Advice firms represent data ‘treasure chest’ for hackers

4 August 2022
| By Laura Dew |
image
image
expand image

Advisers should not be complacent about cyber attacks, even if they are a small firm, as they are sitting on a volume of valuable data for a hacker.

In a webinar, AFA national chair, Ashley Mahadeea, and Fraser Jack, founder of the Cyber Collective Australia, discussed the biggest threats to cybersecurity for advice firms.

“Financial advice firms are 300x more likely to be hacked than other firms, it’s a valuable treasure chest of information. Clients give so much information because they trust the adviser to look after it and that would be very valuable for a hacker.

“Data is an extension of a person’s life and an adviser should look after the data just as they would look after the client.”

If data was extracted from an advice firm’s practice, clients’ identities and accounts could be stolen for gambling or drug syndicates or tax returns could be amended among other problems.

As to what advisers needed to do if an attack happened, Jack said there were multiple agencies that advisers were obligated to contact.

“Number one, they are obligated to let their clients know that their information has been taken, especially if it’s credentials so they can update their passwords and protect them. Then there’s reporting obligations for breaches within the Corporations Act that’s about notifying their licensee and reporting obligations for other government agencies

“So there is a lot of requirements to report and advisers have to fall on their sword and tell their clients that they were unable to protect them when they gave you trusted information.

As to what firms should do, Jack said it should be a high priority for them as there could be high fines and litigation costs if a firm was found to not have taken reasonable steps to prevent against an attack.

Earlier this year, the regulator warned cybersecurity breaches could incur penalties as high as $525 million while it made its first cyber attack ruling in May regarding RI Advice. RI Advice was found to have breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks.

Jack said: “Licensees will be coming to advisers, if they haven’t done so already, to provide evidence they are doing the right thing because they need to report it to the regulator. The stakes are high because they could lose the trust of their clients, they could lose their business and lose their reputation.

“The cost of putting something like this in place is less than 1% of their turnover and less than 1% of their time so it’s not a big cost to implement.

“The stakes are too high, the chances of it happening are very high and the cost to fix it is reasonably low.”

Read more about:

AUTHOR

 

Recommended for you

 

MARKET INSIGHTS

sub-bg sidebar subscription

Never miss the latest news and developments in wealth management industry

Squeaky'21

My view is that after 2026 there will be quite a bit less than 10,000 'advisers' (investment advisers) and less than 100...

4 days 13 hours ago
Jason Warlond

Dugald makes a great point that not everyone's definition of green is the same and gives a good example. Funds have bee...

4 days 14 hours ago
Jasmin Jakupovic

How did they get the AFSL in the first place? Given the green light by ASIC. This is terrible example of ASIC's incompet...

5 days 13 hours ago

AustralianSuper and Australian Retirement Trust have posted the financial results for the 2022–23 financial year for their combined 5.3 million members....

9 months 1 week ago

A $34 billion fund has come out on top with a 13.3 per cent return in the last 12 months, beating out mega funds like Australian Retirement Trust and Aware Super. ...

8 months 4 weeks ago

The verdict in the class action case against AMP Financial Planning has been delivered in the Federal Court by Justice Moshinsky....

9 months 1 week ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND