mistake 5: Treating Proportionality as a Reason to Delay, Not a Risk Calibration Tool
Why it happens: The requirement that cyber measures be "proportionate to the nature of the business, extent and complexity of information held, the value of assets held, [and] the magnitude and potential consequences" sounds like permission to do less. Smaller firms or those with "less sensitive" data interpret proportionality as justification for minimal investment.
Real consequence: ASIC's proportionality analysis cuts both ways. FIIG held billions in client assets and extensive personal information. The court found their measures inadequate relative to that risk profile. But proportionality also means a small advisory firm with 50 clients and limited data doesn't need the same infrastructure. The mistake is using proportionality to avoid hard decisions rather than to calibrate controls to actual risk. If you hold sensitive data or manage significant assets, proportionality demands more, not less.
The fix: Conduct a formal risk assessment that documents the sensitivity of data you hold, the value of assets under management, and the potential consequences of compromise. Use that assessment to define your proportionate control baseline. For high-sensitivity environments, this means continuous monitoring, regular penetration testing, and incident response capabilities that can activate within hours. For lower-risk profiles, it might mean managed detection and response services and quarterly vulnerability assessments. Document the rationale. When ASIC or your auditor asks why you implemented certain controls and not others, you need evidence-based answers, not resource constraints as the explanation.
Prevention Checklist: AFSL Cyber Resilience
Use this checklist to evaluate whether your current cyber program meets ASIC's expectations:
Governance and Accountability
- Cyber risk is explicitly included in your section 912A risk management framework
- Board receives regular reporting on cyber resilience, not just IT project updates
- Cyber security roles have defined decision rights and escalation paths
- Annual review of cyber resources (financial, technological, human) against risk profile
Risk Management Systems
- Documented risk assessment covering data sensitivity, asset value, and potential consequences
- Controls calibrated to risk assessment findings, with rationale documented
- Regular testing of control effectiveness, not just control existence
- Remediation tracking for identified vulnerabilities with executive visibility
Detection and Response
- Continuous monitoring with defined detection use cases for your environment
- Incident response plan tested at least annually with realistic scenarios
- Defined process for detecting compromised privileged accounts and unauthorized access
- Capability to identify and investigate anomalous data movement
Resources and Capability
- Cyber security function has adequate time and budget to perform strategic risk management
- Personnel with cyber responsibilities are appropriately experienced for the role
- Access to external expertise for specialized capabilities (threat intelligence, forensics)
- Technology investments balanced across prevention, detection, and response
Continuous Improvement
- Quarterly control testing with documented results and remediation plans
- Regular review of controls against evolving threat landscape
- Post-incident reviews that identify systemic improvements, not just technical fixes
- Evidence that identified gaps are addressed within defined timeframes
ASIC's enforcement focus on cyber resilience isn't temporary. The regulator has identified cyber-attacks and inadequate operational resilience as ongoing threats to market confidence. The FIIG case establishes the evidentiary standard: detailed, technical, forensic examination of whether your controls are adequate, proportionate, properly implemented, regularly tested, and appropriately resourced. If you can't demonstrate all five, you're carrying regulatory risk alongside your cyber risk.





