ASIC Launches Legal Action Against FIIG Securities

The Australian Securities and Investments Commission (ASIC) has initiated legal proceedings against FIIG Securities, alleging "systemic and prolonged cybersecurity failures" that reportedly spanned over four years.
ASIC contends that FIIG Securities failed to implement adequate cybersecurity measures between March 2019 and June 2023. This alleged lack of security allowed an external attacker to infiltrate the company's IT network for nearly three weeks in June 2023.
The regulator stated that the breach resulted in the theft of approximately 385 gigabytes of confidential data belonging to around 18,000 clients. This sensitive information, which reportedly included names, addresses, birth dates, driver's licences, passports, bank account details, and tax file numbers, was later reportedly released on the dark web.
FIIG Securities reportedly became aware of the security incident on June 2, 2023, after being alerted by the Australian Signals Directorate's Cyber Security Centre (ASD's ACSC). However, ASIC claims that the company did not commence its own investigation into the breach until June 8, 2023.
ASIC Chair Joe Longo emphasized the critical importance of proactive cybersecurity measures, stating, "We allege FIIG's inadequate cybersecurity measures left the business and its confidential client information vulnerable and exposed to significant risk." He further cautioned that cybersecurity is not a "set and forget" issue and requires ongoing attention and improvement.
In its legal action, ASIC is seeking civil penalties and compliance orders against FIIG Securities for the alleged failures, which include not having adequate firewalls, software updates, cybersecurity training, and sufficient resources dedicated to cybersecurity. This case marks ASIC's second instance of taking enforcement action related to cybersecurity, following a previous ruling against RI Advice in 2022.
Subscribe Now

