ASIC commences proceedings against RI Advice

21 August 2020
| By Oksana Patron |
image
image
expand image

The Australian Securities and Investments Commission (ASIC) has announced it has commenced proceedings against RI Advice for alleged failure to have adequate cyber security systems. 

The regulator said the action followed a number of alleged cyber breach incidents at certain authorised representatives (ARs) of RI, including an alleged cyber breach incident at Frontier Financial Group as trustee for The Frontier Trust (Frontier) from December 2017 to May 2018. 

ASIC alleged that Frontier was subject to a “brute force” attack whereby a malicious user successfully gained remote access to Frontier’s server and spent more than 155 hours logged into the server, which contained sensitive client information including identification documents. 

Following this, RI failed to have implemented (including by its ARs) adequate policies, systems and resources which were reasonably appropriate to manage risk in respect of cybersecurity and cyber resilience. 

ASIC is seeking: 

  • Declarations that RI contravened provisions of the Corporations Act, specifically sections 912A(1)(a), (b), (c), (d) and (h) and (5A); 
  • Orders that RI pay a civil penalty in an appropriate amount to be determined by the Court; and 
  • Compliance orders that RI implements systems that are reasonably appropriate to adequately manage risk in respect of cybersecurity and cyber resilience and provide a report from a suitably qualified independent expert confirming that such systems have been implemented. 

RI was, until 1 October 2018, a wholly owned subsidiary of Australia and New Zealand Banking Group Limited. On 1 October 2018, RI became a wholly owned subsidiary of IOOF Holdings Limited (IOOF). 

“The allegations by ASIC are very general but appear to relate to a small number of cyber-attacks of a nature not uncommonly faced by Australian businesses, on a small number of authorised representatives of RI Advice, and in most instances, no client data would appear to have been compromised. Some of ASIC’s complaints relate back to events from 2016,” IOOF said in a statement made to the Australian Securities Exchange (ASX).


The firm also said that RI Advice worked for some time with its ARs and third party experts to improve its cybersecurity and resilience and has indicated to ASIC its willingness to work co-operatively in respect of these matters.

 

Read more about:

AUTHOR

 

Recommended for you

 

MARKET INSIGHTS

sub-bg sidebar subscription

Never miss the latest news and developments in wealth management industry

Squeaky'21

My view is that after 2026 there will be quite a bit less than 10,000 'advisers' (investment advisers) and less than 100...

1 week 1 day ago
Jason Warlond

Dugald makes a great point that not everyone's definition of green is the same and gives a good example. Funds have bee...

1 week 1 day ago
Jasmin Jakupovic

How did they get the AFSL in the first place? Given the green light by ASIC. This is terrible example of ASIC's incompet...

1 week 2 days ago

AustralianSuper and Australian Retirement Trust have posted the financial results for the 2022–23 financial year for their combined 5.3 million members....

9 months 2 weeks ago

A $34 billion fund has come out on top with a 13.3 per cent return in the last 12 months, beating out mega funds like Australian Retirement Trust and Aware Super. ...

9 months ago

The verdict in the class action case against AMP Financial Planning has been delivered in the Federal Court by Justice Moshinsky....

9 months 2 weeks ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND