X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the ifa bulletin
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
No Results
View All Results
Home News

What happens after a cyber incident?

Cyber security is an important issue for all businesses, but financial advice firms need to be particularly vigilant.

by Keith Ford
January 10, 2024
in News
Reading Time: 4 mins read
Share on FacebookShare on Twitter

Financial advice firms face some specific risks around cyber security due to their access to financial information. Combined with a recent history of hacks that have shown that even the largest businesses in Australia are in danger of hacks, such as Optus and Medibank, it is important that advice firms prepare for what happens in the event of a cyber incident, not just how to avoid one.

According to Jason Symons, partner – head of cyber at Mills Oakley, the first reaction is often grief and denial.

X

“I think denial is pretty common because it’s that moment where it’s like, ‘Oh, it’s our turn’ or ‘It’s happened to us’,” Mr Symons said on the FAAA podcast.

“You have to be able to, I guess, help whoever’s found out, whoever the leaders of that organisation are, to not panic, to try and keep reasonably calm, and that there are people who are experienced in dealing with one of these and we can help them.”

This transitions into a period where a team of experts is working together across disciplines involving legal, IT forensics, communications, both external experts and internal people dealing with each of those issues.

“We’re working together. We’re having regular teams meetings, or even face to face, war-room type situations and we’re working through the problem methodically,” Mr Symons added.

“Whether it’s a ransomware attack dealing with the criminal group, or it might be some sort of live data breach where we have to manage the assessment of that data breach and possibly notification.”

Importantly, Mr Symons said, in addition to requirements around informing clients of a breach and when that needs to happen, there are also regulatory requirements involved in the response to a cyber incident, such as informing the Office of the Australian Information Commissioner (OAIC).

“That’s the regulator that sits within the Privacy Act. When we talk about a data breach, we’re talking about personal information being compromised by criminals and the access or disclosure of information,” he said.

“The regulator is interested in you telling her and the individuals impacted within certain periods of time and providing regulated information in your notification.

“But then, if you’re responsible for critical infrastructure assets, you have to tell the Australian Cyber Security Centre (ACSC) about an incident. If you’re not, but you still want to tell the government what’s happening to you as a responsible corporate citizen, or you may want to see if they’ve got information about the criminal group that could be useful to you, you inform the ACSC through the cyber reporting website.

“But what that then does is that can then filter through to the different state police authorities, the Federal Police, and that coordination of government agencies happens through the ACSC.”

There is also a clean-up phase that happens following an incident, ranging from technical issues to responding to client questions.

“If we’re talking about an incident that’s been notified to different regulators, there’s often a tail to that of questions being asked and you having to respond,” Mr Symons said.

“Similarly, if you’ve notified hundreds of people or even thousands, that notification process might take a while and working it through possibly responding to questions, having FAQs online, updating websites, that all goes on for a while.”

“Then you’ve got to think about whether there’s clean-up with regards to the business itself. So, are you back online properly now? Have you been able to restore from backups or recover the system separately, and that’s a whole other stream of work that can take some time.”

Unsurprisingly, a business can take a serious reputational hit when clients have had their data breached, so the clean-up phase also includes a “brand rebuild”.

“The brand rebuild starts to happen in this phase, which is you’re through the immediate crisis, and then you need to take a step back and go, ‘OK, what trust have we lost here? What has happened to our company more broadly, that we might need to address through different strategies and working through that?’”

Related Posts

Image: ergign/stock.adobe.com

InterPrac to defend ASIC claims over ‘external investment product failure’

by Keith Ford
November 14, 2025
4

Following the Australian Securities and Investments Commission’s (ASIC) announcement that it had commenced civil proceedings against InterPrac Financial Planning, ASX-listed...

Image: Benjamin Crone/stock.adobe.com

Banned licensee under fire over $114m of investments in Shield

by Keith Ford
November 14, 2025
2

The Australian Securities and Investments Commission (ASIC) has sought leave to commence proceedings that allege MWL operated a business model,...

brain

Emotional intelligence remains a vital skill for the modern adviser

by Alex Driscoll
November 14, 2025
0

Financial advice, more so than other wealth management professions, relies deeply on a well-functioning and collaborative relationship between professional and...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Private Credit in Transition: Governance, Growth, and the Road Ahead

Private credit is reshaping commercial real estate finance. Success now depends on collaboration, discipline, and strong governance across the market.

by Zagga
October 29, 2025
Promoted Content

Boring can be brilliant: why steady investing builds lasting wealth

Excitement sells stories, not stability. For long-term wealth, consistency and compounding matter most — proving that sometimes boring is the...

by Zagga
September 30, 2025
Promoted Content

Helping clients build wealth? Boring often works best.

Excitement drives headlines, but steady returns build wealth. Real estate private credit delivers predictable performance, even through volatility.

by Zagga
September 26, 2025
Promoted Content

Navigating Cardano Staking Rewards and Investment Risks for Australian Investors

Australian investors increasingly view Cardano (ADA) as a compelling cryptocurrency investment opportunity, particularly through staking mechanisms that generate passive income....

by Underfive
September 4, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Poll

This poll has closed

Do you have clients that would be impacted by the proposed Division 296 $3 million super tax?
Vote
www.ifa.com.au is a digital platform that offers daily online news, analysis, reports, and business strategy content that is specifically designed to address the issues and industry developments that are most relevant to the evolving financial planning industry in Australia. The platform is dedicated to serving advisers and is created with their needs and interests as the primary focus.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About IFA

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Risk
  • Opinion
  • Podcast
  • Promoted Content
  • Video
  • Profiles
  • Events

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited