Gridware Logo

ASIC's Legal Action Against FIIG Securities Highlights Critical Cybersecurity Lessons for Australian Businesses

By Ahmed Khanji Updated 15 October 2025 3 min read

in 𝕏
ASIC's Legal Action Against FIIG Securities Highlights Critical Cybersecurity Lessons for Australian Businesses

In a significant move that has caught the attention of Australia’s financial sector, the Australian Securities and Investments Commission (ASIC) has launched legal proceedings against FIIG Securities Limited over serious cybersecurity lapses. These allegations revolve around the company’s failure to adequately protect its IT networks, resulting in a prolonged data breach affecting thousands of customers.

What Happened?

According to ASIC, between March 2019 and June 2023, FIIG Securities reportedly neglected key aspects of cybersecurity management, enabling unauthorised access to their systems. The breach, notably severe, went unnoticed for nearly three weeks, from May 19 to June 8, 2023, during which approximately 385GB of sensitive data was compromised. This included deeply personal client details such as names, addresses, birth dates, driver’s licenses, passport information, banking details, and tax file numbers. Around 18,000 clients were affected. A detailed digital forensic investigation wasn’t conducted until many days after the ASD notified FIIG of the leaked data.

Key Failures Highlighted by ASIC

ASIC’s allegations outline several critical areas where FIIG fell short:

  • The company failed to effectively managed the cyber breach.
  • The company allegedly failed to properly configure and monitor firewall systems, leaving critical gaps for hackers to exploit.
  • Regular patching and updates, essential to cybersecurity, were neglected, exposing vulnerabilities to potential attackers.
  • ASIC claims FIIG did not allocate enough financial and technological resources to ensure robust cybersecurity defences.
  • Employees were reportedly not provided with adequate training to detect and prevent cyber threats effectively.

FIIG was unaware of the breach until alerted by the Australian Cyber Security Centre (ACSC) on June 2, 2023, and only began an internal investigation nearly a week later.

Why This Matters to Your Business

This lawsuit serves as a timely reminder for all Australian businesses, particularly in the financial sector, about the importance of proactive cybersecurity measures. The legal action demonstrates that regulators are increasingly vigilant about cybersecurity and expect businesses to prioritise data security seriously.

Actionable Lessons to Protect Your Business

Here’s what businesses can immediately learn and apply from this incident:

  1. Invest in Regular Security Assessments: Conduct routine cybersecurity audits to detect and mitigate vulnerabilities before attackers do.
  2. Stay Updated and Patched: Ensure all software, systems, and applications receive regular updates and patches.
  3. Educate Employees: Offer regular, mandatory cybersecurity training to staff to build a frontline defence against phishing and other common cyber threats.
  4. Commit Adequate Resources: Dedicate appropriate financial, technological, and human resources to your cybersecurity strategy.

Moving Forward

ASIC’s case against FIIG Securities is not just a headline. It is a clear signal to the financial industry and beyond that cybersecurity failures have real, tangible consequences. For businesses entrusted with sensitive customer data, adversary simulation or red team exercises are a great start to stay ahead of cyber threats, to not just to meet compliance obligations but also to maintain trust and reputation in an increasingly digital world.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.