The board is personally on the hook now — how cyber became a directors' duty in Australia

Published Aug 21, 2026 by Xiph

Picture the standing agenda of a mid-sized Australian company. Finance gets forty minutes and an argument. Cyber gets a slide — usually green, occasionally amber — presented by whoever manages the IT contract, and everyone nods. The working theory is that cyber is a technical matter, technical matters get delegated, and delegation is what good governance looks like.

Australia's regulators no longer subscribe to that theory. Across three regimes — corporate law, prudential standards and privacy — the question asked after an incident has quietly changed. It is no longer just what failed? It is what did the board ask, what did it understand, and what did it do about it? "We left it to IT" has shifted from a defence to an admission.

Directors of big listed companies have mostly registered the shift; their lawyers make sure of it. Most directors of mid-sized companies have not — and they have the least cover when it matters.

The board is personally on the hook now — how cyber became a directors' duty in Australia

ASIC said the quiet part out loud

Start with the law that binds every company director in the country: section 180 of the Corporations Act — the duty of reasonable care and diligence. Nothing in it mentions computers. It doesn't need to.

ASIC chair Joe Longo has spent three years telling directors exactly how the regulator reads it: a cyber attack is a foreseeable risk, cyber security and resilience "are not merely technical matters on the fringes of directors' duties", and a board that fails to give them sufficient priority exposes its directors to enforcement action for not acting with care and diligence. That is a stated enforcement theory, repeated year after year.

And ASIC litigates it. In 2022 the Federal Court found licensee RI Advice had breached its obligations after nine cyber incidents in six years exposed inadequate risk management — a first-of-its-kind case ending in court-supervised remediation and $750,000 towards ASIC's costs. In early 2026 the sequel landed harder: FIIG Securities was penalised around $2.5 million after a ransomware crew spent roughly three weeks inside its network in 2023 and stole the confidential data of some 18,000 clients.

Two details in FIIG should unsettle every director. First, FIIG had the policies — a documented framework, security policies, the lot. It simply didn't follow them, and the court treated the binder not as protection but as a record of what the company knew it should be doing. Second, the compliance program ends with FIIG's chief executive personally attesting to the remediation. No directors were sued — this time. But this year the Federal Court also found former Star Entertainment executives had personally breached section 180 over governance failures — different subject matter, the same section ASIC points at for cyber. The machinery for personal liability is fully assembled.

APRA wrote it down first — and it flows downhill

To see where expectations of directors are heading, read the rules already binding banks, insurers and superannuation funds. APRA's Prudential Standard CPS 234 has, since 2019, opened with the sentence most standards bury: the board is ultimately responsible for the entity's information security. Not the CIO. Not the vendor. The board — with material incidents notified to APRA within 72 hours.

APRA then checked: independent "tripartite" assessments across more than 300 entities found basic, widespread gaps, and the regulator said it would actively target non-compliance. When Medibank was breached in 2022, the consequence was a $250 million capital add-on until remediation was complete — governance failure, priced in capital. Since 1 July 2025, CPS 230 has pushed further: boards must approve how long critical operations may be down, and entities must lodge a register of material service providers. The Financial Accountability Regime now pins these duties to named individuals.

This matters even to a company APRA has never heard of, for two reasons. Prudential standards are the template courts and regulators reach for when deciding what "reasonable" cyber risk management looks like — the high-water mark drifts downstream. And if you supply software, IT services or data handling to a regulated entity, CPS 230 makes you their material-service-provider problem: their obligations arrive as security clauses, questionnaires and audit rights — the same downhill flow we described with the SOCI Act.

10 December 2026 — the newest duty is about what your software decides

The next deadline is one most boards haven't heard of. From 10 December 2026, new transparency rules under the Privacy Act require organisations to disclose their use of automated decision-making. Where a computer program makes — or substantially and directly helps make — a decision about a person using their personal information, and that decision could reasonably be expected to significantly affect their rights or interests, your privacy policy must say so: the kinds of information used, and the kinds of decisions made.

That reads like a task for whoever last touched the privacy policy. It isn't, for two reasons.

You cannot disclose what you haven't inventoried. Loan and credit approvals, tenant screening, automated CV filtering, insurance pricing, fraud engines that freeze a customer's account — mid-sized businesses run far more of this than their boards realise, much of it buried inside third-party SaaS nobody thinks of as "AI". And there is no grandfathering: if a qualifying system is running on 10 December, the duty is live, whether the software arrived last month or in 2019.

The regulator also has faster weapons than it used to: compliance and infringement notices over a defective privacy policy, with civil penalties behind them reaching the greater of $50 million, three times the benefit gained, or 30% of adjusted turnover for serious cases. The OAIC ran its first compliance sweep of privacy policies in January and will publish guidance on the new rules by September — the runway is being cleared deliberately. A privacy policy that misdescribes your own automation is a governance document you published about yourself, and it will be Exhibit A.

So the board question is not "has legal updated the policy?" It is "do we actually know every system making significant automated decisions about people — and who checked?"

What "demonstrate" actually means

Put the three regimes side by side and the common thread is plain. Nobody expects a director to configure a firewall. What ASIC, APRA and the OAIC each expect is that the board can demonstrate it treated cyber as a material business risk — that it asked, understood the answer, and acted. Longo has been specific about where boards fail: ASIC keeps finding daylight between what boards believe they oversee, what management reports to them, and what is actually implemented.

Demonstration is a paperwork word, deliberately. A minute that records "cyber report noted" demonstrates nothing. A minute that records the question asked, the answer given, the decision taken and the follow-up date demonstrates everything. FIIG is the cautionary tale in reverse: documents you don't act on become the prosecution's timeline. If it isn't written down — or is written down and then ignored — you have quietly built the case against yourself.

Four items for every quarterly agenda — and the evidence to keep

None of this requires a new committee. It requires four standing questions, asked every quarter, with the answers filed.

  1. Exposure — what would hurt most, and what changed? One page, in plain English: the systems and data whose loss would genuinely damage the business, the top five current risks, and what moved since last quarter — including patch latency, the number we've argued belongs on every board report. Keep: the paper itself, plus minutes recording what the board challenged and decided.

  1. Resilience — could we take a punch this quarter? When was the incident response plan last exercised with the people who would be ringing each other at 2am? When did we last restore from backup, and how long did it take? Do we know our notification clocks — the OAIC's data breach scheme, the 72-hour ransomware payment report that has applied to businesses turning over $3 million since May 2025, SOCI's 12 hours if it reaches us? Keep: the exercise report, the restore-test log, the current contact tree.

  2. Third parties — who can hurt us from outside? A register of every supplier with access to your systems or data, what assurance you hold on each beyond a self-completed questionnaire, and which single provider's failure would stop you trading. This is CPS 230's logic applied voluntarily — before a major customer applies it to you contractually. Keep: the register, the assessments, the security clauses in new contracts.

  3. The horizon — what lands next, and are we ready? Right now that means the automated decision-making inventory and privacy policy rewrite before 10 December, ransomware-reporting readiness, and whatever your insurer's renewal questionnaire now demands. Keep: an obligations register with an owner and a date against each item, the system inventory, the redrafted policy, training records.

Kept together, that file — papers, minutes, registers, test results, remediation tracking — is the demonstration regulators are asking for. The test is simple: could you hand it to a regulator, or a plaintiff's lawyer, eighteen months from now, and be comfortable with what it says about you?

A final word

Nothing above asks a director to become a technologist. It asks for the discipline boards already apply to financial risk — informed questions, credible answers, documented action — pointed at a risk every regulator now calls foreseeable. The direct costs are rising on their own: the ASD logged a cybercrime report every six minutes last financial year, and the average incident cost a medium-sized business $97,200 — up 55% in a year. The governance consequences outlast the invoice.

For most mid-sized companies the honest obstacle isn't will, it's bandwidth: no full-time security executive exists to prepare the quarterly paper, brief the board, maintain the evidence file and watch the compliance calendar. That is the gap a virtual CISO exists to fill: senior security leadership, board reporting and compliance upkeep at a fraction of a full-time hire. Xiph Cyber provides that standing resource to Australian boards — and a cyber security risk audit is the fastest way to see what your evidence file would show today. To put these four questions on your next agenda, with answers behind them, get in touch at enquiries@xiphcyber.com — you'll speak to a real person within 24 hours.


Posted in: Security