All Articles

The Federal Court Just Fined FIIG Securities $2.5M for Inadequate Cyber Security

Michael Jordison Michael Jordison
·

On 9 February 2026, the Federal Court handed FIIG Securities a $2.5 million penalty for failing to maintain adequate cyber security controls. It’s the first time an Australian Financial Services Licensee has been penalised specifically for cyber security failures.

This isn’t a story about a sophisticated nation-state attack. It’s a story about a company that stored passwords in plain text files, didn’t enforce multi-factor authentication, and ran one penetration test in four years.

What happened

A cyberattack beginning 19 May 2023 resulted in 385 gigabytes of data being exfiltrated. Approximately 18,000 clients were affected. The stolen data included passport details, tax file numbers, driver’s licences, Medicare cards, and bank account information.

The Australian Cyber Security Centre notified FIIG of a potential intrusion on 2 June 2023. FIIG didn’t begin its own investigation for six days.

What the court found

The failures weren’t exotic. Justice Derrington documented a pattern of underinvestment spanning 13 March 2019 to 8 June 2023, over four years. The list reads like a checklist of things every firm should already have:

  • No multi-factor authentication for remote access
  • Passwords stored in plain text files on the network
  • No 14+ character passwords for privileged accounts
  • No quarterly access reviews
  • Only one penetration test in four years
  • No regular vulnerability scanning
  • No software patching management plan
  • No qualified IT personnel monitoring threat alerts
  • No mandatory staff cyber security training
  • No tested incident response plan
  • No endpoint detection and response software

The court found FIIG breached three sections of the Corporations Act (s912A):

  1. Failure to provide financial services efficiently, honestly, and fairly (s912A(1)(a))
  2. Inadequate technological, human, and financial resources (s912A(1)(d))
  3. Deficient risk management systems (s912A(1)(h))

The conduct was characterised as “careless rather than deliberate.” That distinction matters. FIIG didn’t intend to be negligent. They just didn’t invest.

The cost comparison that should keep you awake

The court noted that adequate compliance would have cost FIIG approximately $1.2 million over the four-year period.

Instead, FIIG is now paying:

  • $2.5 million in civil penalties
  • $500,000 toward ASIC’s legal costs
  • Approximately $1.5 million in breach remediation
  • Total: over $4 million, plus reputational damage you can’t quantify

$1.2 million spread over four years, or $4 million in one hit. That’s the maths.

Why this matters to your firm

If you’re running an accounting practice or law firm in SE Queensland, you might think this doesn’t apply to you. FIIG held an AFSL, not a tax agent registration or practising certificate.

But the principle transfers directly.

For accountants:

  • APES 325 requires a documented risk management framework covering IT and cyber risks
  • The TPB’s Code of Professional Conduct (Code 6) mandates safeguarding client information
  • The TPB’s new exposure draft (D62/2026) specifically addresses AI and data security obligations
  • The Tax Agent Services Act 2009 makes inadequate client data protection a conduct issue

For lawyers:

  • Law societies require reasonable steps to protect client confidentiality
  • Professional indemnity insurers increasingly audit cyber security controls at renewal
  • The statutory tort for serious invasions of privacy (effective June 2025) means clients can now sue you directly for data breaches

The regulatory bodies are watching this decision. ASIC Deputy Chair Sarah Court said it plainly: “Cyber-attacks and data breaches are escalating in both scale and sophistication, and inadequate controls put clients and companies at real risk.”

The “careless not deliberate” finding is the real warning

FIIG didn’t set out to be negligent. They just didn’t prioritise security spending. Justice Derrington’s judgment at paragraph 80 states this penalty “will send a warning to businesses with inappropriate underinvestment in cybersecurity.”

The practical lesson is not that every small firm needs an enterprise security program. It is that directors should be able to explain which risks were assessed, which controls were implemented, what remained outstanding, and why.

Ask yourself the FIIG checklist:

  • Is MFA enforced for every user, including remote access?
  • Are passwords stored securely, not in spreadsheets, not in shared documents?
  • When was your last penetration test? Have you ever had one?
  • Do you have an incident response plan? Has it been tested?
  • Is someone qualified actually monitoring your security alerts?
  • Are your staff trained on cyber security? When was the last session?

If you’re answering “no” or “I’m not sure” to more than two of these, you’re in FIIG territory.

What you should do

  1. Run a security baseline. You need to know where you stand before you can fix anything. Your M365 Secure Score is a decent starting point. It’s free and it’s already in your tenant.
  2. Fix the basics first. MFA everywhere. Block legacy authentication. Review who has admin access. These three changes eliminate the majority of compromise vectors.
  3. Get a penetration test. Not a vulnerability scan. An actual test by someone who knows what they’re doing. Our Cyber Business Review includes OSCP-certified penetration testing if you want an honest assessment.
  4. Document your controls. When your insurer asks what you’ve done, “we think we’re okay” isn’t an answer. When the TPB or your law society asks, it’s even worse.
  5. Talk to someone. If you’re not sure where your gaps are, book a conversation. We’ll give you a straight answer about what needs attention and what doesn’t.

The Federal Court just established that underinvestment in cyber security is a breach of your obligations. The question isn’t whether your regulator will follow ASIC’s lead. It’s when.

Michael Jordison

Need to prove where you stand?

Compare Essential Eight, SMB1001 and DISP side by side, and see the evidence each one expects you to produce.

More on this: Compliance articles · Cyber Compliance