The Federal Court's decision in ASIC v FIIG Securities Limited has prompted many GRC leaders to reassess their risk management systems. The AUD 2.5 million penalty against FIIG is more than a headline; it's a detailed examination of regulatory expectations for your cyber security controls, outlined in a 92-page judgment. If you hold an AFSL, these are the questions you should be asking your team right now.
Do We Need Vulnerability Scanning on Every Internet-Facing Asset?
Yes, and ASIC will verify your compliance.
FIIG's shortcomings included not conducting vulnerability scanning on internet-facing infrastructure. The Court found this violated section 912A(1)(h), which requires maintaining adequate risk management systems. ASIC rejected the notion that having a firewall was enough. They expect regular, documented scanning to identify vulnerabilities before attackers do.
The standard is proportionality. FIIG managed between AUD 2.99-3.7 billion in client assets and held detailed personal information on about 18,000 clients. Given this scale and sensitivity, ASIC's stance was clear: if you're managing billions in client assets, you need automated vulnerability management covering every external surface.
If your organization handles similar volumes of Special Categories of Data or client funds, assume ASIC will apply the same scrutiny. Document your scanning frequency, remediation timelines for critical findings, and the rationale for any exceptions. If you're not scanning at least quarterly, be prepared to justify why your risk profile warrants less frequent coverage.
What Does "Adequate Human Resources" Mean for Cyber Security?
Your cyber security lead can't juggle multiple roles.
The Court found FIIG failed to meet section 912A(1)(d), which requires adequate resources, including human resources. FIIG's Head of Technology and Operations was responsible for cyber security while also handling operational IT duties. ASIC and the Court agreed that this person couldn't properly manage cyber security responsibilities due to competing demands.
This isn't about headcount for its own sake. It's about ensuring the people responsible for your cyber controls have the capacity to implement, test, and respond effectively. If your CISO is also your CTO and Head of Infrastructure, you've created a structural vulnerability that ASIC will flag as non-compliance.
The practical test: can your cyber security lead demonstrate they've conducted activities ASIC expects (vulnerability assessments, threat detection review, incident response planning, vendor risk oversight) within the past quarter? If they're too busy maintaining the network to document these activities, you lack adequate human resources under section 912A(1)(d).
How Granular Does Our Threat Detection Need to Be?
Granular enough to detect an intrusion before external alerts.
FIIG's cyber-attack lasted from 19 May 2023 to 8 June 2023, and they only learned of it when the Australian Cyber Security Centre alerted them on 2 June 2023. Approximately 385GB of client data was exfiltrated during that time. The Court found FIIG's monitoring and threat detection capabilities inadequate under section 912A(1)(h).
ASIC expects real-time or near-real-time monitoring that alerts on anomalous data movement, privilege escalation, and lateral movement across your network. You need someone reviewing these alerts and a documented process for escalating suspicious activity to decision-makers who can authorize containment actions.
This doesn't mean you need a 24/7 security operations center if you're a mid-sized firm, but you can't rely solely on antivirus. At a minimum, you need endpoint detection and response (EDR) tools configured to alert on behavioral indicators, and a defined response protocol for when those alerts trigger.
Are We Liable if We Outsource Cyber Security to a Managed Service Provider?
Yes. Section 912A obligations remain your responsibility.
Many AFSL holders use managed security service providers (MSSPs) for monitoring, patching, or incident response. While this is a reasonable decision, the Court's reasoning in the FIIG case clarifies that outsourcing execution doesn't outsource accountability. You remain responsible for ensuring the controls are adequate and proportionate to your risk.
Your obligations include:
- Defining specific controls you expect the MSSP to operate (vulnerability scanning frequency, alert triage SLAs, patch deployment windows)
- Reviewing evidence that those controls are functioning (scan reports, alert logs, patch compliance dashboards)
- Conducting annual assessments of the MSSP's performance against your requirements
- Maintaining internal expertise to evaluate whether the MSSP's work meets ASIC's expectations
If your MSSP fails to detect an intrusion and you can't demonstrate oversight of their performance, ASIC will treat that as your failure under section 912A(1)(h). The vendor relationship doesn't shield you from liability.
How Often Do We Need to Test Our Incident Response Plan?
At least annually, with documented outcomes and remediation of gaps.
ASIC expects not just having risk management systems in place, but testing them regularly and addressing identified vulnerabilities. The Court found FIIG's controls were not adequately tested or reviewed.
Your incident response plan should be exercised through tabletop scenarios involving the people who would execute the plan: your technology lead, legal counsel, communications lead, and executive decision-makers. Document what worked, what didn't, and what changes you're making as a result.
If you've never run a tabletop exercise, or if your last one was over 18 months ago, you're operating with untested controls. ASIC's position is that untested controls don't satisfy section 912A(1)(h), regardless of how well-documented they are on paper.
What's the Penalty Exposure if We Get This Wrong?
FIIG paid AUD 2.5 million plus AUD 500,000 in costs, but the financial penalty is only part of your exposure.
The reputational damage from a court finding that your cyber security was inadequate, combined with the operational cost of remediating deficiencies under regulatory scrutiny, will exceed the penalty itself. FIIG's client data ended up on the dark web, leading to a brand recovery effort that spans years.
More immediately, ASIC has signaled that cyber resilience is a "clear license-to-operate expectation." If your risk management systems are found inadequate, you're not just facing a penalty. You're facing enhanced supervision, enforceable undertakings, or conditions on your license that restrict your business activities until you demonstrate compliance.
Where Do We Start if We're Not Confident We'd Pass This Test?
Commission an independent gap assessment against ASIC's expectations as documented in the FIIG judgment.
Don't wait for ASIC to ask. Bring in an external assessor to evaluate your current controls against the specific deficiencies the Court identified: vulnerability scanning coverage, threat detection capabilities, human resourcing, testing cadence, and governance oversight. Document the gaps, prioritize remediation based on your risk profile, and create a timeline for closing each gap with assigned ownership.
If ASIC does inquire, you want to show them a gap assessment you commissioned, a remediation plan with milestones, and evidence of progress. While this won't eliminate liability if you've already had a breach, it demonstrates you're taking section 912A obligations seriously and positions you as a firm managing cyber risk proactively.
The FIIG decision isn't an outlier. It's ASIC's template for evaluating every AFSL holder's cyber controls going forward.





