The conduct ASIC pursued FIIG for ran from 2019 to 2023, which means the ruling judged an environment that predated the mainstream use of generative AI and before any board was seriously discussing quantum risk. FIIG was penalised for struggling with yesterday's problems.
Mark Andersen, Managing Director at andersenIT and Leah Mooney, AI Governance and Privacy Lead at Wotton Kearney, spent an hour in the webinar andersenIT hosted on the 30th July, on what that means for anyone now facing today’s problems, and these are the moments we keep coming back to.
Reconnaissance is close to fully automated. Leah's point in the webinar was that threat actors have gone a step further and are now running ransom negotiations through generative AI, so they aren't even writing their own threats anymore.
Mark's view is that none of this requires directors to become technical. What it requires is better questions, for example, where is AI being used, what data is going into it, who approved it and what's the evidence for each answer. That last one is harder than it sounds, because AI features are now switched on inside almost every platform you already own, down to the PDF viewer. Nobody approved those.
Encryption is often the reason a breach is judged unlikely to cause serious harm and therefore not notifiable. Mark's argument is that financial services feel this earlier than most industries, because the data stays useful for so long. A scanned passport or a tax file number is worth the same to a criminal in 2032. An attacker doesn't need to break the encryption when they take the file, only to keep it until they can.
The practical starting point he gives is a crypto inventory. Which systems, certificates, backups and archives depend on cryptography, and how long the data behind each stays sensitive.
FIIG was penalised for basic governance, not emerging technology, but the timeline is the part that applies to everyone else. The governance work you're doing today gets tested in a year, or two, or three, against expectations that regulators are still in the process of raising.
Regulators also don't stop at the incident:
Both decisions accepted there is no such thing as perfect security, and that an organisation can do everything to the best available standard and still find itself breached. As Leah put it, it doesn't have to be perfection, but it is a high standard and expectations are high.
The obligations turn on having adequate resources and adequate risk management systems, and because the legislation never defines that word, "adequate" ends up doing a great deal of heavy lifting. It falls to each organisation to work out what it means for them.
"Without evidence, it's just a claim. It's not actually compliance."
A highlight quote from Mark, and one that changes what a board meeting sounds like. "Do we have MFA?" stops being a yes or no question. It becomes 97% deployed, and who are the exceptions, and who approved them. The answer you can back up with evidence is the only one that counts on the day someone asks.
Two questions worth putting to your team this week:
How do you evidence a cyber uplift without gifting the regulator a list of remediation items they can then hold you to? Mark and Leah take that one on in the Q&A, along with everything else we've left out here.
Watch the full webinar here: https://youtu.be/XlMbz4S2gxI