1 August 2026 1 min read

What Actually Happened

Between March 2019 and June 2023, FIIG Securities, a fixed income broker managing around three billion dollars for its clients, failed to put basic cyber security controls in place. In 2023 an attacker exploited those gaps, stole roughly 385 gigabytes of confidential data, and prompted FIIG to notify about 18,000 clients that their personal information may have been compromised. The stolen data included driver licences, passport details, bank account numbers and tax file numbers, close to everything an identity thief could want.

ASIC did not act because FIIG was unlucky enough to be attacked. It acted because the failures that let the attack succeed were basic, avoidable and left unaddressed for years. In February 2026 the Federal Court ordered FIIG to pay $2.5 million in penalties, plus a further $500,000 toward ASIC costs.

Why This Matters Beyond Financial Services

The penalty was issued under the obligations that apply to financial services licensees, so brokers, advisers and other licensed firms should read it as a direct warning. But the principle reaches every business that holds customer data.

Australian directors already carry a duty of care and diligence under the Corporations Act, and regulators increasingly treat oversight of cyber risk as part of that duty. Any business holding personal information also has obligations under the Privacy Act to take reasonable steps to protect it. The FIIG case shows what regulators now consider reasonable, and how expensive it is to fall short. According to ASIC, this was the first time the Federal Court has imposed civil penalties for cyber security failures under the general AFS licensee obligations. As ASIC Deputy Chair Sarah Court put it, ASIC expects financial services licensees to be on the front foot every day to protect their clients. It is unlikely to be the last case of its kind.

The Failures ASIC Named

The judgment listed the specific controls FIIG did not have in place. Read it as a checklist. They fall into three areas, and none of them are exotic.

Identity and Access

No multi factor authentication for remote access, and weak passwords and access controls on privileged accounts. The front door was effectively left unlocked.

Systems and Monitoring

Poorly configured firewalls and security software, no regular penetration testing or vulnerability scanning, no structured plan for security updates, and no qualified staff watching threat alerts.

People and Response

No mandatory cyber security awareness training for staff, and no tested annual incident response plan for the day something goes wrong.

What a Director Should Actually Do About It

You do not need to become a security expert. You do need to be able to answer a few questions with confidence, because one day a regulator, an insurer or a court might ask them.

  • Is multi factor authentication switched on everywhere, especially for remote and administrator access?
  • Do we know which staff hold privileged access, and is it limited to the few who genuinely need it?
  • Are our systems and applications patched on a known schedule, not whenever someone remembers?
  • When did we last test that our backups restore and that our incident response plan works?
  • Does our team know how to spot and report a phishing attempt?

If you cannot answer those clearly, that is not a technical gap. It is a governance gap, and after FIIG it is one the board owns. Most of these controls also form the core of the Essential Eight, the framework we use to measure and lift a business security posture.

The Bottom Line

The FIIG penalty puts a number on something that used to feel abstract. Cyber security is no longer only about avoiding downtime or embarrassment. It is a legal and financial responsibility that sits with the people running the business, and the standard expected of them has now been written into a court judgment.

The businesses that come out of this well are the ones that treat the ASIC checklist as a prompt to act rather than a story about someone else. Getting the fundamentals right is not complicated, and it is far cheaper than the alternative. If you are not sure where you stand, a cyber security review is the place to start.

This article is general information, not legal advice. For guidance on your specific obligations, speak with a qualified legal professional. Details of the FIIG Securities matter are drawn from ASIC’s media release published on 9 February 2026.