X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the ifa bulletin
  • News
  • Opinion
  • Podcast
  • Risk
  • Video
  • Events
    • ifa Excellence Awards
    • Super Fund Of The Year
    • Australian Wealth Management Awards
    • Fund Manager Of The Year
    • Evolution of Advice Summit
    • Australian Wealth Management Summit
  • Promoted Content
  • Webcasts
No Results
View All Results
  • News
  • Opinion
  • Podcast
  • Risk
  • Video
  • Events
    • ifa Excellence Awards
    • Super Fund Of The Year
    • Australian Wealth Management Awards
    • Fund Manager Of The Year
    • Evolution of Advice Summit
    • Australian Wealth Management Summit
  • Promoted Content
  • Webcasts
No Results
View All Results
No Results
View All Results
Home Opinion

How advice businesses can use outsourcing to manage their cyber security risk

When it comes to cyber security risk, most financial advice practices focus on the advice compliance file but this can be at the expense of other key areas. Outsourcing cyber security risks can be a good option for capability-stretched licensees. However, it requires proper due diligence to implement.

by David Carney
August 29, 2022
in Opinion
Reading Time: 5 mins read
How advice businesses can use outsourcing to manage their cyber security risk

Increased responsibility to understand and assure a secure operating environment under which advice is produced, stored and shared has emerged as a result of a Supreme Court ruling. RI Advice was a highly regarded advice licensee with 119 practices. But between June 2014 and May 2020, nine cyber security incidents were found within their network, ranging from fraudulently sent emails to phishing incidents and hacking attacks.

The ruling has motivated all licensees and insurers to critically examine their standards and third-party relationships they hold across their network. We expect specific requirements to be placed on practices to mitigate the cyber security risks through evidence and attestation by both licensees and the insurers.

X

Whilst all advice businesses have professional indemnity (PI), very few have coverage specifically for cyber security. This is due to a lack of proper education by the industry around the issue. In addition, cyber security is currently not a requirement for corporate authorised representatives or PI insurers.

This is expected to change. If cyber security protection is not mandated, it should be considered best practice given the rate of attempted cyber attacks globally as infrastructure moves to digital storage via remote access.

Cyber security is merely one component of a larger framework of governing risks and threats to the viability of an advice firm. Governance can include assessment of risks such as money laundering and terrorism financing, and the creation and maintenance of a risk register to record them as well as regular strategies to manage the commercial and financial viability of the business.

However, many advice firms don’t consider cyber security to be significant enough for further attention. This can be a dangerous stance to take. You only need to look at the case of RI Advice when ASIC found that it failed to have adequate risk management systems to manage its cyber security risks. The consequences were devastating, with RI Advice ordered to pay $750,000 towards the regulator’s costs.

Why cyber security remains a gap in risk governance

Most risk compliance managers understand what is required to effectively manage any threats that may come their way. However, corporate governance frameworks often provide little insight as to how to execute a proper cyber security strategy for their firm.

A reason this may be the case is that cyber security approaches can vary from business to business, leading to inconsistencies across the industry and complacency within firms.

There are many key decisions principals and compliance managers need to consider around forming a proper governance framework, including:

  • Clear and deliberate commitment to move from file compliance to business governance, through its addition to quarterly business planning and specific appraisal when considering different technology implementation and third-party relationships
  • Deciding the ownership of governance – who is responsible for different business line functions within the business through the development of a responsibility assignment (RACI) matrix
  • Whether to outsource your governance to an outsourcing firm or keep it in-house
  • Completing an external governance risk assessment that includes evaluating business operations and finding improvements, assessing your procedures to determine compliance with industry regulations and standards
  • Deciding line-item ownership of the risk register across the various roles within the advice business. It’s important that everyone is involved in the governance of the business, and that position descriptions should include ownership or risk and which projects they own; and
  • Regularly reassessing the significance of risk and determining projects to mitigate those risks. In some of those projects, you might look to third-party suppliers where you may have capability or knowledge gaps within your internal structure.

Implementing a proper cyber security framework

To meet the need for better cyber security governance, there are several frameworks and standards that help businesses create or enhance their cyber security program to cover all areas of their information security. Standards ISO 27001 and APRA CPS 234 are two such examples, each designed to meet a particular set of needs.

ISO 27001 allows for advice businesses to adopt a risk-based approach to information security that is internationally accepted as best practice. Achieving this certification proves to clients and partners that your business is committed to achieving a global standard of information security. Third-party relationships that meet this international certification in information management ensure you have a defensible position when it comes to cyber security.

In addition, APRA recently created a new standard called APRA CPS 234 to help APRA-regulated entities increase their overall resilience towards incidents that can affect the security of information.

While not applying directly to advice practices, the standard speaks to the more serious approach being taken towards cyber security across the Australian financial services ecosystem. Advice businesses whose group ownership is based within Australia provide additional protection under Australian laws.

Conclusion

As more practices shift to self-licensing, there is also a greater need for businesses to understand issues of governance, cyber security and sustainability as they are no longer outsourcing these competencies to a licensee.

Advice practices have no excuse to not implement cyber security into their governance framework. Not only will it provide the principal (and the team) peace of mind, but it will also give them assurance that they won’t be prone to data breaches and become the next whose licensee finds themselves on the wrong side of ASIC.

David Carney, CEO, Virtual Business Partners

Tags: Outsourcing

Related Posts

Image: Steve Sloane, LinkdIn

The End of Financial Year doesn’t create an adviser capacity problem, it exposes it

by Steve Sloane
July 6, 2026
0

Contribution strategies, capital gains planning, structuring calls, insurance, and a wave of reviews clients want done before the year turns...

Image: LinkdIn

The new correlation problem

by Matt Quaife
June 29, 2026
0

If you’re sitting in front of clients or investment committees at the moment, it probably feels like markets are being...

Image: Justin Gilmour/supplied

Advisers need to be paid on value not years of experience

by Justin Gilmour
June 22, 2026
3

More importantly, it is becoming a barrier to attracting, developing and retaining the next generation of advisers our industry desperately...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
News

Shane Oliver joins Australian Wealth Management Summit as keynote speaker

Shane Oliver joined AMP in 1984, becoming Chief Economist in 1994 and is now Chief Economist and Head of Macro...

by ifa Staff
June 22, 2026
Promoted Content

Got your own AFSL? You don’t need to go it alone.

With the licensee landscape constantly shifting, holding your own license means that your future itself is not tied to someone...

by Lifespan
June 4, 2026
Promoted Content

Why portfolio resilience matters more in a volatile world

Private credit in a volatile world: why investors are revisiting portfolio resilience From escalating geopolitical conflict to rising oil prices...

by Zagga
March 26, 2026
Promoted Content

The importance of empathy and the advice regulatory quagmire: a Q&A with Ashley Tilston

Congratulations on winning Holistic Adviser of the Year for both NSW and Australia at the ifa awards, what do you think set you apart to...

by Alex Driscoll
March 3, 2026

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Poll

This poll has closed

Do you have clients that would be impacted by the proposed Division 296 $3 million super tax?
Vote
www.ifa.com.au is a digital platform that offers daily online news, analysis, reports, and business strategy content that is specifically designed to address the issues and industry developments that are most relevant to the evolving financial planning industry in Australia. The platform is dedicated to serving advisers and is created with their needs and interests as the primary focus.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About IFA

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Risk
  • Opinion
  • Podcast
  • Promoted Content
  • Video
  • Profiles

© 2026 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Opinion
  • Podcast
  • Risk
  • Video
  • Events
    • ifa Excellence Awards
    • Super Fund Of The Year
    • Australian Wealth Management Awards
    • Fund Manager Of The Year
    • Evolution of Advice Summit
    • Australian Wealth Management Summit
  • Promoted Content
  • Webcasts
  • Advertise
  • About
  • Contact Us

© 2026 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited