• Contact
  • Feedback
Banking Day
Stay Ahead. Stay Informed.
Concise. Candid. Provocative.
Get the daily banking news that matters
Banking Day – Your trusted source for independent financial insights.
Subscribe Now
  • News
  • Topics
    • All Topics
    • Briefs
    • Major Banks
    • Authorised deposit-taking institutions
    • Insurance, funds and super
    • Payments, mobile & wallets
    • Consumer lending
    • Mortgages
    • Business lending
    • Finance regulation
    • Debt capital markets
    • Ratings agencies
    • Equity capital markets
    • Professional services
    • Work & career
    • Foreign news
    • Other topics
  • Free Trial
  • Subscribe
  • Resources
    • Industry events
  • About us
    • About Banking Day
    • Advertise
    • Feedback
    • Contact Banking Day
  • Search
  • Login
  • My account
    • Account settings
    • User Admin
    • Logout

Login or request a free trial

Big gaps found in cyber risk management

14 November 2023 5:51AM

There are gaps in Australian financial institutions’ management of cyber security risk, with most companies operating on a reactive rather than proactive basis, a new survey has found. ASIC surveyed regulated entities to get an understanding of their ability to manage risks, protect information assets and respond to and recover from security incidents. The survey was completed by 697 respondents. Among the gaps identified: 44 per cent of respondents said they do not manage third-party or supply chain risk; 58 per cent have limited or no capability to protect confidential information adequately; 33 per cent do not have a cyber incident response plan; and 20 per cent have not adopted a cyber security standard. Small organisations scored lower ratings from ASIC than larger ones. Most small organisations were ranked in maturity tier 1: “Capabilities are reactive. Policies and procedures are not formalised.” The regulator said small businesses need to do more to educate staff about cyber risks, develop response plans, conduct regular security assessments, and implement more robust monitoring and logging solutions. Most larger organisations fell into maturity tier 2: “Capabilities exist but policies are procedures are rarely updated and not followed consistently.” ASIC said all organisations should aim to make their cyber security strategies more effective by conducting third-party risks assessments, establishing contractual obligations with third parties and ensuring all confidential information shared with third parties is protected. Organisations should introduce multi-factor authentication procedures and encryption protocols to protect confidential information from unauthorised access. They should conduct simulated cyber-attacks to evaluate the effectiveness of their responses. And they should enforce a data retention policy that specifies how long data should be held and when it should be destroyed.

I'm a returning subscriber

*
Password reset *
Login

Request a free trial

  • Emailing you the news at 7am.
  • Covering core lending and funding issues, strategy, payments, regulation, risk management, IT, marketing and more.
  • Original news and summaries of major stories from other media – ditch your newspaper subscriptions.
  • Focused on banking and finance, saving you the time spent wading through newspapers and other services.
  • With reporting from former editors and senior writers from the AFR and The Australian.
  • Configured for your phone, laptop and PC.
Free trial Banking Day
Stay Ahead. Stay Informed.
Concise. Candid. Provocative.
Get the daily banking news that matters
Banking Day – Your trusted source for independent financial insights.
Subscribe Now

Consumer lending

  • Latitude, Harvey Norman liable for interest free GO card con

Copyright © WorkDay Media 2003-2025.

Banking Day is a WorkDay Media publication

WorkDay Media Unit Trust

  • Privacy policy
  • Terms of access and use