Cyber resilience
Cyber security and resilience is essential to all organisations operating in the digital economy. As digital services become more interconnected, the increasing sophistication and frequency of cyber-attacks has the potential to cause widespread disruption and damage. A material cyber incident may cause significant harm to consumers, destabilise markets and affect trust and confidence in Australia’s financial system.
In Australia, a broad regulatory framework places obligations on businesses, and the people that run them, to properly manage cyber risk. These obligations are administered by various Government departments and agencies. ASIC’s focus within this framework is on Australian financial markets, those that operate in or on those markets, and providers of financial services (other than those principally regulated by another agency such as the Australian Prudential Regulatory Authority).
Our vision is for Australia’s financial markets and systems to be resilient to cyber incidents. We work collaboratively with organisations, regulators and Government to:
- promote active, continuous, and proportionate management of cyber risks
- proactively monitor and supervise regulated organisations
- share good practices and standards, and
- take deterrence-based enforcement action, where appropriate.
ASIC guidance
Cyber resilience is the ability to adapt to disruptions caused by cyber security incidents while maintaining continuous business operations. This includes the ability to detect, manage and recover from incidents.
We have published information and guidance to help organisations improve their cyber security and resilience:
- What a Federal Court ruling on cybersecurity means for AFS licensees
- Key questions for boards to ask about their firm’s cyber resilience
- Good practice guidance, to help organisations operate adaptive and responsive cyber resilience processes
- Report 429 Cyber resilience: Health check, to help organisations improve cyber resilience through awareness and collaboration.
Resources
Many resources are available on the topic of cyber resilience, including regulatory documents, reports, speeches, articles and links to external resources.
We also encourage you to visit the Australian Cyber Security Centre (ACSC) and register to receive their alerts. The ACSC has a range of resources for small and medium businesses and large organisations, including useful tips, guides and assessment tools.
Help for consumers
Everyone has a role to play in ensuring online security, including consumers. Visit our Moneysmart website for information about how to protect yourself from online scams and manage your personal finances with confidence. The ACSC also provides practical tips for individuals and families to stay safe online.
Assessing cyber resilience
We have historically asked firms operating in Australia’s financial markets to complete self-assessment surveys on their cyber resilience. The following reports identify key trends from the surveys and highlight existing good practices and areas for improvement:
- Report 555 Cyber resilience of firms in Australia’s financial markets and media release
- Report 651 Cyber resilience of firms in Australia’s financial markets: 2018–19 and media release
- Report 716 Cyber resilience of firms in Australia’s financial markets: 2020–21 and media release.