$2.5 Million Fine for “Inadequate Cybersecurity”

Financial-services trading desk with regulatory penalty warnings on screen

Estimated Exposure: Client financial data breached. $2.5 million penalty.

What Happened: Fiig Securities — a financial services firm — ran “inadequate cybersecurity measures” for more than four years. Then they got hacked. ASIC took them to the Federal Court. Not the privacy regulator — the financial regulator. First time ever the Federal Court imposed civil penalties for cybersecurity failures under Australian Financial Services licence obligations.

The message: if you hold a licence, you hold a duty. Four years of knowing your security was shit and doing nothing about it now has a $2.5 million price tag. And ASIC has said publicly there are more actions coming.

Source: ASIC v Fiig Securities, Federal Court of Australia 2025

FIIG Securities faced Federal Court action over cybersecurity failures under its Australian financial services licence obligations.

Get Certified Before
You're the Next Headline

Every story on this page started the same way — a published vulnerability, a site nobody was watching, and weeks before anyone noticed. The free scan looks at your site from the outside, the same way an automated scanner does. It costs nothing, there is no obligation, and it takes about thirty seconds to start.

Scan My Site — Free