ASIC Is Now Fining Advice Firms Over Cyber Failures — Here’s What It Means for Your Practice
Cyber security has stopped being an IT line item for financial advice firms and become a regulator problem. Last week Insignia Financial confirmed a credential-stuffing attack on its Expand platform that hit around 100 superannuation accounts — attackers reusing stolen username-and-password pairs to walk straight in. It lands while ASIC is openly treating cyber failures by licensees as a headline enforcement priority for 2026, and firms have told Adviser Ratings they’re lifting compliance spend by roughly 31 per cent in response.
The reason that number is climbing is the precedent. In February the Federal Court ordered FIIG Securities to pay $2.5 million — the first civil penalty in Australia for cyber security failures under general AFSL obligations — after roughly 385GB of client data was stolen and 18,000 clients had to be notified. The court noted adequate controls would have cost about $1.2 million. The penalty came in at nearly double that. The message to every licensee is blunt: underinvesting in security is now more expensive than the security itself.
Here’s the pattern we see across the advice and accounting practices we onboard around Sydney and Central West NSW: multi-factor authentication switched on for Microsoft 365 but not for the third-party platforms — portals, CRMs, super and investment gateways — where client data actually lives. That’s exactly the gap credential stuffing exploits. Start there. Turn on MFA for every platform that touches client information, block reused and breached passwords, and make sure someone is actually watching login anomalies rather than finding out weeks later. Then get the Essential Eight basics — patching, tested backups, an incident response plan you’ve rehearsed — documented, because ASIC expects to see them.
If you’re not sure which of your platforms are exposed, that’s the audit worth doing this month. All IT Services works with Australian financial services and wealth firms to close these gaps and stand up cyber security controls that hold up to regulatory scrutiny.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
