ASIC is intensifying its focus on board directors and executives who fail to adequately prepare for cyberattacks. The move comes as part of ASIC chairman Joe Longo's address to The Australian Financial Review Cyber Summit.
Longo warned that the regulator was seeking out breached companies that had neglected cybersecurity measures, declaring, “If things go wrong, ASIC will be looking for the right case where company directors and boards failed to take reasonable steps.”
The summit also features Home Affairs Minister Clare O’Neil discussing her ambitious plan to halt the sale of cyber-insecure products.
O'Neil will present six "cyber shields" that will form the cornerstone of the government's upcoming cybersecurity strategy. The strategy aims to cover a range of areas from education and partnerships to strengthening essential infrastructure.
Longo emphasises that cybersecurity is not just about having secure systems but also about resilience, which involves the ability to recover from cyber incidents. In contrast to O’Neil’s statement on the accountability of tech firms for security breaches, Longo will insist that the onus is on companies to secure their digital supply chains.
Both O'Neil and Longo point to the recent hacks of Optus and Medibank as alarm bells for businesses to take cybersecurity more seriously.
A rise in cyber incidents
This tougher stance by ASIC comes amidst a rise in cyber incidents. Between January and June this year, 409 data breaches were reported and at least one in five Australian businesses faced cyber breaches last year, according to the Office of the Australian Information Commissioner and the Australian Bureau of Statistics respectively. Details on fines or punishments for cyber unpreparedness are yet to be disclosed, but the ASIC website warns of "significant penalties".
ASIC’s sharpened focus marks a pivotal moment in regulatory oversight, echoing broader governmental moves to tighten cybersecurity measures across the Australian business landscape.