Significant fine for data breach

I read an article in Lexology that I thought was important enough to share with our readers.
‘The Australian Securities and Investments Commission (ASIC) has secured a Federal Court ruling requiring FIIG Securities Limited (FIIG) to pay $2.5 million in civil penalties for longstanding failures in cyber security and data protection.1 The ruling marks the first time the Federal Court has imposed civil penalties for cyber security failures under Australian Financial Services licence (AFSL) obligations, and represents a significant development in Australian regulatory treatment of data protection and cyber risk within the financial services sector.
The action followed a significant 2023 cyber incident in which approximately 385 gigabytes of highly sensitive personal information, including driver’s licence details, passport information, bank account numbers and tax file numbers, was stolen and later published online.2 While the penalty was imposed under licensing provisions rather than privacy? Specific legislation, the decision has broader implications for how organisations approach personal data governance and cyber resilience.’
You can access the article for free using this link: https://www.lexology.com/r/VBzhZNz/157fb7af50
Clearly every organisation has a duty to protect the privacy of their staff, customers, suppliers and other stakeholders. In addition, it is a no brainer that cyber insurance is a virtually important insurance protection.