CASE INSIGHTS

Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92

1. Executive Summary

In Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92, Derrington J imposed a $2.5 million pecuniary penalty on FIIG Securities Limited for systemic cybersecurity failures under its Australian financial services licence obligations.

FIIG admitted that, between 13 March 2019 and 8 June 2023, it failed to:

  • do all things necessary to ensure its financial services were provided efficiently, honestly and fairly, contrary to s 912A(1)(a);
  • have adequate financial, technological and human resources, contrary to s 912A(1)(d); and
  • have adequate risk management systems, contrary to s 912A(1)(h).

Each failure constituted a civil penalty contravention under s 912A(5A) of the Corporations Act 2001 (Cth).

The proceeding followed a cyberattack commencing on 19 May 2023. Approximately 385GB of data, including personal information relating to FIIG clients, was downloaded from FIIG’s servers. Screenshots of two documents containing client information were later published on the dark web.

The Court stressed that a successful cyberattack does not, without more, establish a statutory contravention. Financial services licensees are not required to prevent every possible attack. The statutory issue is whether the licensee maintained cybersecurity measures, resources and risk systems that were adequate having regard to its business, information holdings, assets under control and exposure to cyber risk: at [4], [16]–[18].

In addition to the penalty, the Court ordered FIIG to:

  • engage an ASIC-approved independent expert;
  • obtain reports on its cybersecurity and cyber resilience;
  • implement any identified remedial actions;
  • provide a chief executive officer attestation concerning implementation; and
  • pay $500,000 towards ASIC’s costs.

The decision confirms that cybersecurity is not merely an information technology issue. For an AFSL holder, it is a core licensing, operational resilience, risk management and governance obligation.


2. Citation and Context

Case: Australian Securities and Investments Commission v FIIG Securities Limited
Neutral citation: [2026] FCA 92
Court: Federal Court of Australia
Judge: Derrington J
Date of judgment: 13 February 2026
Orders made: 9 February 2026
File: QUD 144 of 2025
Procedural posture: Agreed facts, admissions, declarations, civil penalty, compliance program and costs.

FIIG held AFSL number 224659. Its licence authorised it to provide financial product advice, deal in fixed-income financial products, make a market in certain products, and provide custodial or depository services.

FIIG collected and retained extensive personal information, including names, addresses, dates of birth, identity-document details, tax file numbers, Australian business numbers and bank account details. The nature and sensitivity of that information materially informed the cybersecurity standard reasonably expected of the licensee.


3. The Cybersecurity Risks

The agreed facts recognised a real risk that FIIG could be subjected to a cyberattack and that an attack could cause:

  • unauthorised access to, modification, deletion or publication of client information;
  • disruption or disabling of FIIG’s systems;
  • loss of access to business information;
  • an inability to provide licensed financial services;
  • impersonation of clients or staff;
  • financial loss;
  • exposure of confidential information and trade secrets;
  • legal claims; and
  • substantial reputational harm.

FIIG was aware of these risks throughout the relevant period.

The Court accepted that the reasonable cybersecurity standard depended on FIIG’s circumstances, including:

  • the nature, size and resources of its business;
  • the personal information it held;
  • the value of funds under advice and assets held for clients;
  • the magnitude and possible consequences of cyber risks; and
  • its contractual obligations to clients: at [17].

4. Cybersecurity Control Failures

The agreed facts identified numerous shortcomings extending across incident response, privileged access, vulnerability management, endpoint protection, patching, training and control assurance.

Incident response

Until about January 2023, FIIG did not have a cyber incident response plan that adequately addressed:

  • detection and confirmation of an incident;
  • containment;
  • cause identification;
  • prevention of recurrence;
  • restoration of normal operations;
  • responsible personnel and escalation contacts; and
  • annual testing of the plan.

The absence of a tested response framework reduced FIIG’s capacity to detect, contain and recover from a cyber incident effectively.

Privileged access and passwords

Certain privileged accounts were also used for ordinary, non-privileged activities. Password requirements were inadequate and some privileged passwords were recorded in files stored on FIIG’s network. FIIG also did not conduct quarterly reviews of access rights.

These failures increased the risk that compromised credentials could provide an attacker with elevated access and that unnecessary or inappropriate access rights would remain undetected.

Vulnerability scanning and penetration testing

FIIG did not maintain network or endpoint scanning capabilities sufficient to identify vulnerabilities. It did not systematically run vulnerability scans, assess the results or remediate identified weaknesses.

Its penetration testing was limited. It did not test its external perimeter, internal network and business-critical applications at least annually, or undertake timely testing following material system changes or increased risk.

Firewalls and network configuration

Although FIIG had next-generation firewalls, they were not appropriately configured to restrict unnecessary outbound internet access or prevent direct file-transfer-protocol connections. Insecure NTLMv1 authentication also remained enabled across relevant systems for much of the period.

The case illustrates that purchasing security technology does not establish compliance. Configuration, monitoring, updating and effective operation are equally important.

Endpoint detection and monitoring

FIIG used Carbon Black endpoint detection and response software on only some systems. Software agents were outdated, threat signatures were not updated daily, alerts were not monitored each day by appropriately skilled personnel and the system was not effectively tuned.

Patching

FIIG did not have a comprehensive patching plan or reliable timeframes for installing critical, high, medium and lower-risk security updates. Unsupported systems were not consistently updated or protected through compensating controls.

The judgment specifically records failures to install patches addressing the known EternalBlue and BlueKeep vulnerabilities over extended periods.

Multi-factor authentication

FIIG did not introduce multi-factor authentication for remote-access users until late 2022.

Staff awareness

Cybersecurity awareness training was limited to references to policies during induction and two organisation-wide emails about phishing or spam in 2022. FIIG did not provide mandatory annual training addressing its key cybersecurity risks and expected staff behaviours.

Control testing

FIIG did not maintain processes to assess endpoint protection configurations quarterly, evaluate other technical controls annually, or review organisational cyber resilience at least annually.


5. Contraventions

ActSectionObligationConductFinding
Corporations Act 2001 (Cth)912A(1)(a)Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairlyFIIG failed to maintain cybersecurity measures appropriate to its business, information holdings and cyber risksEstablished
Corporations Act 2001 (Cth)912A(1)(d)Have adequate resources, including financial, technological and human resourcesFIIG underinvested in technology and did not employ or outsource sufficient skilled cybersecurity personnelEstablished
Corporations Act 2001 (Cth)912A(1)(h)Have adequate risk management systemsFIIG failed fully to implement, maintain and monitor controls identified in its own policies and auditsEstablished
Corporations Act 2001 (Cth)912A(5A)Civil penalty provision applying to relevant general-obligation breachesEach of the three failures constituted a civil penalty contraventionThree contraventions

The Court treated the three contraventions as closely interrelated because each arose substantially from FIIG’s inadequate cybersecurity arrangements. However, the risk-management failure also involved a distinct failure to implement and monitor controls that FIIG had itself identified.


6. Efficiently, Honestly and Fairly

Derrington J applied established authority that s 912A(1)(a):

  • does not impose a standard of perfection;
  • is forward-looking and concerned with steps necessary to achieve the statutory standard;
  • requires competence and adequacy; and
  • may be breached where cybersecurity measures fall below the reasonable standard the public is entitled to expect.

The Court accepted that failing to establish adequate cybersecurity measures can constitute a failure to provide financial services efficiently and fairly.

The decision does not establish that every cyber incident is a breach of s 912A(1)(a). The key question is whether the licensee’s preparation, controls and resources were reasonably adequate before the incident.


7. Adequate Resources

Section 912A(1)(d) required FIIG to have sufficient technological, human and financial resources to manage its cybersecurity obligations.

Although FIIG employed between nine and 14 information technology staff, those personnel did not have sufficient cybersecurity expertise, capacity or allocated time, having regard to their other responsibilities. Operational responsibility was delegated to the Chief Operating Officer, but the overall staffing and expertise model remained inadequate.

FIIG also failed to allocate sufficient financial resources to implement appropriate cybersecurity technology or engage suitably skilled internal or external specialists.

A headcount alone therefore does not demonstrate adequate resourcing. Licensees need to assess:

  • specialist capability;
  • responsibility and authority;
  • workload and available time;
  • access to external expertise;
  • technology investment; and
  • whether resources are proportionate to the risks faced.

8. Risk Management Systems

The Court accepted that an adequate cybersecurity risk management system required FIIG to:

  1. identify and assess cyber risks;
  2. identify and establish suitable controls;
  3. implement and maintain those controls; and
  4. monitor whether the controls remained effective.

FIIG failed fully to implement and monitor controls appearing in its own information security policies and annual custodial-services audits. That failure established the s 912A(1)(h) contravention.

The decision is especially significant for audit and compliance functions. A policy, risk register or audit recommendation may aggravate rather than reduce exposure where it demonstrates that the organisation identified a risk or control but failed to implement it.


9. Cyberattack and Customer Impact

The Court did not find that FIIG’s failures conclusively caused the cyberattack or that adequate controls would necessarily have prevented it.

The agreed position was more qualified: if appropriate measures and identified risk controls had been in place by 19 May 2023, there was an increased chance FIIG could have detected the attack, activated its incident response sooner and prevented some or all of the client information from being downloaded.

FIIG incurred approximately $1.5 million in remediation costs. The consequences for clients whose personal information was compromised could not be quantified but were potentially significant, including the ongoing risk of misuse by malicious actors.


10. Penalty

The Court imposed the jointly proposed $2.5 million penalty.

The maximum available penalty for the three contraventions was calculated at $41.25 million, but the Court considered the contraventions to form a substantially overlapping course of conduct.

Relevant factors included:

  • the contraventions continued for approximately four years and three months;
  • FIIG knew that material cybersecurity risks existed;
  • the failures arose from inadequate investment rather than deliberate wrongdoing;
  • FIIG had no previous comparable contraventions;
  • FIIG cooperated fully with ASIC and made admissions;
  • FIIG incurred significant remediation costs;
  • the penalty represented about 20% of FIIG’s net assets and 8% of its 2025 turnover; and
  • the estimated cost of compliant cybersecurity measures during the relevant period was approximately $1.2 million.

The Court considered that the penalty delivered an appropriate deterrent “sting” and ensured that non-compliance was not economically preferable to proper cybersecurity investment.


11. Compliance Program

Under s 1101B, FIIG must engage an independent expert agreed with ASIC.

The expert must:

  • assess FIIG’s cybersecurity and cyber resilience arrangements;
  • identify further necessary documentation, resources and controls;
  • prepare an initial report;
  • oversee a timetable for remedial actions; and
  • prepare a final implementation report.

FIIG’s CEO must then attest that they have read and understood the reports, made reasonable inquiries and are satisfied that the remedial actions have been implemented. FIIG must bear the expert and remediation costs.


12. Risk Management and Compliance Recommendations

AudienceControl typeRisk indicatorPractical control
BoardGovernanceCyber investment materially below assessed riskBoard-approved cyber strategy, budget and risk appetite
Executive managementGovernanceCyber responsibility added to a general operational roleDedicated accountable executive with clear authority
TechnologyPreventativePrivileged accounts used for ordinary workSeparate privileged identities and secure credential storage
Security operationsDetectiveEndpoint alerts not monitored dailySkilled continuous or daily monitoring and escalation
Vulnerability managementPreventativeNo systematic scanning or patch scheduleRisk-based scanning and mandatory remediation timeframes
Incident responseCorrectiveResponse plan untested or incompleteAnnual simulation and documented lessons learned
Human resourcesPreventativeTraining limited to induction or emailsMandatory annual role-based security training
Risk functionGovernanceControls appear in policies but are not implementedControl ownership, implementation evidence and effectiveness testing
Internal auditDetectiveAssurance focuses on policy existenceTechnical testing of control design and operation
Board risk committeeGovernanceCyber metrics report activity rather than exposureReporting on vulnerabilities, patch age, privileged access and incident readiness

13. Recommended Next Steps

AFSL holders should:

  1. benchmark cybersecurity controls against the nature, scale and complexity of the licensed business;
  2. identify the personal and confidential information held and assess the impact of compromise;
  3. document required technological, human and financial resources;
  4. maintain and test a complete cyber incident response plan;
  5. separate privileged and ordinary user access;
  6. conduct systematic vulnerability scanning and annual penetration testing;
  7. apply risk-based patching deadlines and document exceptions;
  8. require multi-factor authentication for remote and privileged access;
  9. provide mandatory annual cybersecurity training;
  10. monitor whether controls required by policies, audits and risk registers are actually implemented; and
  11. provide the board with outcome-based reporting on cyber risk and resilience.

This analysis is suitable for internal legal and compliance review, but cyber-control requirements should be adapted to each licensee’s business, information holdings, threat environment and current technical standards.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?