Cybersecurity and
AFSL compliance and
what every financial services leader needs to know

Our Services
In 2022, ASIC updated its guidance under Regulatory Guide 104 (RG 104), reinforcing the responsibility of Australian Financial Services License (AFSL) holders to maintain adequate technological resources.
For leaders in financial services, this means that cybersecurity is no longer an optional IT issue, it is now central to your compliance obligations, business continuity, and client trust.
But what does RG104 mean?
RG104 makes it really clear to all AFSL holders, they must maintain technology that is both stable and secure, aligned to the nature, scale and complexity of their financial services business. However, RG104 is well beyond the right infrastructure.
As an overview RG104 obligations highlight:
- Cybersecurity and information security
- Risk management systems
- Outsourced IT Oversight
- Incident Response
- Employee Training & Supervision
So why is this important?
Over the last 18 months, multiple financial services firms in Australia have faced ASIC enforcement actions, not just because they were breached but because they couldn’t demonstrate adequate cyber risk management before a breach occurred.
In one high profile case in 2023, a boutique Advisory Firm received $1.2million penalty and temporary suspension of license operations due to failure to implement basic cybersecurity safeguards including:
- No formal incident response plan
- Inadequate endpoint protection
- No staff cybersecurity awareness training
What are regulators expecting?
ASIC has repeatedly highlighted the importance of the following requirements:
- Cyber risk registers as a part of your business risk
- Third party oversight including you working with MSPs and cloud vendors
- Business continuity plans and stress testing the plans
- User activity monitoring and transparency on privilege access controls
- ISO 27001 alignment especially where regulatory scrutiny is higher
Need Help?
financial services business, join our Webinar Event.
Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.