CASE INSIGHTS

Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496

1. Executive summary

In Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496, Rofe J declared that RI Advice contravened ss 912A(1)(a) and 912A(1)(h) of the Corporations Act 2001 (Cth) by failing to maintain and adequately implement cybersecurity and cyber-resilience documentation, controls and risk-management systems across its authorised representative network.

RI Advice operated under a third-party business-owner model. Independently owned authorised representatives provided financial services to retail clients under RI Advice’s Australian financial services licence and electronically held sensitive client information, including identification documents, financial information and, in some cases, health information. Since 15 May 2018, the network had provided services to at least 60,000 retail clients.

Between June 2014 and May 2020, nine cybersecurity incidents occurred at authorised representative practices. Those incidents included compromised email accounts, phishing, ransomware, server intrusion, loss of client files and unauthorised access to personal information affecting several thousand clients. Investigations identified basic control failures, including outdated antivirus software, inadequate email filtering, missing backups, shared passwords and insecure storage of access credentials.

RI Advice admitted that, as at 15 May 2018, its cybersecurity documentation, controls and risk-management systems were inadequate. It later introduced significant improvements, but accepted that implementation across its network took too long. The declared contravention continued from 15 May 2018 until 5 August 2021.

The Court ordered RI Advice to engage an external cybersecurity expert to assess whether further measures were required, report to ASIC and oversee implementation. RI Advice was also ordered to pay $750,000 as a contribution to ASIC’s costs. No pecuniary penalty was imposed.

The decision is important because it establishes that cybersecurity is not merely an information-technology issue. For an AFS licensee, inadequate cyber controls can constitute:

  • a failure to ensure financial services are provided efficiently and fairly under s 912A(1)(a); and
  • a failure to maintain adequate risk-management systems under s 912A(1)(h).

The judgment also confirms that licensees remain responsible for cyber-risk management across authorised representative networks, even where representatives are independently owned and operate their own technology environments.


2. Citation and context

Case: Australian Securities and Investments Commission v RI Advice Group Pty Ltd
Neutral citation: [2022] FCA 496
Court: Federal Court of Australia
Judge: Rofe J
Judgment and orders: 5 May 2022
Proceeding: VID 556 of 2020
Registry: Victoria
Nature of proceeding: Agreed declarations and compliance orders concerning cybersecurity and cyber-resilience failures.

ASIC commenced the proceeding on 21 August 2020. It initially alleged contraventions of several general licensee obligations and sought declarations, a pecuniary penalty and compliance orders. The matter settled before the final hearing. RI Advice admitted contraventions of ss 912A(1)(a) and 912A(1)(h), and the parties submitted an agreed statement of facts and proposed orders. The Court independently determined that the agreed declarations and orders were appropriate.


3. Business and operating model

RI Advice held AFSL number 238429 and authorised independently owned corporate and individual authorised representatives to provide financial services on its behalf.

The authorised representative practices received, stored and accessed extensive confidential and sensitive client information, including:

  • names, residential addresses and dates of birth;
  • telephone numbers and email addresses;
  • driver licences and passports;
  • financial information; and
  • some health information.

There were approximately 89 to 119 authorised representative practices during the relevant period. The decentralised nature of the network created a material governance challenge: cybersecurity controls had to be implemented consistently across independently operated businesses with different systems, personnel and technology providers.

That operating model did not displace RI Advice’s obligations as the licensee. The financial services were provided under its licence, and cyber risk arising within the representative network was therefore a risk connected with the provision of those services.


4. Cybersecurity incidents

The nine incidents identified in the agreed facts included:

PeriodIncidentConsequence
June 2014Adviser email account compromisedFive clients received fraudulent investment emails; one client transferred about $50,000
June 2015Third-party website provider hackedFake webpage placed over the practice’s website
September 2016Fraudulent email apparently sent by practice employeeClient received a false request for money
January 2017Ransomware attackFiles became inaccessible
May 2017Server compromised through remote-access portInformation relating to about 220 clients was held for ransom and not recovered
December 2017–April 2018Prolonged unauthorised server accessPersonal information of several thousand clients was compromised
May 2018Adviser email account compromisedFraudulent bank-transfer request sent to bookkeeper
August 2019Employee email account compromisedPhishing emails sent to more than 150 clients
April 2020Repeat the compromise of the same email addressFurther phishing emails sent to contacts

The incidents showed that the risks were neither hypothetical nor isolated. They reflected recurring weaknesses across the authorised representative network and demonstrated the potential for financial loss, identity misuse, privacy harm and disruption to client services.


5. Control deficiencies

Investigations following the incidents identified weaknesses including:

  • antivirus software that was absent or out of date;
  • no filtering or quarantining of incoming email;
  • inadequate or non-existent backup arrangements;
  • shared passwords;
  • default passwords that had not been changed;
  • passwords and access information stored insecurely;
  • credentials known to third parties;
  • inconsistent use of multifactor authentication;
  • inadequate monitoring of compliance by authorised representatives; and
  • delayed implementation of minimum cybersecurity practices.

RI Advice had taken some measures before May 2018, including training, newsletter communications, incident reporting and contractual professional standards. Those measures included recommendations on password protection, software updates, backups and secure email use. However, RI Advice admitted that the overall documentation, controls and risk-management systems were not adequate.

The key failure was therefore not a complete absence of cyber activity. It was the lack of an effective, consistently implemented and verified control framework across the entire network.


6. Contraventions

ActSectionObligationConductFinding
Corporations Act 2001 (Cth)s 912A(1)(a)Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairlyRI Advice failed to ensure adequate cybersecurity measures were implemented across its authorised representative networkContravention from 15 May 2018 to 5 August 2021
Corporations Act 2001 (Cth)s 912A(1)(h)Maintain adequate risk-management systemsCybersecurity and cyber-resilience systems left clients exposed to an unacceptable level of riskContravention from 15 May 2018 to 5 August 2021

The declaration concerning s 912A(1)(a) referred specifically to a failure to ensure that financial services were provided efficiently and fairly. ASIC did not allege, and RI Advice did not admit, dishonest conduct.


7. Key legal principles

Cybersecurity is part of an AFS licensee’s general obligations

The Court accepted that the broad obligations in ss 912A(1)(a) and 912A(1)(h) required RI Advice to:

  • identify cybersecurity and cyber-resilience risks arising in the provision of financial services; and
  • maintain adequate documentation, controls and risk-management systems across its authorised representative network.

Cyber risk was therefore directly connected with the licensee’s regulated activities, rather than being a peripheral technology matter.

A breach of s 912A(1)(a) does not require dishonesty

The Court reiterated that conduct may fail to meet the efficiently, honestly and fairly standard even where it is not dishonest or morally improper. Acts or omissions may contravene the provision because the licensee failed to act efficiently and fairly.

For internal breach assessments, the absence of fraud, bad faith or intentional misconduct does not resolve the issue. Inadequate procedures, training, oversight or implementation may independently breach the obligation.

A separate statutory breach is unnecessary

A contravention of s 912A(1)(a) does not depend on proving a breach of another statutory, contractual, common-law or fiduciary duty. The general obligation is itself the source of the legal standard.

This is significant where a cyber incident does not clearly breach a prescriptive financial services provision. The licensee may still face regulatory exposure if its systems fall below the required standard.

“Adequate” is a contextual and technical standard

Section 912A(1)(h) requires adequate risk-management systems. The Court observed that adequacy is a normative standard assessed by reference to the risks faced by the particular business.

In cybersecurity matters, the assessment is technically complex and is likely to require evidence from appropriately qualified experts. The general public’s expectations do not determine the specific content of an adequate cybersecurity framework.

The practical implication is that licensees should obtain specialist cyber-risk advice, rather than relying exclusively on legal, compliance or management judgement.

Cyber risk cannot be eliminated, but it must be reduced

The Court recognised that cybersecurity risk evolves and cannot be reduced to zero. However, adequate documentation and controls can materially reduce that risk to an acceptable level.

The obligation is therefore not strict liability for every cyber incident. A licensee is not necessarily in breach simply because an attack succeeds. The regulatory question is whether its framework was appropriately designed, implemented, monitored and improved, having regard to its risk profile.

Implementation speed is part of adequacy

RI Advice developed a range of controls, standards and remediation initiatives, but admitted that implementation took too long. By 6 August 2021, the majority of practices had implemented most identified good practices to an acceptable level, but the licensee accepted that this should have occurred earlier.

A sound policy or planned control is not sufficient where material risks remain unmanaged during a prolonged rollout. Licensees must assess urgency, establish deadlines and verify completion.


8. Remediation undertaken

Following its acquisition by the IOOF group, RI Advice implemented significant improvements, including:

  • external cybersecurity reviews;
  • a Cyber Security Support Guide;
  • mandatory multifactor authentication;
  • cybersecurity training and assessments;
  • minimum cybersecurity standards;
  • centralised storage requirements for client records;
  • a cybersecurity incident-response process;
  • practice-level gap assessments;
  • cybersecurity insurance requirements for new representatives;
  • remediation plans and close-out reports; and
  • independent review through the Cyber Resilience Initiative.

Security In Depth assessed practices against 11 cybersecurity practices and issued initial and close-out reports. By 6 August 2021, the majority of practices had implemented most measures to a good level.

These measures were relevant to the agreed resolution, but did not erase the historical contraventions.


9. Orders and remedies

OrderLegal basisScope
Declaration of contraventions 21, Federal Court of Australia Act 1976; s 1101B, Corporations ActContraventions of ss 912A(1)(a) and 912A(1)(h) from 15 May 2018 to 5 August 2021
External expert reviews 1101BSecurity In Depth, or another agreed expert, to identify any further required cyber measures
Implementation obligationss 1101BRI Advice to commence and complete any further measures within agreed timeframes
Reporting to ASICs 1101BExpert reports on required measures and implementation outcomes
CostsCourt orderRI Advice to pay $750,000 toward ASIC’s costs
Remaining claimsCourt orderProceeding otherwise dismissed

No pecuniary penalty was ordered. The outcome centred on declarations, forward-looking compliance obligations and costs.

The compliance orders were appropriate because clients had faced an unacceptable level of risk and an independent expert assessment was necessary to determine whether RI Advice’s current framework required further improvement.


10. Relevance for AFS licensees and authorised representatives

The judgment has direct implications for licensees operating through decentralised advice practices, corporate authorised representatives, outsourced providers or franchise-style networks.

A licensee cannot rely solely on:

  • contractual obligations imposed on representatives;
  • optional guidance;
  • self-attestation;
  • general awareness training;
  • technology-provider assurances; or
  • incident response after an attack.

The licensee must be able to demonstrate that controls are:

  1. proportionate to the information and systems at risk;
  2. mandatory where appropriate;
  3. implemented across the network;
  4. independently tested or otherwise verified;
  5. monitored on an ongoing basis;
  6. updated as threats evolve; and
  7. supported by effective incident escalation and remediation.

The case also demonstrates that authorised representatives’ technology arrangements are within the licensee’s regulatory risk perimeter where those representatives provide services under the licence.


11. Recommended controls

AudienceControl typeLegal rationaleRisk indicatorPractical control
Board and risk committeeGovernancess 912A(1)(a) and (h)Decentralised representative networkApprove cyber-risk appetite and receive implementation reporting
Licensee managementGovernanceLicensee remains responsible for AR networkControls delegated to independently owned practicesAssign accountable executive ownership
AR onboardingPreventativeCyber risk must be assessed before authorisationLegacy systems or unsupported softwareConduct technical due diligence before appointment
Technology securityPreventativeSensitive client information requires protectionShared passwords or single-factor accessMandate MFA, encryption and access controls
Compliance monitoringDetectivePolicies must be implemented and effectiveReliance on self-attestationTest practices through evidence-based audits
Incident managementCorrectiveCyber incidents may affect financial services and clientsPhishing, ransomware or data accessImplement mandatory escalation and response timeframes
Data governancePreventativeClient records must be stored securelyLocal drives and personal email accountsRequire approved central document repositories
Business continuityCorrectiveServices must remain resilientMissing or untested backupsMaintain isolated backups and recovery testing
Third-party managementPreventativeExternal vendors create cyber exposureUnassessed IT or website providerApply security standards and contractual audit rights
Internal auditDetectiveIndependent assurance supports adequacyRepeated unresolved cyber findingsConduct periodic end-to-end maturity reviews

12. Recommended next steps

AFS licensees should:

  • map where client information is stored and accessed across their representative network;
  • establish minimum mandatory cybersecurity controls;
  • identify practices that do not meet those controls;
  • impose risk-based remediation deadlines;
  • verify implementation through technical evidence;
  • review multifactor authentication, backups, patching and email security;
  • test incident-response and business-continuity arrangements;
  • integrate cyber incidents into breach-reporting assessments;
  • assess whether third-party providers meet the licensee’s standards; and
  • provide the board with clear reporting on overdue gaps and residual risk.

13. Broader impact

  • Signals ASIC’s increased focus on non-financial risks, including technology and operational risks
  • May lead to increased investment in cybersecurity measures across the financial services industry
  • Highlights the potential for cybersecurity breaches to result in significant financial and operational impacts
  • Demonstrates the evolving nature of AFS Licence obligations in response to technological changes
  • Reflects the growing importance of digital resilience in the financial services sector
  • This landmark case sets a precedent that cybersecurity is not just an IT issue but a fundamental aspect of an AFS Licensee’s compliance obligations. It underscores that cybersecurity risk management should be ongoing, not a one-time implementation.
  • For advisers, it emphasises the importance of adhering to cybersecurity policies and procedures set by their licensee. It also highlights the need for continuous training and awareness about cybersecurity risks and best practices.
  • This case could influence legislative changes or amendments to the Corporations Act to incorporate more explicit requirements regarding cybersecurity, reflecting ongoing legislative responsiveness to technological risks.
  • It’s important to note that the decision was based on an agreed statement of facts and joint proposals for declarations and orders by both parties. This emphasises the cooperative aspect of the resolution and the consensual nature of the orders.

AFS Licensees should view this case as a prompt to review and potentially upgrade their cybersecurity measures, encompassing technical controls, policies, procedures, and staff training.

The Court’s order for an external cybersecurity expert review aligns with a broader regulatory trend towards independent assurance of compliance systems. This suggests that all AFS licensees should consider regular independent reviews of cybersecurity measures as a preventative step.

Ultimately, this case reflects ASIC’s view that robust cybersecurity measures are integral to a licensee’s obligation to provide financial services ‘efficiently, honestly and fairly’, signalling a new era of regulatory focus on digital resilience in the financial sector.

This analysis is suitable for internal legal and compliance review, but final positions should be confirmed against the complete source material, current legislation and any subsequent regulatory developments.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?