Latest News

Hot Issues
spacer
ATO no longer treating debt the same as during COVID
spacer
Warning for early lodger this tax time!
spacer
Global companies turn to cost-cutting amid ongoing inflation
spacer
Don’t get caught out at tax time with your multiples jobs
spacer
Does Your Small Business Need to Follow AML Privacy Rules?
spacer
SMEs warned as ATO ramps up tax debt collection
spacer
Taxpayer given 35% penalty for BAS recklessness
spacer
How Our Diets have Changed.
spacer
Tips to help you this tax time
spacer
Tax Time Checklists Individuals; Company; Trust; Partnership; and Super Funds
spacer
ATO warns millions of Australian chasing tax deductions to stop making 'unusual' claims
spacer
Impersonation scams are on the rise
spacer
Components of a cyber security plan
spacer
Social Security Payments and Their Effect on Discretionary Trusts
spacer
LRBA ban no better for housing supply or retirement, accountants clap back
spacer
The evolution of the world's languages
spacer
2026 Year-End Tax Planning Guide – Part 1
spacer
2026 Year-End Tax Planning Guide – Part 2
spacer
PAYDAY SUPER STARTS 1 JULY 2026 – Planning guides
spacer
Payday Super: 6 Things Small Businesses Need to Know
spacer
SMEs to be hit hardest by new trust tax reforms
spacer
6 tips to help businesses avoid financial difficulties
spacer
Managing your mental health and wellbeing during times of uncertainty
spacer
Check out what Uses the Most Internet Traffic: Data from 1994 to 2026
spacer
Key tax changes and measures from the 2026 Federal Budget
spacer
Federal budget 2026: Winners and losers
spacer
A breakdown of 2026-27 Federal Budget Themes and Papers.
spacer
ATO reminds practitioners to avoid common FBT mistakes
spacer
Why every business should have an AI policy
spacer
RSM welcomes updated PCG on transfer pricing for inbound distributors
spacer
Major super tax changes now law
spacer
ATO taking a closer look at investment properties
spacer
Choosing the right trustee structure for your SMSF
Article archive
spacer
Quarter 2 April - June 2026
spacer
Quarter 1 January - March 2026
spacer
Quarter 4 October - December 2025
spacer
Quarter 3 July - September 2025
spacer
Quarter 2 April - June 2025
spacer
Quarter 1 January - March 2025
spacer
Quarter 4 October - December 2024
spacer
Quarter 3 July - September 2024
spacer
Quarter 2 April - June 2024
spacer
Quarter 1 January - March 2024
spacer
Quarter 4 October - December 2023
spacer
Quarter 3 July - September 2023
spacer
Quarter 2 April - June 2023
spacer
Quarter 1 January - March 2023
spacer
Quarter 4 October - December 2022
Directors on the hook for cyber security, ASIC warns

Repelling attacks is just the start – businesses must demonstrate an ability to respond or the board will be held accountable, the regulator says.

.

Directors are duty-bound to ensure their company has “adequate” cyber security and the ability to recover from an attack or they could face action by ASIC, the chair of the regulator says.

Joe Longo said cyber readiness meant more than trying to engineer a bulletproof system but extended to building an ability to respond.

 

“Cyber preparedness is not simply a question of having impregnable systems. That’s not possible,” he said. “Instead, while preparedness must include security, it must also involve resilience, meaning the ability to respond and weather a significant cyber security incident.”

 

“This can only be built on thorough and comprehensive planning for significant cyber security incidents, and a clearly thought-out risk management strategy.”

 

Recovery plans on their own were also insufficient without regular testing and never-ending risk reassessment, including within supply chains.

Speaking at the Australian Financial Review Cyber Summit yesterday, Mr Longo said last year’s attacks against Optus and Medibank were a wake-up call but surveys showed most businesses lacked confidence in their organisation’s ability to remain resilient in a “worst-case” cyber event.

One important lesson was that relying on third-party providers always involved risk.

“None of us has control over the security of a third-party provider,” he said. “If we rely solely on the security measures those providers have in place, we leave a wide opening for a data breach if those measures are compromised.”

He said the Latitude Financial breach earlier this year originated from an outside provider and because Latitude was itself a service provider, millions more than its own customers were affected.

Initial findings from an ASIC survey still in progress revealed “that one of the weakest links in cyber preparedness is third-party suppliers, vendors, and managed service providers”.

Supply chain risks were a related issue, with almost one in two respondents saying they did not manage third-party or supply chain risk.

Mr Longo said ASIC had uncovered disconnects in the way various parts of a business handled the digital risks between:

  • Boards’ oversight of cyber risk.
  • Management reporting of cyber risk to boards.
  • Management identification and remediation of cyber risk.
  • Cyber risk assessments.
  • How cyber risk controls are implemented.

“This disconnect must be addressed,” he said. “Cyber security and resilience are not merely technical matters on the fringes of directors’ duties. ASIC expects directors to ensure their organisation’s risk management framework adequately addresses cyber security risk, and that controls are implemented to protect key assets and enhance cyber resilience.”
“Failing to do so could mean failing to meet your regulatory obligations.”

“Measures taken should be proportionate to the nature, scale and complexity of your organisation – and the criticality and sensitivity of the key assets held. This includes reassessment of cyber security risks on an ongoing basis, based on threat intelligence and vulnerability identification.”

“For all boards, cyber security and cyber resilience have got to be top priorities. “If boards do not give cyber security and cyber resilience sufficient priority, this creates a foreseeable risk of harm to the company and thereby exposes the directors to potential enforcement action by ASIC based on the directors not acting with reasonable care and diligence.”

He said boards and directors also had to consider how they would communicate with customers, regulators, and the market when things went wrong.

“Do they have a clear and comprehensive response and recovery plan? Has it been tested?

“How will the company detect if the system has been broken, or exploited? History shows that even robust defence systems can be circumvented, and resilience demands you be prepared for that possibility.”

He said two points needed to be emphasised: there was a need to act now, and third-party suppliers were a “clear vulnerability”.

“If you’re not evaluating your third-party cyber security risk, you’re deceiving yourself. And recent events show that you will suffer for it.”

“Don’t put yourself in that position.”

 

 

 

Philip King
19 September 2023
accountantsdaily.com.au

 

Liability limited by a Scheme approved under Professional Standards Legislation.
© O'Brien and Partners 2024 - All Rights Reserved | 333 Canterbury Road, Canterbury VIC 3126 | Tel: 03 9509 3911 Site by Acctweb