Powered by MOMENTUM MEDIA
moneymanagement logo
 
 

ASIC launches second cyber security enforcement action

ASIC/fixed-income/bonds/cybersecurity/enforcement/

13 March 2025
| By Jasmine Siljic |
image
image image
expand image

ASIC is suing FIIG Securities for alleged failures in its cyber security measures, describing the matter as a “wake-up call” to all licensees.

The corporate regulator stated that FIIG Securities Limited (FIIG) allegedly failed to have adequate cyber security measures for over four years, according to documents filed by ASIC in the Federal Court.

FIIG Securities, established in 1998, provides retail and wholesale investors with access to fixed income investments and bond financing. It has approximately $4.5 billion in funds under advice.

This failure led to the theft of approximately 385GB of confidential data, ASIC alleged, with some 18,000 clients notified that their personal information might have been compromised.

ASIC alleged FIIG failed to take the appropriate steps from March 2019 to 8 June 2023 to ensure it had adequate cyber risk management systems in place, which is required by an Australian Financial Services Licensee (AFSL).

“FIIG’s cyber security failures enabled a hacker to enter its IT network and go undetected from 19 May 2023 until 8 June 2023, resulting in the theft of personal information and subsequent release of client data on the dark web,” the statement continued.

“The stolen data included highly sensitive customer information, including names, addresses, birth dates, driver’s licences, passports, bank accounts and tax file numbers.”

The regulator stated that FIIG advised ASIC it was contacted by the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) about a potential cyber security incident on 2 June 2023. FIIG was not aware the incident occurred before this contact, ASIC said.

“FIIG did not investigate and respond to the incident until 8 June 2023, almost a week after it had been notified of potential malicious activity by the ASD’s ACSC.”

ASIC chair Joe Longo said the matter should serve as a “wake-up call” to all licensees regarding the dangers of neglecting their cyber security systems.

“Cyber security isn’t a set and forget matter. All companies need to proactively and regularly check the adequacy of their cyber security measures and follow the advice of the ASD’S ACSC,” he commented.

“Advancing digital safety and resilience is a strategic priority for ASIC, and we have been actively engaging with companies to support the continuous improvement of cyber and operational resilience practices.

“Australian financial services licensees are required by law to have adequate cyber security risk management systems in place. We allege FIIG’s inadequate cyber security measures left the business and its confidential client information vulnerable and exposed to significant risk.”

As a result, ASIC is seeking declarations of contraventions, civil penalties and compliance orders.

The announcement marks the regulator’s second cyber security enforcement action, with the first being launched against RI Advice in 2022.

In May 2022, the Federal Court ruled AFSL, RI Advice, had breached its licence obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cyber security risks.

ASIC has continued to flag the case of RI Advice as an example of the need for cyber security measures within a financial services firm.
 

Read more about:

AUTHOR

Recommended for you

sub-bgsidebar subscription

Never miss the latest news and developments in wealth management industry

MARKET INSIGHTS

Significant ethical issues there. If a relationship is in the process of breaking down then both parties are likely to b...

1 day 3 hours ago

It's not licensees not putting them on, it's small businesses (that are licensed) that cannot afford to put them on. The...

1 week 1 day ago

So we are now underwriting criminal scams?...

6 months 1 week ago

Despite the financial adviser exam being rooted in ethics, two professional year advisers believe the lack of support and transparency from the regulator around the exam ...

4 weeks 1 day ago

Australian retirees could increase their projected annual incomes by as much as 51 per cent through comprehensive financial advice, according to a Vanguard study, but cos...

4 weeks ago

After last month’s surprise hold, the Reserve Bank of Australia has announced its latest interest rate decision....

2 days 23 hours ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND
Fund name
3y(%)pa
1
DomaCom DFS Mortgage
74.26 3 y p.a(%)
3