X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the ifa bulletin
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
No Results
View All Results
Home News

Fortnum lawsuit highlights cyber security as ‘core compliance obligation’

The corporate regulator’s action against Fortnum should be a “clear message” to AFSLs that cyber risk is far more than an IT issue, according to a law firm.

by Keith Ford
August 6, 2025
in News
Reading Time: 4 mins read
Share on FacebookShare on Twitter

Cyber security and the risks that go along with it are an increasing threat across every industry, but the financial services sector presents an enticing target for bad actors.

Narrowing it down even further to the financial advice space and the access to client financial details, coupled with smaller businesses that are potentially less equipped to deal with cyber attacks making up a significant proportion of the sector, puts a bull’s-eye on firms.

X

According to law firm Hall & Wilcox, the Australian Securities and Investments Commission’s (ASIC) latest action against Fortnum Private Wealth should serve as a “clear message to Australian Financial Services Licence (AFSL) holders that cyber risk is not just an IT issue, but a core compliance obligation”.

Last month, ASIC filed proceedings in the NSW Supreme Court that claim Fortnum Private Wealth failed to meet its obligations as an AFS licensee due to inadequate policies, frameworks, systems and controls in place to deal with cyber security risks.

According to ASIC chair Joe Longo, the alleged failure “to adequately manage cyber security risks exposed the company, its representatives and their clients to an unacceptable level of risk of a cyber attack”.

The action relates to a number of cyber breaches dating back to 2021 and 2022, one of which ASIC referred to as a “major breach” that led to more than 9,000 clients’ data being published on the dark web.

“This is ASIC’s second cyber-related enforcement proceeding in 2025, and the third of its kind overall. This reflects a growing pattern of enforcement, underscoring ASIC’s expectation that licensees must proactively manage cyber threats or face serious legal consequences,” Hall & Wilcox said.

The firm added that the allegations ASIC has put forward largely focus on Fortnum failing to adequately manage cyber security risks by:

  • Failing to implement adequate cyber security policies or frameworks to manage and mitigate cyber security risks for it and its ARs.
  • Not requiring its ARs to undertake a prescribed minimum amount of cyber security training.
  • Lacking oversight and monitoring systems for ARs’ cyber security practices.
  • Not having adequate human resources or engage qualified cyber security consultants to provide financial services.
  • Operating without a risk management system that addressed cyber security concerns.

“As part of their operations, the ARs handled personal information, including identification documents, tax file numbers and financial information,” Hall & Wilcox said.

“ASIC refers to Fortnum’s duties as a licensee to identify and understand the cyber security risks that it and its ARs faced and its requirement to have controls in place to appropriately manage those risks.

“Most of the cyber security incidents affecting Fortnum’s ARs allegedly occurred after the introduction of Fortnum’s cyber security policy. ASIC claims that Fortnum failed to implement measures to strengthen its cyber security policies, frameworks, systems and controls despite these incidents occurring.”

The other AFS licensee that ASIC has gone after this year is fixed income securities dealer FIIG Securities, which suffered a single prolonged breach involving 385 GB of client data theft that affected 18,000 clients.

While the nature of the attack and the areas of alleged failures were different to the Fortnum incidents, both resulted in the threat actor publishing the stolen data on the dark web.

In March, Longo noted that the lawsuit against FIIG aligned with ASIC’s strategic priority to advance “digital safety and resilience”.

“This matter should serve as a wake-up call to all companies on the dangers of neglecting your cyber security systems,” the chair said at the time.

“Cyber security isn’t a set and forget matter. All companies need to proactively and regularly check the adequacy of their cyber security measures and follow the advice of the ASD’s ACSC.”

Hall & Wilcox added that ASIC’s “enforcement trajectory” provides a number lessons for all AFSL holders and “reaffirms that cyber risk management is a non-negotiable part of AFSL compliance”.

Alongside the legal and compliance obligations, the law firm added that licensees need to ensure their resourcing matches the risk.

“This includes engaging cyber security personnel to assess, implement and maintain cyber framework. Generic or outdated policies without specialist input will not meet ASIC’s standards,” it said.

Licensees are also responsible not only for their own systems, Hall & Wilcox said, but also for the “cyber security posture of their ARs and must mandate ongoing cyber security training and education for staff and ARs”.

“Such training should evolve as novel cyber security threats emerge to avoid becoming outdated.”

Tags: Compliance

Related Posts

Image: magann/stock.adobe.com

New year adviser losses spread across 161 licensees

by Keith Ford
January 12, 2026
0

According to the latest Padua Wealth Data numbers, while there was a net loss of 223 advisers for the period...

Image: Benjamin Crone/stock.adobe.com

Shield liquidators given go ahead to sell off holdings

by Keith Ford
January 12, 2026
0

In an update to unitholders late last year, Jason Tracy of Alvarez & Marsal said the Federal Court had made...

‘Conversion friction’ costing firms’ revenue: whitepaper

by Alex Driscoll
January 12, 2026
0

CLSR, regulatory and licensee fees are all well-known expenses and stressors for financial advice firms, and while it is true these conditions...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Innovation through strategy-led guidance: Q&A with Sheshan Wickramage

What does innovation in the advice profession mean to you?  The advice profession is going through significant change and challenge, and naturally...

by Alex Driscoll
December 23, 2025
Promoted Content

Seasonal changes seem more volatile

We move through economic cycles much like we do the seasons. Like preparing for changes in temperature by carrying an...

by VanEck
December 10, 2025
Promoted Content

Mortgage-backed securities offering the home advantage

Domestic credit spreads have tightened markedly since US Liberation Day on 2 April, buoyed by US trade deal announcements between...

by VanEck
December 3, 2025
Promoted Content

Private Credit in Transition: Governance, Growth, and the Road Ahead

Private credit is reshaping commercial real estate finance. Success now depends on collaboration, discipline, and strong governance across the market.

by Zagga
October 29, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Poll

This poll has closed

Do you have clients that would be impacted by the proposed Division 296 $3 million super tax?
Vote
www.ifa.com.au is a digital platform that offers daily online news, analysis, reports, and business strategy content that is specifically designed to address the issues and industry developments that are most relevant to the evolving financial planning industry in Australia. The platform is dedicated to serving advisers and is created with their needs and interests as the primary focus.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About IFA

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Risk
  • Opinion
  • Podcast
  • Promoted Content
  • Video
  • Profiles
  • Events

© 2026 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
  • About
  • Advertise
  • Contact Us

© 2026 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited