Nmap Law

Networks, Media, AI and Privacy Law

ASIC v FIIG: What the Court Decision Reveals About Cyber Liability and Evidence

ASIC v FIIG cyber governance analysis

ASIC v FIIG is not primarily a cyber story

It is a story about a company that represented its security posture to regulators and customers while operating with controls that did not match those representations. The gap between the claim and the reality is where liability lives. That is the signal worth paying attention to.

The case exposed known vulnerabilities left unpatched, security monitoring not operating effectively, and a gap between what was reported upward and what was happening at the system level. None of that is technically exotic. It is the ordinary failure mode of organisations that treat cyber governance as a reporting exercise rather than an operational one.

Why evidence matters more than policy

Most organisations have policies. The Privacy Act requires them, ISO 27001 requires them, every audit framework requires them. Policies are cheap to produce and easy to present. What courts actually examine is whether the policy connected to a real operational control, whether that control was tested, and whether someone can stand up and explain what the test showed.

If your access control policy says privileged accounts are reviewed quarterly and the last review was eighteen months ago, the policy is not a protection. It is a document proving you knew what you were supposed to do and did not do it.

The practical implication: for every control you are claiming to have, there should be evidence it actually operates. Logs, test results, audit outputs, remediation records. If you cannot produce that evidence, you have a gap that will matter when things go wrong.

Where the gaps usually hide

Controls that are claimed but rarely tested are the most common problem. Close behind are vendors who are supposed to provide controls but are never audited. Incident procedures that are documented but never practised sit in the same category. All three look fine on paper until a forensic investigator or a court asks for the receipts.

This pattern is predictable enough that it should inform how you scope an assessment or an advisory engagement. Testing whether a control exists is useful. Testing whether evidence of its operation exists and would hold up to scrutiny is the work that actually protects clients.

A practical starting point

Pick one high-risk control claim. Find the last evidence it actually operated. Trace what has happened since. If the answer is unclear, you have found the gap worth fixing.

If you are advising an organisation after a breach, this is the first question to answer before you touch anything else: what can you prove, and what can you not? The answer shapes every conversation with regulators, insurers, and legal counsel that follows.

The organisations that manage to defend themselves credibly after an incident are not the ones with the most mature frameworks. They are the ones that can produce a clean, contemporaneous record of how they managed their controls before the incident happened. Start building that record now.