AUSTRALIA Trends and Developments Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
selves or a law attracting “a penalty or sanction for a criminal offence”. This prevents the information from being used in most regulatory enforcement actions, but leaves the entities exposed to criminal law provi - sions. While individuals (including directors) may be able to rely on the privilege against self-incrimination where criminal law issues become live, the business entity itself is unlikely to have such protections given cor - porate entities do not have such a privilege under Australian law. Public suggestions of including a safe harbour provision were dismissed by the Australian government and this may complicate compliance with this obligation, particularly if the Australian govern - ment relies on criminal sanctions (alone or as alterna - tives to civil penalties) to enforce cybersecurity leg - islation. Contrastingly, there are expanded protections for any information voluntarily provided to the National Cyber Security Co-ordinator concerning an actual or poten - tial cybersecurity incident, with Section 42 rendering such information inadmissible in criminal proceed - ings (except in very specific circumstances) and any “proceedings for breach of any other Commonwealth, State or Territory law (including the common law)”. However, these protections do not prevent authorities from obtaining the information via other methods and relying on it thereafter. Online Safety Act On 10 December 2025, the under 16-year-old ban mandated by the Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) came into effect and more than five million accounts were deactivated. This legislation passed 12 months prior and imposed an obligation on ten social media platforms to take “reasonable steps” to prevent age-restricted users from having an account, imposes restrictions on the kind of information that can be collected, and how this information is stored, used, and protected. Since the legislation’s passing, the government adopted the Online Safety (Age-Restricted Social Media Plat - forms) Rules 2025 and the eSafety Commissioner has released guidance. Reportedly, several countries, including Denmark, France, New Zealand, and Malay -
sia, as well as the EU, have said they are considering similar bans. Enforcement ASIC enforcement action In 2025, ASIC has ramped up its enforcement action and commenced its second and third cybersecurity enforcement actions against AFS licensees. • In March 2025, FIIG Securities Limited (FIGG) was taken to the Federal Court for failing to have adequate cybersecurity measures for more than four years in contravention of Sections 912A(1)(a), (d), and (h), and 912A(5A) of the Corporations Act 2001 (Cth). ASIC sought civil penalties and compli - ance orders. • In July 2025, Fortnum Private Wealth Limited (“Fortnum”) was taken to the Supreme Court of NSW, with ASIC seeking declarations that Fortnum failed to comply with its licensee obligations under Section 912A of the Corporations Act 2001 (Cth) and a pecuniary penalty. The first such action was finalised in May 2022, when the Federal Court ruled another AFS licensee, RI Advice, had breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecu - rity risks. Both of these cases appear to have involved a cyber- incident, with a hacker accessing FIIG’s IT network undetected from 19 May to 8 June 2023, only coming to FIIG’s attention when contacted by ASD’s ACSC regarding a potential cybersecurity incident on 2 June 2023 and failing to investigate for six days; and several of Fortnum’s authorised representatives experiencing cyber-incidents in or around May 2023, including one major cyber-attack that led to the data of 9,000 clients being published online. ASIC’s position is that cyber-risk management is a non-negotiable part of AFSL compliance and a key part of a licensee’s duty to provide services efficiently, honestly, and fairly under Section 912A of the Corpo - rations Act. The importance is underscored by ASIC’s priorities announced in its Corporate Plan (2025-26),
29 CHAMBERS.COM
Powered by FlippingBook