Cyber & RG104 Guide for AFSL Holders

Cyber & RG104 Guide for AFSL Holders

blank

Download the guide

Meeting Your RG 104 Obligations.

A 5 minute read for Australian financial services executives. Covers the four RG 104 obligation areas, the five foundational controls, a 90 day plan, and nine questions for your IT partner.

Written for executives, read in five minutes, designed to be forwarded to your information technology partner or compliance lead.

Whats Inside

  • The 4 RG 104 obligation areas and the section 912A duty behind them
  • The 5 foundational cyber controls mapped to RG 104.100’s 10 review criteria
  • 30 / 30 / 30 day plan: assess, remediate and evidence
  • The 9 questions to put to your information technology partner
  • Recent ASIC enforcement: RI Advice, FIIG Securities, ASIC supervisory posture

How to avoid the cost of a cybersecurity breach

blank

How to avoid
the cost of a
cybersecurity breach

blank

Why is ISO 27001 the right framework?

ISO 27001 is the internationally recognised standard for information security management, it outlines how to:

  1. Identify and treat information risks
  2. Establish clear governance policies
  3. Continuously monitor and improve
  4. Align people, processes and technology to protect information assets

While ISO 27001 is not mandatory under the ASIC RG104, it is often used as a benchmark of adequacy in risk and compliance audits.

What does best practice look like?

While many small to medium sized fin services firms outsource their technical support, they are still liable for establishing the right governance practices, all backed by external controls.

Here’s a typical 20–30-person firm that meets ASIC’s expectations:

  1. Live threat alerting via SIEM tools
  2. Incident response plan with clearly defined escalation
  3. Multi-factor authentication (MFA) for all remote and privileged access
  4. Annual backup testing, including offsite and immutable storage
  5. Ongoing staff cyber awareness training and policy sign-offs

Need Help?

If you need help in understanding how this will impact your
financial services business, join our Webinar Event.

Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.

Cybersecurity and AFSL compliance and what every financial services leader needs to know

blank

Cybersecurity and
AFSL compliance and
what every financial services leader needs to know

blank

In 2022, ASIC updated its guidance under Regulatory Guide 104 (RG 104), reinforcing the responsibility of Australian Financial Services License (AFSL) holders to maintain adequate technological resources.

For leaders in financial services, this means that cybersecurity is no longer an optional IT issue, it is now central to your compliance obligations, business continuity, and client trust.

But what does RG104 mean?

RG104 makes it really clear to all AFSL holders, they must maintain technology that is both stable and secure, aligned to the nature, scale and complexity of their financial services business. However, RG104 is well beyond the right infrastructure.

As an overview RG104 obligations highlight:

  • Cybersecurity and information security
  • Risk management systems
  • Outsourced IT Oversight
  • Incident Response
  • Employee Training & Supervision

So why is this important?

Over the last 18 months, multiple financial services firms in Australia have faced ASIC enforcement actions, not just because they were breached but because they couldn’t demonstrate adequate cyber risk management before a breach occurred.

In one high profile case in 2023, a boutique Advisory Firm received $1.2million penalty and temporary suspension of license operations due to failure to implement basic cybersecurity safeguards including:

  1. No formal incident response plan
  2. Inadequate endpoint protection
  3. No staff cybersecurity awareness training

What are regulators expecting?

ASIC has repeatedly highlighted the importance of the following requirements:

  1. Cyber risk registers as a part of your business risk
  2. Third party oversight including you working with MSPs and cloud vendors
  3. Business continuity plans and stress testing the plans
  4. User activity monitoring and transparency on privilege access controls
  5. ISO 27001 alignment especially where regulatory scrutiny is higher

Need Help?

If you need help in understanding how this will impact your
financial services business, join our Webinar Event.

Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.

How to step up cybersecurity in 2025

blank

How to step up cybersecurity
in 2025.

What businesses are doing now.

blank

Cybersecurity is about building trust, resilience and continuity into your business.

In today’s connected environment, strong cyber foundations aren’t a technical upgrade. They’re a strategic advantage. The businesses getting ahead aren’t reacting to issues, they’re building layers of protection that allow them to move forward with confidence.

Digital transformation has opened the door to better, faster, and more connected ways of working. With cloud platforms, remote collaboration, and integrated systems now standard, the way businesses operate has evolved, and so has the way they protect what matters. Smart organisations aren’t standing still. They’re taking a more strategic approach to cybersecurity, building layered protection that keeps pace with how they work.

At Danet Technology, we believe the best protection strategy is layered. Think of it like an onion, every layer you add makes your business harder to breach. That’s why we’ve developed a practical approach to cybersecurity based on modern best practice and ISO-certified governance. It’s not about paranoia. It’s about preparation.

What’s changed (and what hasn’t)

Cybercrime is escalating, not just in volume but in sophistication. A recent report by the Australian Cyber Security Centre revealed that a new cybercrime is reported every8 minutes, with financial losses exceeding$33 billion annually.

What hasn’t changed? Too many businesses are still underprepared.

Cybersecurity isn’t just a big business issue, it’s a smart business priority. Small and mid-sized organisations are increasingly prioritising security that matches the way they work. While tools like antivirus and backups still have their place, they’re now just one part of a broader approach. The shift we’re seeing is toward layered, business-aligned protection, designed to reduce risk, meet compliance needs and support long-term growth.

Common attacks that are still wreaking havoc

  • Phishing: Still the most common cause of breaches. Whether it’s broad-based phishing or hyper-targeted whaling attacks, social engineering is on the rise.
  • Ransomware: Attackers lock down your files and demand payment, often in cryptocurrency. The impact is immediate and severe.
  • Cloud Jacking: With more businesses shifting to cloud services, attackers are exploiting misconfigurations and insecure credentials to access data.
  • Endpoint Exploits: With remote work the norm, unsecured laptops, mobiles and networks make it easier for attackers to gain entry.
  • Malware: Old-school, but still effective. Malicious software like trojans and spyware are often deployed via email attachments or dodgy websites.

The onion method, layered protection that actually works

Danet’s “onion method” is based on the idea that security should come in layers. Each layer protects your business from a different angle, and together they reduce your exposure to threats.

It starts with daily, automatic backups, ideally cloud-based, tested regularly, and stored securely. Then comes macro control. Block or disable non-vetted Microsoft Office macros to prevent them from delivering malicious code. Control admin privileges by limiting who has elevated access and removing unnecessary permissions. Use multi-factor authentication for all important systems and accounts, requiring an extra layer of identity verification.

Apply patches within 48 hours for both operating systems and applications. Many attacks succeed because of unpatched vulnerabilities. Hardening your applications, such as uninstalling or disabling outdated software like Flash or Java, helps reduce the risk of exploitation. Finally, apply application control. Only approved programs should be allowed to run on your systems. This can significantly reduce the risk of malware execution.

All of these steps are based on the Australian Cyber Security Centre’s Essential Eight, and together they form a strong defence. The more layers you add, the more resilient your business becomes.

What should you do next

Stepping up your cybersecurity doesn’t mean doing everything at once, but it does mean getting started. The best approach is to appoint someone in your team as a cybersecurity lead (much like a fire warden) who can help drive internal awareness. From there, begin mapping out a risk register, identifying the kinds of risks your business faces, how likely they are to occur, and how severe the consequences would be.

Next, evaluate which risks are manageable within your team’s current capacity and where external expertise might be needed. Begin formalising cybersecurity policies, implementing preventative technical controls, and developing a business continuity and disaster recovery plan. These should go hand-in-hand with staff training and a review of any third-party providers who access your systems or data.

If you’re unsure where to begin, talk to someone who can guide you through it. At Danet, we help organisations identify their risks, prioritise safeguards, and meet modern security standards with confidence.

Need a second opinion on your current setup? ​

We offer free cybersecurity audits and infrastructure reviews to help identify hidden risks and prioritise your next steps.
Book a discovery call at danet.com.au to find out more.

ISO-Certified Managed IT Services for Professional Firms

blank

Why Professional Services Firms Choose ISO 27001, ISO 9001 & Cybersecurity Accredited IT Providers

And why Danet continues to deliver secure, structured and scalable support for the work you do.

blank

In professional services, trusted relationships are everything. Law firms, accounting practices, consultants and recruitment agencies all operate with one common expectation, consistent, secure, high-performance technology that supports client service, regulatory compliance, and growth.

That’s why more professional services firms are choosing ISO-accredited managed IT service providers (MSPs) who don’t just react to issues, but build the right foundations from the start.
At Danet, we’ve been ISO 27001 and ISO 9001 certified for two years, and we’ve just passed our latest external audit again. These accreditations reflect our commitment to quality, information security, and industry leadership in managed IT services for professional services.

What is ISO accreditation?

ISO 27001 certification ensures every element of your IT environment, infrastructure, users, applications, and policies, is supported by a clear, structured Information Security Management System (ISMS). It’s about how those systems are governed, monitored and improved to support your business.

ISO 9001 adds a quality layer across every interaction, ensuring that service requests, incident resolution, project delivery and change control are underpinned by a consistent, reliable and continually improved process.

Together, these accreditations allow us to deliver IT support that meets the high expectations of professional services firms: precise, dependable and strategically aligned.

Supporting the way you work

Every professional services firm has its own rhythm, the pace of deadlines, client meetings, sensitive documentation and secure collaboration. We understand that your technology partner isn’t just there to provide support; they’re there to ensure your systems are stable, your risks are covered, and your team can stay focused on delivering exceptional service. That includes:

  • Proactive monitoring and issue resolution
  • Secure cloud infrastructure and Microsoft 365 management
  • Remote work enablement and endpoint protection
  • Business continuity planning and disaster recovery
  • Strategic IT roadmaps tailored to regulatory and operational goals

These services are delivered with the confidence of a partner that understands your obligations.

Built for the expectations of your sector

Professional services teams are trusted with some of the most sensitive data in the country. They operate in regulated environments, engage with clients at critical moments, and uphold high standards of confidentiality and responsiveness. It’s a model that demands technology partners who offer the same discipline and accountability.

That’s where Danet stands apart. We support firms across legal, accounting, and advisory sectors with secure, stable, and scalable managed IT services, delivered by a team that takes the time to understand what success looks like in your world.

Our ISO credentials aren’t just certifications, they’re lived frameworks. We bring structure to your technology operations, resilience to your cybersecurity posture, and long-term thinking to every project and conversation.

Partnering for Performance

At Danet, we focus on building strong, structured partnerships with professional services clients who value alignment, performance, and peace of mind.

We’re proud to deliver managed IT support that reflects the standards you already hold, secure, accredited, client-ready, and built to perform.

If your firm is ready to strengthen its IT foundation with a 
trusted ISO 27001 and ISO 9001 certified partner,
we’re here to supportyou, every step of the way.