Cybersecurity advice can get vague very quickly. Businesses are told to take cyber risk seriously, improve governance and have appropriate controls, but that still leaves a fairly obvious question: what does that actually mean in practice?
The Federal Court’s February 2026 orders against FIIG Securities give a useful answer. Following proceedings brought by ASIC, FIIG was ordered to pay $2.5 million in pecuniary penalties, contribute $500,000 towards ASIC’s costs and undertake a compliance program involving an independent expert. The case followed a 2023 cyberattack in which around 385GB of confidential information was stolen and some 18,000 clients were notified that their personal information may have been compromised.
The useful part for other businesses is not the headline penalty. It is the list of controls ASIC says were missing or inadequate.
The issue was bigger than one successful cyberattack
FIIG admitted that it failed to comply with its Australian Financial Services licence obligations and that adequate cybersecurity measures, suited to the size of the firm and the sensitivity of the information it held, would have helped it detect and respond to the breach sooner.
ASIC also said following FIIG’s own policies and procedures could have supported earlier detection and prevented some or all of the client information from being downloaded. That distinction matters. A documented policy is not much use if the controls described in it are not actually operating.

Photo by Christina @ wocintechchat.com via Unsplash.
What ASIC identified as inadequate
MFA, passwords and privileged access
ASIC specifically identified inadequate multi-factor authentication for remote access users, weak password controls and inadequate access controls around privileged accounts. These are fairly basic identity controls, but they only help when they are properly scoped and enforced across the systems that matter.
Patching and vulnerability management
The case also identified the absence of a structured plan to ensure key software systems were being updated for security vulnerabilities, along with inadequate penetration testing and vulnerability scanning. Updating systems cannot depend on somebody remembering to do it when they have spare time.
Monitoring that somebody actually responds to
One of the more important findings was the lack of suitably qualified IT personnel monitoring threat alerts so cyberattacks could be identified and acted on. Buying security software is only part of the job. If alerts are generated but nobody is responsible for reviewing, investigating and escalating them, the business can still have a large blind spot.
This is the practical difference between simply having security tools and having a functioning security monitoring and response process.
Security awareness training
ASIC also identified the absence of mandatory cybersecurity awareness training. Training is not a substitute for technical controls, but team members should know how to recognise suspicious activity, how to report it quickly and what to do when something does not look right. That is the approach we covered in our cybersecurity awareness training guide.
An incident response plan that is actually tested
FIIG was also found not to have an appropriate cyber incident response plan tested at least annually. A document sitting in a folder is not the same as knowing who will make decisions, who will contain systems, what evidence needs to be preserved, how backups will be handled and who needs to be contacted when an incident occurs.
Enough people and resources to manage the risk
The Court outcome was not just about technical configuration. ASIC also pointed to inadequate financial, technological and human resources. Cybersecurity has to have an owner, enough time and the right capability behind it. It cannot be treated as an extra task that somebody eventually gets to.

Photo by Campaign Creators via Unsplash.
This does not mean every business faces the same $2.5 million penalty
FIIG was an Australian Financial Services licensee, and the proceedings concerned specific obligations under its AFS licence and the Corporations Act. Different businesses have different legal and regulatory obligations. The FIIG outcome should not be read as a claim that every Australian small business can be penalised in exactly the same way for the same amount.
The broader lesson is still useful: regulators are increasingly looking beyond whether a business bought a security product. The more important question is whether the organisation has controls that are proportionate to its size and the sensitivity of the information it holds, and whether those controls can be shown to work.
The useful question is: can you prove the controls are working?
For a smaller professional services business, that does not require building a giant internal security department. It does mean being able to answer some fairly practical questions.
Is MFA actually enforced where it matters?
Not just enabled for most users. Can you show which accounts, applications and administrative access paths are protected, and where any gaps remain?
Can you show that systems are being patched?
There should be visibility over device and software update status, a way of identifying exceptions and a process for dealing with systems that cannot be patched normally.
Who reviews security alerts?
If the answer is just that the endpoint or firewall sends alerts, the next question is who reviews them, when they are reviewed and what happens when something genuinely suspicious is detected.
When was the incident response process last tested?
A short tabletop exercise can expose missing contacts, unclear responsibilities, backup assumptions and gaps in logging before the business is dealing with a real incident.
The takeaway for smaller businesses
The FIIG case is not a reason to panic or buy another pile of security products. It is a good reminder that basic controls need to be implemented properly, monitored and supported with evidence.
Frameworks such as the Essential Eight are useful because they turn some of this into a more structured set of controls. The same principle applies more broadly: know what is in place, know where the gaps are, make sure somebody owns the monitoring and response, and keep enough evidence to show the controls are operating.
Q10 can review the technical side of an environment, including identity, endpoint security, patching, monitoring, backups and incident response readiness, then work through the gaps in sensible stages. See our cybersecurity services or managed IT services for more information.
Source: ASIC, ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failures, 9 February 2026.
Featured image: Dan Nelson / Unsplash.
