O’Connor Emmet Accountants & Tax Advisers
  • Home
  • About Us
  • International Tax
  • Australian Tax
  • Irish Tax
  • Business Services
  • Latest News
  • Contact Us
  • Book a Consultation
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Directors on the hook for cyber security, ASIC warns

Repelling attacks is just the start – businesses must demonstrate an ability to respond or the board will be held accountable, the regulator says.

.

Directors are duty-bound to ensure their company has “adequate” cyber security and the ability to recover from an attack or they could face action by ASIC, the chair of the regulator says.

Joe Longo said cyber readiness meant more than trying to engineer a bulletproof system but extended to building an ability to respond.

 

“Cyber preparedness is not simply a question of having impregnable systems. That’s not possible,” he said. “Instead, while preparedness must include security, it must also involve resilience, meaning the ability to respond and weather a significant cyber security incident.”

 

“This can only be built on thorough and comprehensive planning for significant cyber security incidents, and a clearly thought-out risk management strategy.”

 

Recovery plans on their own were also insufficient without regular testing and never-ending risk reassessment, including within supply chains.

Speaking at the Australian Financial Review Cyber Summit yesterday, Mr Longo said last year’s attacks against Optus and Medibank were a wake-up call but surveys showed most businesses lacked confidence in their organisation’s ability to remain resilient in a “worst-case” cyber event.

One important lesson was that relying on third-party providers always involved risk.

“None of us has control over the security of a third-party provider,” he said. “If we rely solely on the security measures those providers have in place, we leave a wide opening for a data breach if those measures are compromised.”

He said the Latitude Financial breach earlier this year originated from an outside provider and because Latitude was itself a service provider, millions more than its own customers were affected.

Initial findings from an ASIC survey still in progress revealed “that one of the weakest links in cyber preparedness is third-party suppliers, vendors, and managed service providers”.

Supply chain risks were a related issue, with almost one in two respondents saying they did not manage third-party or supply chain risk.

Mr Longo said ASIC had uncovered disconnects in the way various parts of a business handled the digital risks between:

  • Boards’ oversight of cyber risk.
  • Management reporting of cyber risk to boards.
  • Management identification and remediation of cyber risk.
  • Cyber risk assessments.
  • How cyber risk controls are implemented.

“This disconnect must be addressed,” he said. “Cyber security and resilience are not merely technical matters on the fringes of directors’ duties. ASIC expects directors to ensure their organisation’s risk management framework adequately addresses cyber security risk, and that controls are implemented to protect key assets and enhance cyber resilience.”
“Failing to do so could mean failing to meet your regulatory obligations.”

“Measures taken should be proportionate to the nature, scale and complexity of your organisation – and the criticality and sensitivity of the key assets held. This includes reassessment of cyber security risks on an ongoing basis, based on threat intelligence and vulnerability identification.”

“For all boards, cyber security and cyber resilience have got to be top priorities. “If boards do not give cyber security and cyber resilience sufficient priority, this creates a foreseeable risk of harm to the company and thereby exposes the directors to potential enforcement action by ASIC based on the directors not acting with reasonable care and diligence.”

He said boards and directors also had to consider how they would communicate with customers, regulators, and the market when things went wrong.

“Do they have a clear and comprehensive response and recovery plan? Has it been tested?

“How will the company detect if the system has been broken, or exploited? History shows that even robust defence systems can be circumvented, and resilience demands you be prepared for that possibility.”

He said two points needed to be emphasised: there was a need to act now, and third-party suppliers were a “clear vulnerability”.

“If you’re not evaluating your third-party cyber security risk, you’re deceiving yourself. And recent events show that you will suffer for it.”

“Don’t put yourself in that position.”

 

 

 

Philip King
19 September 2023
accountantsdaily.com.au

 

Share this entry
  • Share on WhatsApp
https://irishtax.com.au/wp-content/uploads/2023/11/cyber-g.jpg 317 475 darkroom https://irishtax.com.au/wp-content/uploads/2022/07/oconnoremmet.png darkroom2023-11-12 00:00:002023-11-18 03:11:00Directors on the hook for cyber security, ASIC warns

Recent Posts

  • SMEs to be hit hardest by new trust tax reforms June 23, 2026
  • Payday Super: 6 Things Small Businesses Need to Know June 21, 2026
  • PAYDAY SUPER STARTS 1 JULY 2026 – Planning guides June 17, 2026
  • 2026 Year-End Tax Planning Guide – Part 2 June 13, 2026
  • 2026 Year-End Tax Planning Guide – Part 1 June 10, 2026
  • From Bricks to iPhones: The Evolution of the Telephone May 30, 2026
  • Succession planning and why it should be at the top of your to-do list May 28, 2026
  • Choosing the right trustee structure for your SMSF May 25, 2026
  • ATO taking a closer look at investment properties May 23, 2026
  • Major super tax changes now law May 21, 2026
  • RSM welcomes updated PCG on transfer pricing for inbound distributors May 17, 2026
  • ATO reminds practitioners to avoid common FBT mistakes May 13, 2026
  • Why every business should have an AI policy May 10, 2026
  • Most Valuable Industries in the World 2026 April 30, 2026
  • Buy an existing business April 28, 2026
  • Fringe Benefits Tax (FBT) Guide – Key Checklist & Rates April 25, 2026
  • Succession planning to remain major focus for ATO this year April 23, 2026
  • Strategies for Effective Debt Recovery for Small Businesses April 21, 2026
  • ATO issues new guidance on penalties for non-compliance with STP April 17, 2026
  • Payday Super: 6 Things Small Businesses Need to Know April 13, 2026
Search Search

Recent Posts

  • SMEs to be hit hardest by new trust tax reforms
  • Payday Super: 6 Things Small Businesses Need to Know
  • PAYDAY SUPER STARTS 1 JULY 2026 – Planning guides
  • 2026 Year-End Tax Planning Guide – Part 2
  • 2026 Year-End Tax Planning Guide – Part 1

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • April 2019
  • March 2019
  • December 2018
  • October 2018
  • June 2018
  • May 2018
  • March 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • October 2016
  • September 2016
  • August 2016
  • June 2016
  • May 2016
  • March 2016
  • December 2015
  • November 2015
  • October 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013

Categories

  • Accounting News
  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

O’Connor Emmet Accountants & Tax Advisers

Tax Agent No. 26033744

Telephone: +61 02 8324 7433
Email: info@oconnoremmet.com.au
Facebook: https://www.facebook.com/oconnoremmetaccountants/

Liability limited by a Scheme approved under Professional Standards Legislation.

Links

  • Australian Tax
  • Office of the Revenue Commissioners
  • Irish Taxation Institute
  • Tax Institute of Australia
  • Association of Chartered Certified Accountants
  • Australian Taxation Office
© Copyright - O’Connor Emmet Accountants & Tax Advisers - Website by Web and Print Design
Link to: Australian Taxation Office (ATO) motor vehicle data matching program extended Link to: Australian Taxation Office (ATO) motor vehicle data matching program extended Australian Taxation Office (ATO) motor vehicle data matching program extend... Link to: I am making a profit but where does all the cash go? Link to: I am making a profit but where does all the cash go? I am making a profit but where does all the cash go?
Scroll to top Scroll to top Scroll to top