1. Executive Summary
In Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92, Derrington J imposed a $2.5 million pecuniary penalty on FIIG Securities Limited for systemic cybersecurity failures under its Australian financial services licence obligations.
FIIG admitted that, between 13 March 2019 and 8 June 2023, it failed to:
- do all things necessary to ensure its financial services were provided efficiently, honestly and fairly, contrary to s 912A(1)(a);
- have adequate financial, technological and human resources, contrary to s 912A(1)(d); and
- have adequate risk management systems, contrary to s 912A(1)(h).
Each failure constituted a civil penalty contravention under s 912A(5A) of the Corporations Act 2001 (Cth).
The proceeding followed a cyberattack commencing on 19 May 2023. Approximately 385GB of data, including personal information relating to FIIG clients, was downloaded from FIIG’s servers. Screenshots of two documents containing client information were later published on the dark web.
The Court stressed that a successful cyberattack does not, without more, establish a statutory contravention. Financial services licensees are not required to prevent every possible attack. The statutory issue is whether the licensee maintained cybersecurity measures, resources and risk systems that were adequate having regard to its business, information holdings, assets under control and exposure to cyber risk: at [4], [16]–[18].
In addition to the penalty, the Court ordered FIIG to:
- engage an ASIC-approved independent expert;
- obtain reports on its cybersecurity and cyber resilience;
- implement any identified remedial actions;
- provide a chief executive officer attestation concerning implementation; and
- pay $500,000 towards ASIC’s costs.
The decision confirms that cybersecurity is not merely an information technology issue. For an AFSL holder, it is a core licensing, operational resilience, risk management and governance obligation.
2. Citation and Context
Case: Australian Securities and Investments Commission v FIIG Securities Limited
Neutral citation: [2026] FCA 92
Court: Federal Court of Australia
Judge: Derrington J
Date of judgment: 13 February 2026
Orders made: 9 February 2026
File: QUD 144 of 2025
Procedural posture: Agreed facts, admissions, declarations, civil penalty, compliance program and costs.
FIIG held AFSL number 224659. Its licence authorised it to provide financial product advice, deal in fixed-income financial products, make a market in certain products, and provide custodial or depository services.
FIIG collected and retained extensive personal information, including names, addresses, dates of birth, identity-document details, tax file numbers, Australian business numbers and bank account details. The nature and sensitivity of that information materially informed the cybersecurity standard reasonably expected of the licensee.
3. The Cybersecurity Risks
The agreed facts recognised a real risk that FIIG could be subjected to a cyberattack and that an attack could cause:
- unauthorised access to, modification, deletion or publication of client information;
- disruption or disabling of FIIG’s systems;
- loss of access to business information;
- an inability to provide licensed financial services;
- impersonation of clients or staff;
- financial loss;
- exposure of confidential information and trade secrets;
- legal claims; and
- substantial reputational harm.
FIIG was aware of these risks throughout the relevant period.
The Court accepted that the reasonable cybersecurity standard depended on FIIG’s circumstances, including:
- the nature, size and resources of its business;
- the personal information it held;
- the value of funds under advice and assets held for clients;
- the magnitude and possible consequences of cyber risks; and
- its contractual obligations to clients: at [17].
4. Cybersecurity Control Failures
The agreed facts identified numerous shortcomings extending across incident response, privileged access, vulnerability management, endpoint protection, patching, training and control assurance.
Incident response
Until about January 2023, FIIG did not have a cyber incident response plan that adequately addressed:
- detection and confirmation of an incident;
- containment;
- cause identification;
- prevention of recurrence;
- restoration of normal operations;
- responsible personnel and escalation contacts; and
- annual testing of the plan.
The absence of a tested response framework reduced FIIG’s capacity to detect, contain and recover from a cyber incident effectively.
Privileged access and passwords
Certain privileged accounts were also used for ordinary, non-privileged activities. Password requirements were inadequate and some privileged passwords were recorded in files stored on FIIG’s network. FIIG also did not conduct quarterly reviews of access rights.
These failures increased the risk that compromised credentials could provide an attacker with elevated access and that unnecessary or inappropriate access rights would remain undetected.
Vulnerability scanning and penetration testing
FIIG did not maintain network or endpoint scanning capabilities sufficient to identify vulnerabilities. It did not systematically run vulnerability scans, assess the results or remediate identified weaknesses.
Its penetration testing was limited. It did not test its external perimeter, internal network and business-critical applications at least annually, or undertake timely testing following material system changes or increased risk.
Firewalls and network configuration
Although FIIG had next-generation firewalls, they were not appropriately configured to restrict unnecessary outbound internet access or prevent direct file-transfer-protocol connections. Insecure NTLMv1 authentication also remained enabled across relevant systems for much of the period.
The case illustrates that purchasing security technology does not establish compliance. Configuration, monitoring, updating and effective operation are equally important.
Endpoint detection and monitoring
FIIG used Carbon Black endpoint detection and response software on only some systems. Software agents were outdated, threat signatures were not updated daily, alerts were not monitored each day by appropriately skilled personnel and the system was not effectively tuned.
Patching
FIIG did not have a comprehensive patching plan or reliable timeframes for installing critical, high, medium and lower-risk security updates. Unsupported systems were not consistently updated or protected through compensating controls.
The judgment specifically records failures to install patches addressing the known EternalBlue and BlueKeep vulnerabilities over extended periods.
Multi-factor authentication
FIIG did not introduce multi-factor authentication for remote-access users until late 2022.
Staff awareness
Cybersecurity awareness training was limited to references to policies during induction and two organisation-wide emails about phishing or spam in 2022. FIIG did not provide mandatory annual training addressing its key cybersecurity risks and expected staff behaviours.
Control testing
FIIG did not maintain processes to assess endpoint protection configurations quarterly, evaluate other technical controls annually, or review organisational cyber resilience at least annually.
5. Contraventions
| Act | Section | Obligation | Conduct | Finding |
|---|---|---|---|---|
| Corporations Act 2001 (Cth) | 912A(1)(a) | Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairly | FIIG failed to maintain cybersecurity measures appropriate to its business, information holdings and cyber risks | Established |
| Corporations Act 2001 (Cth) | 912A(1)(d) | Have adequate resources, including financial, technological and human resources | FIIG underinvested in technology and did not employ or outsource sufficient skilled cybersecurity personnel | Established |
| Corporations Act 2001 (Cth) | 912A(1)(h) | Have adequate risk management systems | FIIG failed fully to implement, maintain and monitor controls identified in its own policies and audits | Established |
| Corporations Act 2001 (Cth) | 912A(5A) | Civil penalty provision applying to relevant general-obligation breaches | Each of the three failures constituted a civil penalty contravention | Three contraventions |
The Court treated the three contraventions as closely interrelated because each arose substantially from FIIG’s inadequate cybersecurity arrangements. However, the risk-management failure also involved a distinct failure to implement and monitor controls that FIIG had itself identified.
6. Efficiently, Honestly and Fairly
Derrington J applied established authority that s 912A(1)(a):
- does not impose a standard of perfection;
- is forward-looking and concerned with steps necessary to achieve the statutory standard;
- requires competence and adequacy; and
- may be breached where cybersecurity measures fall below the reasonable standard the public is entitled to expect.
The Court accepted that failing to establish adequate cybersecurity measures can constitute a failure to provide financial services efficiently and fairly.
The decision does not establish that every cyber incident is a breach of s 912A(1)(a). The key question is whether the licensee’s preparation, controls and resources were reasonably adequate before the incident.
7. Adequate Resources
Section 912A(1)(d) required FIIG to have sufficient technological, human and financial resources to manage its cybersecurity obligations.
Although FIIG employed between nine and 14 information technology staff, those personnel did not have sufficient cybersecurity expertise, capacity or allocated time, having regard to their other responsibilities. Operational responsibility was delegated to the Chief Operating Officer, but the overall staffing and expertise model remained inadequate.
FIIG also failed to allocate sufficient financial resources to implement appropriate cybersecurity technology or engage suitably skilled internal or external specialists.
A headcount alone therefore does not demonstrate adequate resourcing. Licensees need to assess:
- specialist capability;
- responsibility and authority;
- workload and available time;
- access to external expertise;
- technology investment; and
- whether resources are proportionate to the risks faced.
8. Risk Management Systems
The Court accepted that an adequate cybersecurity risk management system required FIIG to:
- identify and assess cyber risks;
- identify and establish suitable controls;
- implement and maintain those controls; and
- monitor whether the controls remained effective.
FIIG failed fully to implement and monitor controls appearing in its own information security policies and annual custodial-services audits. That failure established the s 912A(1)(h) contravention.
The decision is especially significant for audit and compliance functions. A policy, risk register or audit recommendation may aggravate rather than reduce exposure where it demonstrates that the organisation identified a risk or control but failed to implement it.
9. Cyberattack and Customer Impact
The Court did not find that FIIG’s failures conclusively caused the cyberattack or that adequate controls would necessarily have prevented it.
The agreed position was more qualified: if appropriate measures and identified risk controls had been in place by 19 May 2023, there was an increased chance FIIG could have detected the attack, activated its incident response sooner and prevented some or all of the client information from being downloaded.
FIIG incurred approximately $1.5 million in remediation costs. The consequences for clients whose personal information was compromised could not be quantified but were potentially significant, including the ongoing risk of misuse by malicious actors.
10. Penalty
The Court imposed the jointly proposed $2.5 million penalty.
The maximum available penalty for the three contraventions was calculated at $41.25 million, but the Court considered the contraventions to form a substantially overlapping course of conduct.
Relevant factors included:
- the contraventions continued for approximately four years and three months;
- FIIG knew that material cybersecurity risks existed;
- the failures arose from inadequate investment rather than deliberate wrongdoing;
- FIIG had no previous comparable contraventions;
- FIIG cooperated fully with ASIC and made admissions;
- FIIG incurred significant remediation costs;
- the penalty represented about 20% of FIIG’s net assets and 8% of its 2025 turnover; and
- the estimated cost of compliant cybersecurity measures during the relevant period was approximately $1.2 million.
The Court considered that the penalty delivered an appropriate deterrent “sting” and ensured that non-compliance was not economically preferable to proper cybersecurity investment.
11. Compliance Program
Under s 1101B, FIIG must engage an independent expert agreed with ASIC.
The expert must:
- assess FIIG’s cybersecurity and cyber resilience arrangements;
- identify further necessary documentation, resources and controls;
- prepare an initial report;
- oversee a timetable for remedial actions; and
- prepare a final implementation report.
FIIG’s CEO must then attest that they have read and understood the reports, made reasonable inquiries and are satisfied that the remedial actions have been implemented. FIIG must bear the expert and remediation costs.
12. Risk Management and Compliance Recommendations
| Audience | Control type | Risk indicator | Practical control |
|---|---|---|---|
| Board | Governance | Cyber investment materially below assessed risk | Board-approved cyber strategy, budget and risk appetite |
| Executive management | Governance | Cyber responsibility added to a general operational role | Dedicated accountable executive with clear authority |
| Technology | Preventative | Privileged accounts used for ordinary work | Separate privileged identities and secure credential storage |
| Security operations | Detective | Endpoint alerts not monitored daily | Skilled continuous or daily monitoring and escalation |
| Vulnerability management | Preventative | No systematic scanning or patch schedule | Risk-based scanning and mandatory remediation timeframes |
| Incident response | Corrective | Response plan untested or incomplete | Annual simulation and documented lessons learned |
| Human resources | Preventative | Training limited to induction or emails | Mandatory annual role-based security training |
| Risk function | Governance | Controls appear in policies but are not implemented | Control ownership, implementation evidence and effectiveness testing |
| Internal audit | Detective | Assurance focuses on policy existence | Technical testing of control design and operation |
| Board risk committee | Governance | Cyber metrics report activity rather than exposure | Reporting on vulnerabilities, patch age, privileged access and incident readiness |
13. Recommended Next Steps
AFSL holders should:
- benchmark cybersecurity controls against the nature, scale and complexity of the licensed business;
- identify the personal and confidential information held and assess the impact of compromise;
- document required technological, human and financial resources;
- maintain and test a complete cyber incident response plan;
- separate privileged and ordinary user access;
- conduct systematic vulnerability scanning and annual penetration testing;
- apply risk-based patching deadlines and document exceptions;
- require multi-factor authentication for remote and privileged access;
- provide mandatory annual cybersecurity training;
- monitor whether controls required by policies, audits and risk registers are actually implemented; and
- provide the board with outcome-based reporting on cyber risk and resilience.
This analysis is suitable for internal legal and compliance review, but cyber-control requirements should be adapted to each licensee’s business, information holdings, threat environment and current technical standards.