X
  • About
  • Advertise
  • Contact
  • Expert Resources
Get the latest news! Subscribe to the Money Management bulletin
  • News
    • Accounting
    • Financial Planning
    • Funds Management
    • Life/Risk
    • People & Products
    • Policy & Regulation
    • Property
    • SMSF
    • Superannuation
    • Tech
  • Investment
    • Australian Equities
    • Global Equities
    • Managed Accounts
    • Fixed Income
    • ETFs
  • Features
    • Editorial
    • Expert Analysis
    • Guides
    • Outsider
    • Rate The Raters
    • Top 100
  • Media
    • Events
    • Podcast
    • Webcasts
  • Promoted Content
  • Investment Centre
No Results
View All Results
  • News
    • Accounting
    • Financial Planning
    • Funds Management
    • Life/Risk
    • People & Products
    • Policy & Regulation
    • Property
    • SMSF
    • Superannuation
    • Tech
  • Investment
    • Australian Equities
    • Global Equities
    • Managed Accounts
    • Fixed Income
    • ETFs
  • Features
    • Editorial
    • Expert Analysis
    • Guides
    • Outsider
    • Rate The Raters
    • Top 100
  • Media
    • Events
    • Podcast
    • Webcasts
  • Promoted Content
  • Investment Centre
No Results
View All Results
No Results
View All Results
Home News Financial Planning

The 4 Rs of cyber security

As AFSLs cite cyber security as their biggest compliance fear, a law firm has shared four steps that listed businesses need to take if they suffer a breach.

by Laura Dew
June 18, 2024
in Financial Planning, News
Reading Time: 4 mins read
Share on FacebookShare on Twitter

As AFSLs cite cyber security as their biggest compliance fear, law firm Hopgood Ganim has shared the four steps firms need to take if they suffer a breach. 

Yesterday, Money Management covered a licensee report from compliance firm Holley Nethercote that cyber security is the “greatest identified compliance risk and concern” for advice firms.

X

Law firm Hopgood Ganim described the duties as the four R’s of readiness, response, recovery and remediation.

Failure to promptly notify of a data breach is a breach of ASX listing rules and could have serious legal consequences for contravening the Corporations Act.

“Accurate and timely disclosure of a data breach will be required as part of the ‘response’ phase of a cyber crisis. However, boards should also take steps during the ‘readiness’ phase to ensure they are prepared to discharge their continuous disclosure obligations easily and effectively during the ‘response’ phase,” the firm said.

Earlier this year, financial technology platform Iress suffered a cyber incident and issued three statements to the ASX: one detailing unauthorised access to Iress code repository, followed by two subsequent updates about it affecting OneVue customers and statements made by an alleged threat actor.

The decision whether disclosure is required or not hinges on an exception regarding confidentiality and whether the matter is sufficiently definite to warrant disclosure. 

At the time of the discovery of a data breach or when a ransom email is received, no disclosure is required as it is not yet possible to determine if the breach is material to the share price, but the ASX does expect the company to undertake forensic work “with urgency”. 

By the time the firm is in discussion with the regulator, they should have at least drafted a statement ready for the market in the event that the breach ceases to be confidential. 

Although they may not be required to disclose, Hopgood Ganim still recommended engaging with the ASX as early as possible and to seek legal advice. This would not breach confidentiality for the purpose of the exception so long as the engagement is on a confidential basis.

If the firm’s investigation discovers personal information has been exfiltrated, then it is required to notify the Office of the Australian Information Commission that sensitive information has been taken, but the extent is not yet known.

The need for disclosure to the market kicks in once affected customers are notified as this means it is no longer confidential, which could materially affect the share price, or when the extent of the data breach is so large that it warrants immediate disclosure. They may also need to make a disclosure if a journalist approaches for a comment about an alleged incident.

The statement needs to include:

  • A description of what has occurred.
  • The material facts known about the data breach.
  • Any material impact on operations or financial position that the entity is aware of at the relevant time.
  • The action that the entity is taking in response to the data breach.
  • When the entity expects to be in a position to update the market.

The company needs to have sufficient information regarding the circumstances of the data breach and potential implications even if they have not yet completed the full investigation. In certain circumstances, a trading halt may be needed to allow time to prepare an accurate and complete disclosure which includes all material information known at the time.

Subsequent ransom requests do not require disclosure as the ASX considers the company has already shared the relevant price-sensitive information, but it would be required if the cyber criminal went ahead and released a large volume of data publicly.

 

Tags: ComplianceCyber SecurityCybercrimeData BreachesLaw

Related Posts

ASIC bans former UGC advice head

by Keith Ford
December 19, 2025

ASIC has banned Louis Van Coppenhagen from providing financial services, controlling an entity that carries on a financial services business or performing any function...

Largest weekly losses of FY25 reported

by Laura Dew
December 19, 2025

There has been a net loss of more than 50 advisers this week as the industry approaches the education pathway...

Two Victorian AZ NGA-backed practices form $10m business

by ShyAnn Arkinstall
December 19, 2025

AZ NGA-backed advice firms, Coastline Advice and Edge Advisory Partners, have announced a merger to form a multi-disciplinary business with $10 million combined...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Consistency is the most underrated investment strategy.

In financial markets, excitement drives headlines. Equity markets rise, fall, and recover — creating stories that capture attention. Yet sustainable...

by Industry Expert
November 5, 2025
Promoted Content

Jonathan Belz – Redefining APAC Access to US Private Assets

Winner of Executive of the Year – Funds Management 2025After years at Goldman Sachs and Credit Suisse, Jonathan Belz founded...

by Staff Writer
September 11, 2025
Promoted Content

Real-Time Settlement Efficiency in Modern Crypto Wealth Management

Cryptocurrency liquidity has become a cornerstone of sophisticated wealth management strategies, with real-time settlement capabilities revolutionizing traditional investment approaches. The...

by PartnerArticle
September 4, 2025
Editorial

Relative Return: How fixed income got its defensiveness back

In this episode of Relative Return, host Laura Dew chats with Roy Keenan, co-head of fixed income at Yarra Capital...

by Laura Dew
September 4, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Podcasts

Relative Return Insider: MYEFO, US data and a 2025 wrap up

December 18, 2025

Relative Return Insider: RBA holds, Fed cuts and Santa’s set to rally

December 11, 2025

Relative Return Insider: GDP rebounds and housing squeeze getting worse

December 5, 2025

Relative Return Insider: US shares rebound, CPI spikes and super investment

November 28, 2025

Relative Return Insider: Economic shifts, political crossroads, and the digital future

November 14, 2025

Relative Return: Helping Australians retire with confidence

November 11, 2025

Top Performing Funds

FIXED INT - AUSTRALIA/GLOBAL BOND
Fund name
3 y p.a(%)
1
DomaCom DFS Mortgage
211.38
2
Loftus Peak Global Disruption Fund Hedged
110.90
3
SGH Income Trust Dis AUD
80.01
4
Global X 21Shares Bitcoin ETF
76.11
5
Smarter Money Long-Short Credit Investor USD
67.63
Money Management provides accurate, informative and insightful editorial coverage of the Australian financial services market, with topics including taxation, managed funds, property investments, shares, risk insurance, master trusts, superannuation, margin lending, financial planning, portfolio construction, and investment strategies.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Financial Planning
  • Funds Management
  • Investment Insights
  • ETFs
  • People & Products
  • Policy & Regulation
  • Superannuation

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
    • All News
    • Accounting
    • Financial Planning
    • Funds Management
    • Life/Risk
    • People & Products
    • Policy & Regulation
    • Property
    • SMSF
    • Superannuation
    • Tech
  • Investment
    • All Investment
    • Australian Equities
    • ETFs
    • Fixed Income
    • Global Equities
    • Managed Accounts
  • Features
    • All Features
    • Editorial
    • Expert Analysis
    • Guides
    • Outsider
    • Rate The Raters
    • Top 100
  • Media
    • Events
    • Podcast
    • Webcasts
  • Promoted Content
  • Investment Centre
  • Expert Resources
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited