Skip to content

How to avoid
the cost of a
cybersecurity breach

blank

Why is ISO 27001 the right framework?

ISO 27001 is the internationally recognised standard for information security management, it outlines how to:

  1. Identify and treat information risks
  2. Establish clear governance policies
  3. Continuously monitor and improve
  4. Align people, processes and technology to protect information assets

While ISO 27001 is not mandatory under the ASIC RG104, it is often used as a benchmark of adequacy in risk and compliance audits.

What does best practice look like?

While many small to medium sized fin services firms outsource their technical support, they are still liable for establishing the right governance practices, all backed by external controls.

Here’s a typical 20–30-person firm that meets ASIC’s expectations:

  1. Live threat alerting via SIEM tools
  2. Incident response plan with clearly defined escalation
  3. Multi-factor authentication (MFA) for all remote and privileged access
  4. Annual backup testing, including offsite and immutable storage
  5. Ongoing staff cyber awareness training and policy sign-offs

Need Help?

If you need help in understanding how this will impact your
financial services business, join our Webinar Event.

Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.