By holding an Australian financial services licensee legally liable for its cyber security, the Federal Court has created a precedent with far-reaching implications for the financial services industry.
The court ruled that RI Advice’s lack of cyber security risk management was a breach of its licence terms, in response to an action brought by the Australian Securities and Investments Commission.
This was the first time ASIC had taken legal action against a licensee.
The court has ordered RI Advice to undergo security training by an organisation agreed upon by it and ASIC within a month, to implement the security measures recommended by that organisation, and to pay $750,000 towards ASIC’s costs.
After ASIC and RI Advice decided to settle the case, the orders were made by consent.
In reaction to security flaws that resulted in many intrusions, the commission filed a complaint against the corporation in 2020.
Between December 2017 and April 2018, an attacker gained access to a file server, potentially compromising the data of thousands of clients.
“While it is impossible to completely eliminate cyber security risk, it is possible to considerably reduce cyber security risk to an acceptable level by implementing proper cyber security documentation and controls.”
“These cyber intrusions were significant occurrences that permitted third parties to get unauthorised access to sensitive personal information,” said ASIC deputy chair Sarah Court.
“To defend against unauthorised access, all companies, including licensees, must have suitable cyber security systems in place.
“In light of the heightened cyber threat environment, ASIC strongly advises all organisations to follow the advice of the Australian Cyber Security Centre and adopt an upgraded cybersecurity posture to strengthen cyber resilience.”


