By Stephen Laird, Co-Founder & Technical Director, Com-X
No organisation wants to find itself in the news for a cybersecurity failure.
And yet, the reality of today’s threat landscape is that incidents are no longer rare, isolated, or reserved for poorly prepared organisations. They are becoming a normal part of doing business in a digital economy where attackers are faster, more organised, and increasingly supported by AI-driven tools.
The FIIG Securities case is a difficult but important reminder of this reality. It is also a public one. For the executives and board members involved, it is not the kind of attention anyone seeks. But for the broader market, it is a signal that cannot be ignored.
Because the uncomfortable truth is this: It could happen to any organisation that does not maintain adequate, continuous, and well-documented cybersecurity practices.
In February 2026, the Federal Court imposed a $2.5 million penalty on FIIG Securities for failing to maintain adequate cybersecurity and cyber risk management over an extended period. The ruling is now widely viewed as a landmark moment in Australian regulatory enforcement.
The message is no longer subtle: Cybersecurity is a governance responsibility, not just a technical control.
Why the FIIG Ruling Matters Beyond One Organisation
It is easy to look at a case like FIIG and see it as specific to financial services or large institutions. That would be a mistake.
While FIIG operated under an Australian Financial Services Licence (AFSL), the expectations reinforced by the court extend across industries where sensitive data, operational continuity, and customer trust are at stake.
Healthcare providers, education institutions, critical infrastructure operators, government agencies, and mid-market businesses are all now operating under increasing scrutiny from regulators, insurers, and customers.
The core principle established by the ruling is simple: Cybersecurity must be actively managed, adequately resourced, and continuously improved.
Not assumed. Not outsourced without oversight. Not addressed once a year during audit cycles.
The End of Checkbox Compliance
One of the most important lessons from the FIIG ruling is that cybersecurity compliance is not a once-a-year exercise.
Historically, many organisations approached cybersecurity through periodic assessments:
- Annual penetration testing
- Annual risk reviews
- Compliance audits every few years
- Security investments following major incidents.
That approach is increasingly viewed as inadequate.
Cyber threats evolve daily. Attackers continuously scan for vulnerabilities. New exploits emerge every week.
Artificial intelligence is accelerating the speed at which cybercriminals identify and exploit weaknesses.
As a result, regulators now expect cybersecurity to be managed as a continuous business process rather than a periodic compliance activity.
This represents a significant shift in mindset for boards and executive teams.
The Five Questions Every Board Should Be Asking
In the wake of the FIIG decision, directors should be asking management five critical questions.
1. Can We Demonstrate Our Cybersecurity Governance?
Having security controls is important.
Being able to demonstrate governance is equally important.
Boards should ensure there is clear documentation covering:
- Cybersecurity policies
- Risk management frameworks
- Security investment decisions
- Risk acceptance processes
- Executive and board reporting.
If a regulator requests evidence tomorrow, could your organisation produce it?
If the answer is uncertain, there is work to do.
2. Are We Continuously Managing Vulnerabilities?
Many organisations still rely on annual testing cycles.
Attackers do not.
Continuous vulnerability management is becoming a baseline expectation for organisations serious about reducing cyber risk.
This includes:
- Continuous asset visibility
- Vulnerability scanning
- Risk prioritisation
- Timely remediation
- Executive reporting.
Organisations need visibility into their attack surface at all times - not just during audit season.
3. Are We Adequately Resourced?
One of the court's key findings was that cybersecurity requires appropriate human and technological resources.
Boards should ask:
- Do we have sufficient internal expertise?
- Are responsibilities clearly defined?
- Do we have access to specialist security skills when required?
- Are our tools being actively managed and monitored?
Technology without expertise rarely delivers meaningful protection.
4. How Quickly Can We Detect and Respond?
Prevention remains important, but modern cyber resilience is equally focused on detection and response.
The reality is that many organisations will experience security incidents.
The difference lies in how quickly they identify and contain them.
Executive teams should understand:
- How threats are monitored
- Who responds to incidents
- What escalation processes exist
- Whether response plans are regularly tested.
A cyber incident is not the time to discover your processes are incomplete.
5. Are We Aligned to Recognised Frameworks?
Australian organisations increasingly look to the ACSC Essential Eight as a benchmark for cybersecurity maturity.
While no framework guarantees protection, recognised standards provide a defensible foundation for governance and risk management.
Boards should understand:
- Current maturity levels
- Existing gaps
- Remediation priorities
- Investment requirements.
Alignment with recognised frameworks demonstrates a commitment to reasonable security practices and continuous improvement.
The Hidden Risk: Documentation
Perhaps the most overlooked lesson from the FIIG ruling is documentation.
Many organisations make sensible cybersecurity decisions but fail to document them effectively.
This creates significant risk.
If a regulator, insurer or court examines your cybersecurity posture after an incident, undocumented decisions effectively do not exist.
Organisations should ensure they maintain records covering:
- Security investment decisions
- Risk assessments
- Vulnerability remediation activities
- Resource allocation decisions
- Risk acceptance approvals
- Board reporting and oversight.
Good governance requires evidence.
Cybersecurity Is Now a Business Imperative
The cybersecurity landscape has changed dramatically over the past five years.
AI-powered attacks are becoming more sophisticated.
Ransomware continues to evolve.
Regulatory scrutiny is increasing.
Cyber insurance requirements are becoming more stringent.
The FIIG ruling confirms what many security professionals have been saying for years: Cybersecurity is now a core business function.
Boards and executive teams that treat it as an operational afterthought will find themselves increasingly exposed to financial, operational and regulatory risk.
Those who invest proactively in governance, visibility, resilience and continuous improvement will be better positioned to protect their organisations and meet growing stakeholder expectations.
The Bottom Line
The FIIG decision is more than a court ruling.
It is a signal that Australian organisations are entering anew era of cybersecurity accountability.
Regulators are no longer asking whether cybersecurity matters.
They are asking whether organisations can demonstrate that they have taken appropriate steps to manage cyber risk.
For boards and executives, the time to answer that question is now - not after an incident occurs.
Is Your Organisation Prepared?
At Com-X, we help organisations assess their cybersecurity maturity, align with frameworks such as the ACSC Essential Eight, implement continuous vulnerability management, strengthen governance, and improve cyber resilience.
Whether you're preparing for an audit, reviewing board-level risk obligations, or looking to improve your overall security posture, our team can help you identify gaps and prioritise practical improvements.
Contact Com-X today for a Cybersecurity Governance and Risk Assessment and discover how prepared your organisation is for today's evolving threat and regulatory landscape.




