1. Executive summary
In Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496, Rofe J declared that RI Advice contravened ss 912A(1)(a) and 912A(1)(h) of the Corporations Act 2001 (Cth) by failing to maintain and adequately implement cybersecurity and cyber-resilience documentation, controls and risk-management systems across its authorised representative network.
RI Advice operated under a third-party business-owner model. Independently owned authorised representatives provided financial services to retail clients under RI Advice’s Australian financial services licence and electronically held sensitive client information, including identification documents, financial information and, in some cases, health information. Since 15 May 2018, the network had provided services to at least 60,000 retail clients.
Between June 2014 and May 2020, nine cybersecurity incidents occurred at authorised representative practices. Those incidents included compromised email accounts, phishing, ransomware, server intrusion, loss of client files and unauthorised access to personal information affecting several thousand clients. Investigations identified basic control failures, including outdated antivirus software, inadequate email filtering, missing backups, shared passwords and insecure storage of access credentials.
RI Advice admitted that, as at 15 May 2018, its cybersecurity documentation, controls and risk-management systems were inadequate. It later introduced significant improvements, but accepted that implementation across its network took too long. The declared contravention continued from 15 May 2018 until 5 August 2021.
The Court ordered RI Advice to engage an external cybersecurity expert to assess whether further measures were required, report to ASIC and oversee implementation. RI Advice was also ordered to pay $750,000 as a contribution to ASIC’s costs. No pecuniary penalty was imposed.
The decision is important because it establishes that cybersecurity is not merely an information-technology issue. For an AFS licensee, inadequate cyber controls can constitute:
- a failure to ensure financial services are provided efficiently and fairly under s 912A(1)(a); and
- a failure to maintain adequate risk-management systems under s 912A(1)(h).
The judgment also confirms that licensees remain responsible for cyber-risk management across authorised representative networks, even where representatives are independently owned and operate their own technology environments.
2. Citation and context
Case: Australian Securities and Investments Commission v RI Advice Group Pty Ltd
Neutral citation: [2022] FCA 496
Court: Federal Court of Australia
Judge: Rofe J
Judgment and orders: 5 May 2022
Proceeding: VID 556 of 2020
Registry: Victoria
Nature of proceeding: Agreed declarations and compliance orders concerning cybersecurity and cyber-resilience failures.
ASIC commenced the proceeding on 21 August 2020. It initially alleged contraventions of several general licensee obligations and sought declarations, a pecuniary penalty and compliance orders. The matter settled before the final hearing. RI Advice admitted contraventions of ss 912A(1)(a) and 912A(1)(h), and the parties submitted an agreed statement of facts and proposed orders. The Court independently determined that the agreed declarations and orders were appropriate.
3. Business and operating model
RI Advice held AFSL number 238429 and authorised independently owned corporate and individual authorised representatives to provide financial services on its behalf.
The authorised representative practices received, stored and accessed extensive confidential and sensitive client information, including:
- names, residential addresses and dates of birth;
- telephone numbers and email addresses;
- driver licences and passports;
- financial information; and
- some health information.
There were approximately 89 to 119 authorised representative practices during the relevant period. The decentralised nature of the network created a material governance challenge: cybersecurity controls had to be implemented consistently across independently operated businesses with different systems, personnel and technology providers.
That operating model did not displace RI Advice’s obligations as the licensee. The financial services were provided under its licence, and cyber risk arising within the representative network was therefore a risk connected with the provision of those services.
4. Cybersecurity incidents
The nine incidents identified in the agreed facts included:
| Period | Incident | Consequence |
|---|---|---|
| June 2014 | Adviser email account compromised | Five clients received fraudulent investment emails; one client transferred about $50,000 |
| June 2015 | Third-party website provider hacked | Fake webpage placed over the practice’s website |
| September 2016 | Fraudulent email apparently sent by practice employee | Client received a false request for money |
| January 2017 | Ransomware attack | Files became inaccessible |
| May 2017 | Server compromised through remote-access port | Information relating to about 220 clients was held for ransom and not recovered |
| December 2017–April 2018 | Prolonged unauthorised server access | Personal information of several thousand clients was compromised |
| May 2018 | Adviser email account compromised | Fraudulent bank-transfer request sent to bookkeeper |
| August 2019 | Employee email account compromised | Phishing emails sent to more than 150 clients |
| April 2020 | Repeat the compromise of the same email address | Further phishing emails sent to contacts |
The incidents showed that the risks were neither hypothetical nor isolated. They reflected recurring weaknesses across the authorised representative network and demonstrated the potential for financial loss, identity misuse, privacy harm and disruption to client services.
5. Control deficiencies
Investigations following the incidents identified weaknesses including:
- antivirus software that was absent or out of date;
- no filtering or quarantining of incoming email;
- inadequate or non-existent backup arrangements;
- shared passwords;
- default passwords that had not been changed;
- passwords and access information stored insecurely;
- credentials known to third parties;
- inconsistent use of multifactor authentication;
- inadequate monitoring of compliance by authorised representatives; and
- delayed implementation of minimum cybersecurity practices.
RI Advice had taken some measures before May 2018, including training, newsletter communications, incident reporting and contractual professional standards. Those measures included recommendations on password protection, software updates, backups and secure email use. However, RI Advice admitted that the overall documentation, controls and risk-management systems were not adequate.
The key failure was therefore not a complete absence of cyber activity. It was the lack of an effective, consistently implemented and verified control framework across the entire network.
6. Contraventions
| Act | Section | Obligation | Conduct | Finding |
|---|---|---|---|---|
| Corporations Act 2001 (Cth) | s 912A(1)(a) | Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairly | RI Advice failed to ensure adequate cybersecurity measures were implemented across its authorised representative network | Contravention from 15 May 2018 to 5 August 2021 |
| Corporations Act 2001 (Cth) | s 912A(1)(h) | Maintain adequate risk-management systems | Cybersecurity and cyber-resilience systems left clients exposed to an unacceptable level of risk | Contravention from 15 May 2018 to 5 August 2021 |
The declaration concerning s 912A(1)(a) referred specifically to a failure to ensure that financial services were provided efficiently and fairly. ASIC did not allege, and RI Advice did not admit, dishonest conduct.
7. Key legal principles
Cybersecurity is part of an AFS licensee’s general obligations
The Court accepted that the broad obligations in ss 912A(1)(a) and 912A(1)(h) required RI Advice to:
- identify cybersecurity and cyber-resilience risks arising in the provision of financial services; and
- maintain adequate documentation, controls and risk-management systems across its authorised representative network.
Cyber risk was therefore directly connected with the licensee’s regulated activities, rather than being a peripheral technology matter.
A breach of s 912A(1)(a) does not require dishonesty
The Court reiterated that conduct may fail to meet the efficiently, honestly and fairly standard even where it is not dishonest or morally improper. Acts or omissions may contravene the provision because the licensee failed to act efficiently and fairly.
For internal breach assessments, the absence of fraud, bad faith or intentional misconduct does not resolve the issue. Inadequate procedures, training, oversight or implementation may independently breach the obligation.
A separate statutory breach is unnecessary
A contravention of s 912A(1)(a) does not depend on proving a breach of another statutory, contractual, common-law or fiduciary duty. The general obligation is itself the source of the legal standard.
This is significant where a cyber incident does not clearly breach a prescriptive financial services provision. The licensee may still face regulatory exposure if its systems fall below the required standard.
“Adequate” is a contextual and technical standard
Section 912A(1)(h) requires adequate risk-management systems. The Court observed that adequacy is a normative standard assessed by reference to the risks faced by the particular business.
In cybersecurity matters, the assessment is technically complex and is likely to require evidence from appropriately qualified experts. The general public’s expectations do not determine the specific content of an adequate cybersecurity framework.
The practical implication is that licensees should obtain specialist cyber-risk advice, rather than relying exclusively on legal, compliance or management judgement.
Cyber risk cannot be eliminated, but it must be reduced
The Court recognised that cybersecurity risk evolves and cannot be reduced to zero. However, adequate documentation and controls can materially reduce that risk to an acceptable level.
The obligation is therefore not strict liability for every cyber incident. A licensee is not necessarily in breach simply because an attack succeeds. The regulatory question is whether its framework was appropriately designed, implemented, monitored and improved, having regard to its risk profile.
Implementation speed is part of adequacy
RI Advice developed a range of controls, standards and remediation initiatives, but admitted that implementation took too long. By 6 August 2021, the majority of practices had implemented most identified good practices to an acceptable level, but the licensee accepted that this should have occurred earlier.
A sound policy or planned control is not sufficient where material risks remain unmanaged during a prolonged rollout. Licensees must assess urgency, establish deadlines and verify completion.
8. Remediation undertaken
Following its acquisition by the IOOF group, RI Advice implemented significant improvements, including:
- external cybersecurity reviews;
- a Cyber Security Support Guide;
- mandatory multifactor authentication;
- cybersecurity training and assessments;
- minimum cybersecurity standards;
- centralised storage requirements for client records;
- a cybersecurity incident-response process;
- practice-level gap assessments;
- cybersecurity insurance requirements for new representatives;
- remediation plans and close-out reports; and
- independent review through the Cyber Resilience Initiative.
Security In Depth assessed practices against 11 cybersecurity practices and issued initial and close-out reports. By 6 August 2021, the majority of practices had implemented most measures to a good level.
These measures were relevant to the agreed resolution, but did not erase the historical contraventions.
9. Orders and remedies
| Order | Legal basis | Scope |
|---|---|---|
| Declaration of contravention | s 21, Federal Court of Australia Act 1976; s 1101B, Corporations Act | Contraventions of ss 912A(1)(a) and 912A(1)(h) from 15 May 2018 to 5 August 2021 |
| External expert review | s 1101B | Security In Depth, or another agreed expert, to identify any further required cyber measures |
| Implementation obligations | s 1101B | RI Advice to commence and complete any further measures within agreed timeframes |
| Reporting to ASIC | s 1101B | Expert reports on required measures and implementation outcomes |
| Costs | Court order | RI Advice to pay $750,000 toward ASIC’s costs |
| Remaining claims | Court order | Proceeding otherwise dismissed |
No pecuniary penalty was ordered. The outcome centred on declarations, forward-looking compliance obligations and costs.
The compliance orders were appropriate because clients had faced an unacceptable level of risk and an independent expert assessment was necessary to determine whether RI Advice’s current framework required further improvement.
10. Relevance for AFS licensees and authorised representatives
The judgment has direct implications for licensees operating through decentralised advice practices, corporate authorised representatives, outsourced providers or franchise-style networks.
A licensee cannot rely solely on:
- contractual obligations imposed on representatives;
- optional guidance;
- self-attestation;
- general awareness training;
- technology-provider assurances; or
- incident response after an attack.
The licensee must be able to demonstrate that controls are:
- proportionate to the information and systems at risk;
- mandatory where appropriate;
- implemented across the network;
- independently tested or otherwise verified;
- monitored on an ongoing basis;
- updated as threats evolve; and
- supported by effective incident escalation and remediation.
The case also demonstrates that authorised representatives’ technology arrangements are within the licensee’s regulatory risk perimeter where those representatives provide services under the licence.
11. Recommended controls
| Audience | Control type | Legal rationale | Risk indicator | Practical control |
|---|---|---|---|---|
| Board and risk committee | Governance | ss 912A(1)(a) and (h) | Decentralised representative network | Approve cyber-risk appetite and receive implementation reporting |
| Licensee management | Governance | Licensee remains responsible for AR network | Controls delegated to independently owned practices | Assign accountable executive ownership |
| AR onboarding | Preventative | Cyber risk must be assessed before authorisation | Legacy systems or unsupported software | Conduct technical due diligence before appointment |
| Technology security | Preventative | Sensitive client information requires protection | Shared passwords or single-factor access | Mandate MFA, encryption and access controls |
| Compliance monitoring | Detective | Policies must be implemented and effective | Reliance on self-attestation | Test practices through evidence-based audits |
| Incident management | Corrective | Cyber incidents may affect financial services and clients | Phishing, ransomware or data access | Implement mandatory escalation and response timeframes |
| Data governance | Preventative | Client records must be stored securely | Local drives and personal email accounts | Require approved central document repositories |
| Business continuity | Corrective | Services must remain resilient | Missing or untested backups | Maintain isolated backups and recovery testing |
| Third-party management | Preventative | External vendors create cyber exposure | Unassessed IT or website provider | Apply security standards and contractual audit rights |
| Internal audit | Detective | Independent assurance supports adequacy | Repeated unresolved cyber findings | Conduct periodic end-to-end maturity reviews |
12. Recommended next steps
AFS licensees should:
- map where client information is stored and accessed across their representative network;
- establish minimum mandatory cybersecurity controls;
- identify practices that do not meet those controls;
- impose risk-based remediation deadlines;
- verify implementation through technical evidence;
- review multifactor authentication, backups, patching and email security;
- test incident-response and business-continuity arrangements;
- integrate cyber incidents into breach-reporting assessments;
- assess whether third-party providers meet the licensee’s standards; and
- provide the board with clear reporting on overdue gaps and residual risk.
13. Broader impact
- Signals ASIC’s increased focus on non-financial risks, including technology and operational risks
- May lead to increased investment in cybersecurity measures across the financial services industry
- Highlights the potential for cybersecurity breaches to result in significant financial and operational impacts
- Demonstrates the evolving nature of AFS Licence obligations in response to technological changes
- Reflects the growing importance of digital resilience in the financial services sector
- This landmark case sets a precedent that cybersecurity is not just an IT issue but a fundamental aspect of an AFS Licensee’s compliance obligations. It underscores that cybersecurity risk management should be ongoing, not a one-time implementation.
- For advisers, it emphasises the importance of adhering to cybersecurity policies and procedures set by their licensee. It also highlights the need for continuous training and awareness about cybersecurity risks and best practices.
- This case could influence legislative changes or amendments to the Corporations Act to incorporate more explicit requirements regarding cybersecurity, reflecting ongoing legislative responsiveness to technological risks.
- It’s important to note that the decision was based on an agreed statement of facts and joint proposals for declarations and orders by both parties. This emphasises the cooperative aspect of the resolution and the consensual nature of the orders.
AFS Licensees should view this case as a prompt to review and potentially upgrade their cybersecurity measures, encompassing technical controls, policies, procedures, and staff training.
The Court’s order for an external cybersecurity expert review aligns with a broader regulatory trend towards independent assurance of compliance systems. This suggests that all AFS licensees should consider regular independent reviews of cybersecurity measures as a preventative step.
Ultimately, this case reflects ASIC’s view that robust cybersecurity measures are integral to a licensee’s obligation to provide financial services ‘efficiently, honestly and fairly’, signalling a new era of regulatory focus on digital resilience in the financial sector.
This analysis is suitable for internal legal and compliance review, but final positions should be confirmed against the complete source material, current legislation and any subsequent regulatory developments.