Court finds RI Advice failed to adequately manage cybersecurity risks

5 May 2022
| By Liam Cormican |
image
image
expand image

The Federal Court has found Australian Financial Services licensee, RI Advice, breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks.

The first ruling of its kind in Australia, the finding came after a significant number of cyber incidents occurred at authorised representatives of RI Advice between June 2014 and May 2020.

In one of the incidents, an unknown malicious agent obtained, through a brute force attack, unauthorised access to an authorised representative’s file server from December 2017 to April 2018 before being detected, resulting in the potential compromise of confidential and sensitive personal information of several thousand clients and other persons.

The finding followed an earlier ruling by the Federal Court in February in which RI Advice Group was ordered to pay a $6 million penalty for failing to take reasonable steps to ensure that its authorised representative, John Doyle, provided appropriate financial advice.

Australian Securities and Investments Commission (AISC), deputy chair, Sarah Court, said the cyber-attacks were significant events that allowed third parties to gain unauthorised access to sensitive personal information.

“It is imperative for all entities, including licensees, to have adequate cybersecurity systems in place to protect against unauthorised access,” Court said.

“ASIC strongly encourages all entities to follow the advice of the Australian Cyber Security Centre and adopt an enhanced cybersecurity position to improve cyber resilience in light of the heightened cyber-threat environment.”

The corporate regulator said RI Advice had taken steps to address cybersecurity risk across its authorised representative network. In addition to the declaration of contravention, the court ordered RI Advice to engage a cybersecurity expert to identify and implement what, if any, further measures are necessary to adequately manage cybersecurity risks across RI Advice’s authorised representative network.

When handing down the judgment, Justice Rofe made clear that cybersecurity should be front of mind for all licensees, stating: “Cybersecurity risk forms a significant risk connected with the conduct of the business and provision of financial services. It is not possible to reduce cybersecurity risk to zero, but it is possible to materially reduce cybersecurity risk through adequate cybersecurity documentation and controls to an acceptable level.”

Read more about:

AUTHOR

 

Recommended for you

 

MARKET INSIGHTS

sub-bg sidebar subscription

Never miss the latest news and developments in wealth management industry

JOHN GILLIES

Might be a bit different to i the past where at most there was one man from the industry on the loaded enquiry boards a...

1 day 2 hours ago
Simon

Who get's the $10M? Where does the money go?? Might it end up in the CSLR to financially assist duped investors??? ...

5 days 21 hours ago
Squeaky'21

My view is that after 2026 there will be quite a bit less than 10,000 'advisers' (investment advisers) and less than 100...

1 week 6 days ago

AustralianSuper and Australian Retirement Trust have posted the financial results for the 2022–23 financial year for their combined 5.3 million members....

9 months 2 weeks ago

A $34 billion fund has come out on top with a 13.3 per cent return in the last 12 months, beating out mega funds like Australian Retirement Trust and Aware Super. ...

9 months 1 week ago

The verdict in the class action case against AMP Financial Planning has been delivered in the Federal Court by Justice Moshinsky....

9 months 2 weeks ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND