AFSLs must prioritise cyber resilience
                                    
                                                                                                                                                        
                            Australian financial services licensees (AFSLs) that have not incorporated cyber resilience in their risk management systems will not be satisfying this licence obligation, a law firm warned.
Holley Nethercote senior lawyer, Fiona McCord, said licensees should be reviewing information technology resources based on not only their ability to avoid, manage, and respond to a cyber incident but also the ability to keep providing the financial services.
McCord said licensees must have adequate information technology resources to provide the financial services covered by the licence.
“If your information is locked down and you must pay a ransom, what will you do? Can you continue to provide the financial services? Have you identified the resources that your business needs to prevent cyber incidents?” McCord asked.
“Have you identified your vulnerability and exposure to cyber incidents? Do you know what the risks are, and have you assessed what controls you need to deal with them?”
McCord said licensees possess highly personal information which makes them vulnerable to criminal activities such as identity fraud, which could be sold for a high price.
This secondary market for personal information and the inability to conduct business would mean businesses would be more willing to pay a ransom to have the information unlocked and returned, she said.
Recommended for you
The central bank has released its decision on the official cash rate following its November monetary policy meeting.
Melbourne advice firm Hewison Private Wealth has marked four decades of service after making its start in 1985 as a “truly independent advice business” in a largely product-led market.
HLB Mann Judd Perth has announced its acquisition of a WA business advisory firm, growing its presence in the region, along with 10 appointments across the firm’s national network.
Unregistered managed investment scheme operator Chris Marco has been sentenced after being found guilty of 43 fraud charges, receiving the highest sentence imposed by an Australian court regarding an ASIC criminal investigation.
							
						
							
						
							
						
							
						
