This masthead covered ASIC's 8 May open letter when it landed. Its legal spine is a single sentence pointing at a Federal Court judgment, and since then that sentence has been doing a lot of work in board papers, vendor decks and law firm alerts. Almost none of them appear to have opened the judgment. So we did.
It is Australian Securities and Investments Commission v FIIG Securities
Limited [2026] FCA 92, decided by Derrington J on 13 February 2026. It is short,
readable, and 86 paragraphs long. ASIC says in its media release that it is
the first time the Federal Court has imposed civil penalties for cyber security
failures under the general AFS licensee obligations
. That characterisation is the
regulator's; the judgment itself does not describe itself as a first.
What the judgment does not say
ASIC's letter tells licensees that, as set out in the court's judgment
, cyber
risk management must be demonstrably effective and proportionate to the size, nature and
complexity of a business. We searched the full judgment for that language. The word
“demonstrably” appears zero times. “Proportionate” appears zero
times. “Size, nature and complexity” appears zero times.
That is not an accusation, and it should not be read as one. Regulators summarise judgments constantly, and a summary is not a quotation. As we set out below, the substance of ASIC's gloss is defensible: the judgment does tie the standard to the circumstances of the particular business. The point is narrower and practical. If your obligation is being described to you in words the court did not use, the words the court did use are worth having, because they are the ones that will be applied.
What the judgment actually says
Three things matter, and none of them is the phrase in circulation.
First, there is no standard of perfection. Recording the parties' joint
submissions on settled law, the judgment states that section 912A(1)(a)
does not impose a standard of perfection, but is a forward-looking standard, directed to
the taking of steps to achieve compliance with the statutory norm
. For anyone who has
sat through a briefing implying that any breach proves inadequacy, that sentence is the
correction.
Second, adequacy is a normative standard, judged against your risks.
Sections 912A(1)(d) and (h) impose a standard of adequacy
, which the judgment
describes as importing a normative standard of conduct against which the licensee's
provision of resources and risk management systems can be judged
. Assessing adequate
risk management systems in a cyber context, it says, requires consideration of the risks
faced by a licensee and whether the business had adequate systems to manage those risks.
Third, and most useful, there is a five-factor test. At paragraph 17 the judgment sets out what should inform the standard of competence in respect of cybersecurity, or, as it puts it, the reasonable standard of performance that the public is entitled to expect:
- the nature of the business, including its size and resources;
- the personal client information it held;
- the value of funds under advice and assets held on behalf of clients;
- the magnitude and potential consequences of the cyber security risks; and
- its contractual obligations to its clients.
Taking those into account, the judgment says the licensee ought to have had in place a
regime of cyber security measures appropriate to its circumstances
.
That last phrase is where ASIC's “proportionate” comes from, and it is a fair compression. But it is a compression of five named, assessable factors into one adjective, and the five are what an adviser or an expert will actually work through. Two of them, the client information held and the contractual obligations owed, are the sort of thing that never appears in a generic maturity assessment.
Where the AI part actually sits
Worth being straight about this, because the framing invites confusion: the FIIG judgment is not an AI case. It concerns cyber security measures at a fixed income broker between 2019 and 2023, and the word artificial intelligence is not what it turns on. The AI connection is ASIC's, not the court's: the regulator's position is that frontier AI is accelerating the cyber threat, and that the existing standard, as illustrated by FIIG, is what licensees will be measured against in that changed environment.
That is a legitimate regulatory move and we said so when the letter landed. It is also why the five factors matter more than the slogan. If AI raises the magnitude and potential consequences of the risks you face, factor four moves, and with it what counts as adequate for you. The test is not a fixed bar that AI has raised. It is a standard that reads your circumstances, and AI is one of the things changing them.
What it cost, and what a court can order
The orders are worth knowing because they show the range of what follows a finding. The court ordered a pecuniary penalty of $2.5 million, payable within 30 days, for contraventions of section 912A(5A), the civil penalty provision engaged when a licensee breaches those licensee obligations.
It also ordered FIIG to pay $500,000 towards ASIC's costs, again within 30 days.
And it ordered a compliance programme under section 1101B(1): engage an independent expert agreed with ASIC, have that expert report on what further documentation, resources and controls in respect of cyber security and cyber resilience are necessary to reasonably manage risk, and then implement the remedial actions identified. That second order is the one to notice. A penalty is a number. A court-supervised expert deciding what your controls must become is an operating constraint, and it is available whenever this section is engaged.
What we would take to a board
This is our view, built on the text above. If you are preparing the tabling that ASIC's letter asks for, the useful artefact is not a statement that your controls are “demonstrably effective”. It is a short document that walks the five factors, says what each means for your business, and says what you have done about the risks they surface. That maps onto how the standard is actually assessed, and it survives the question the slogan invites, which is: demonstrable to whom, against what?
We have linked the judgment below. It runs to 86 paragraphs and the part that matters is paragraphs 14 to 18. It is worth the twenty minutes.