Add Fazzaco to desktop

Add Fazzaco to desktop

Access Fazzaco from desktop next time

Add now
English

ASIC Outlines AFS Licensees' Cybersecurity Obligations

Source: Anne

9fd7779820643209fa31faf6a98fbf0.jpeg

Fazzaco learned that the Australian Securities and Investments Commission (ASIC) today outlined its expectations of AFS licensees in fulfilling cybersecurity obligations after an Australian financial services (AFS) licensee has been found to have breached its licence obligations by failing to adequately manage its cybersecurity risks.

Fazzaco Live Webinar on 12th May: Vladimir Moshkov on How to Start a Crypto Exchange from Scratch

The judgment noted that RI Advice Group Pty Ltd had a number of inadequate risk management practices across its network, including some of its authorised representatives failing to have up-to-date antivirus software, system backups, email filtering or quarantining, and poor password practices. Inadequacies in its cybersecurity risk management lead to a number of cyber incidents affecting clients in the six-year period to May 2020.

"Cybersecurity should be front of mind for all AFS licensees.While it is not possible to reduce cybersecurity risk to zero … it is possible to materially reduce cybersecurity risk through adequate cybersecurity documentation and controls..." said Justice Rofe in her judgment.

Meanwhile, the Australian Cyber Security Centre (ACSC) recommends organisations implement eight essential mitigation strategies from their Strategies to mitigate cyber security incidents.

ASIC's Expectations of AFS Licensees:

  • First, AFS licensees should be aware of the potential consumer harms that arise from cybersecurity shortcomings.

  • Second, they should adopt good cybersecurity risk management practices to reduce potential harm to consumers. The regulator expects active management of cyber risks and continuous cybersecurity improvement, including assessment of cyber incident preparedness and review of incident response and business continuity plans.

  • Third, AFS licensees are expected to act quickly in the event of a cyber incident to minimise the risk of ongoing harm. Theft of sensitive personal information can significantly affect consumers’ financial and physical well-being and can be long-lasting. All organisations should regularly re-assess their cyber risks and ensure their detection, mitigation and response measures adequately support the size and complexity of their business, and the sensitivity of the information they hold.

  • Finally, AFS licensees are strongly encouraged to report cyber incidents to the ACSC. Licensees should also consider if any obligation arises to report the incident to ASIC.

In addition, the regulator highlighted that dual regulated AFS licensees will also have obligations to comply with the standards of other regulators, such as APRA.

"This decision confirms that AFS licensees must have adequate technological systems, policies and procedures to ensure sensitive consumer information is protected. This will minimise the risk of consumer harm," ASIC said, "If an AFS licensee fails to meet its obligations as a result of similar conduct or omissions, ASIC may take enforcement action, as we did with RI Advice, which can result in significant penalties."

Create Company Page